[arch-security] [ASA-201507-7] flashplugin: remote code execution
rgacogne at archlinux.org
Wed Jul 8 11:54:23 UTC 2015
Arch Linux Security Advisory ASA-201507-7
Date : 2015-07-08
CVE-ID : CVE-2015-5119
Package : flashplugin
Type : remote code execution
Remote : Yes
Link : https://wiki.archlinux.org/index.php/CVE
The package flashplugin before version 22.214.171.1241-1 is vulnerable to
remote code execution.
Upgrade to 126.96.36.1991-1.
# pacman -Syu "flashplugin>=188.8.131.521-1"
The problem has been fixed upstream in version 184.108.40.2061.
A critical vulnerability (use-after-free in the AS3 ByteArray class) has
been identified in Adobe Flash Player 220.127.116.11 and earlier versions
for Windows, Macintosh and Linux. Successful exploitation could cause a
crash and potentially allow an attacker to take control of the affected
Adobe is aware of reports that an exploit targeting this vulnerability
has been published publicly.
A remote attacker can execute arbitrary code on the affected host using
a crafted flash application.
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 801 bytes
Desc: OpenPGP digital signature
More information about the arch-security