{"id":"MGASA-2014-0291","summary":"Updated flash-player-plugin packages fix multiple vulnerabilities","details":"Adobe Flash Player 11.2.202.394 contains fixes to critical security \nvulnerabilities found in earlier versions that could potentially allow an \nattacker to take control of the affected system.\n\nThis update includes additional validation checks to ensure that Flash Player\nrejects malicious content from vulnerable JSONP callback APIs (CVE-2014-4671).\n\nThis update resolves security bypass vulnerabilities \n(CVE-2014-0537, CVE-2014-0539).\n","modified":"2026-04-16T06:23:05.489136454Z","published":"2014-07-09T23:21:32Z","upstream":["CVE-2014-0537","CVE-2014-0539","CVE-2014-4671"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2014-0291.html"},{"type":"WEB","url":"http://helpx.adobe.com/security/products/flash-player/apsb14-17.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=13706"}],"affected":[{"package":{"name":"flash-player-plugin","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/flash-player-plugin?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"11.2.202.394-1.mga3.nonfree"}]}],"ecosystem_specific":{"section":"nonfree"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0291.json"}},{"package":{"name":"flash-player-plugin","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/flash-player-plugin?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"11.2.202.394-1.mga4.nonfree"}]}],"ecosystem_specific":{"section":"nonfree"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0291.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}