{"id":"MGASA-2017-0014","summary":"Updated flash-player-plugin packages fix security vulnerabilities","details":"Adobe Flash Player 24.0.0.194 contains fixes to critical security\nvulnerabilities found in earlier versions that could potentially allow\nan attacker to take control of the affected system.\n\nAdobe is aware of a report that an exploit for CVE-2016-7892 exists in\nthe wild, and is being used in limited, targeted attacks against users\nrunning Internet Explorer (32-bit) on Windows.\n\nThis update resolves security bypass vulnerabilities (CVE-2016-7890,\nCVE-2017-2938).\n\nThis update resolves use-after-free vulnerabilities that could lead to\ncode execution (CVE-2016-7872, CVE-2016-7877, CVE-2016-7878,\nCVE-2016-7879, CVE-2016-7880, CVE-2016-7881, CVE-2016-7892,\nCVE-2017-2932, CVE-2017-2936, CVE-2017-2937). \n\nThis update resolves buffer overflow vulnerabilities that could lead to\ncode execution (CVE-2016-7867, CVE-2016-7868, CVE-2016-7869,\nCVE-2016-7870, CVE-2017-2927, CVE-2017-2933, CVE-2017-2934,\nCVE-2017-2935).\n\nThis update resolves memory corruption vulnerabilities that could lead\nto code execution (CVE-2016-7871, CVE-2016-7873, CVE-2016-7874,\nCVE-2016-7875, CVE-2016-7876, CVE-2017-2925, CVE-2017-2926,\nCVE-2017-2928, CVE-2017-2930, CVE-2017-2931).\n\nNote that Adobe has dropped Adobe Access DRM support from all their\nLinux releases since their 11.2 release series (which no longer gets\nsecurity updates), so any Flash content protected with Adobe Access\nwill no longer work.\n","modified":"2026-04-16T06:23:04.169563423Z","published":"2017-01-13T10:32:16Z","upstream":["CVE-2016-7867","CVE-2016-7868","CVE-2016-7869","CVE-2016-7870","CVE-2016-7871","CVE-2016-7872","CVE-2016-7873","CVE-2016-7874","CVE-2016-7875","CVE-2016-7876","CVE-2016-7877","CVE-2016-7878","CVE-2016-7879","CVE-2016-7880","CVE-2016-7881","CVE-2016-7890","CVE-2016-7892","CVE-2017-2925","CVE-2017-2926","CVE-2017-2927","CVE-2017-2928","CVE-2017-2930","CVE-2017-2931","CVE-2017-2932","CVE-2017-2933","CVE-2017-2934","CVE-2017-2935","CVE-2017-2936","CVE-2017-2937","CVE-2017-2938"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2017-0014.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=19960"},{"type":"WEB","url":"https://helpx.adobe.com/security/products/flash-player/apsb16-39.html"},{"type":"WEB","url":"https://helpx.adobe.com/security/products/flash-player/apsb17-02.html"}],"affected":[{"package":{"name":"flash-player-plugin","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/flash-player-plugin?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"24.0.0.194-1.mga5.nonfree"}]}],"ecosystem_specific":{"section":"nonfree"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2017-0014.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}