{"id":"MGASA-2018-0120","summary":"Updated flash-player-plugin packages fix security vulnerability","details":"Adobe Flash Player 28.0.0.161 addresses critical use-after-free\nvulnerabilities that could lead to remote code execution (CVE-2018-4877,\nCVE-2018-4878). Successful exploitation could potentially allow an\nattacker to take control of the affected system.\n\nAdobe is aware of a report that an exploit for CVE-2018-4878 exists in the\nwild, and is being used in limited, targeted attacks against Windows users.\nThese attacks leverage Office documents with embedded malicious Flash\ncontent distributed via email.\n","modified":"2026-04-16T06:25:45.101725660Z","published":"2018-02-07T13:50:37Z","upstream":["CVE-2018-4877","CVE-2018-4878"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2018-0120.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=22534"},{"type":"WEB","url":"https://helpx.adobe.com/security/products/flash-player/apsb18-03.html"}],"affected":[{"package":{"name":"flash-player-plugin","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/flash-player-plugin?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"28.0.0.161-1.mga6.nonfree"}]}],"ecosystem_specific":{"section":"nonfree"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2018-0120.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}