Red Hat Bugzilla – Bug 1067656
CVE-2014-0498 CVE-2014-0499 CVE-2014-0502 flash-plugin: multiple flaws lead to arbitrary code execution (APSB14-07)
Last modified: 2016-10-04 04:27:53 EDT
Adobe has released Flash Player 11.2.202.341 for Linux to correct the following flaws: * These updates resolve a stack overflow vulnerability that could result in arbitrary code execution (CVE-2014-0498). * These updates resolve a memory leak vulnerability that could be used to defeat memory address layout randomization (CVE-2014-0499). * These updates resolve a double free vulnerability that could result in arbitrary code execution (CVE-2014-0502). External References: http://helpx.adobe.com/security/products/flash-player/apsb14-07.html
This issue has been addressed in following products: Supplementary for Red Hat Enterprise Linux 5 Supplementary for Red Hat Enterprise Linux 6 Via RHSA-2014:0196 https://rhn.redhat.com/errata/RHSA-2014-0196.html