MGASA-2018-0120

Source
https://advisories.mageia.org/MGASA-2018-0120.html
Import Source
https://advisories.mageia.org/MGASA-2018-0120.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2018-0120
Related
Published
2018-02-07T13:50:37Z
Modified
2026-02-04T03:22:55.092732Z
Summary
Updated flash-player-plugin packages fix security vulnerability
Details

Adobe Flash Player 28.0.0.161 addresses critical use-after-free vulnerabilities that could lead to remote code execution (CVE-2018-4877, CVE-2018-4878). Successful exploitation could potentially allow an attacker to take control of the affected system.

Adobe is aware of a report that an exploit for CVE-2018-4878 exists in the wild, and is being used in limited, targeted attacks against Windows users. These attacks leverage Office documents with embedded malicious Flash content distributed via email.

References
Credits

Affected packages

Mageia:6 / flash-player-plugin

Package

Name
flash-player-plugin
Purl
pkg:rpm/mageia/flash-player-plugin?arch=source&distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
28.0.0.161-1.mga6.nonfree

Ecosystem specific

{
    "section": "nonfree"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2018-0120.json"