Published on: 09 July 2015
Security updates are released for Adobe Flash Player to address multiple vulnerabilities caused by memory corruption, heap buffer overflow, type confusion or use-after-free error. To successfully exploit the vulnerabilities, a remote attacker could entice a targeted user to open a specially crafted web page, Flash file, or document that supports embedded Flash content.
A successful attack could lead to arbitrary code execution, sensitive information disclosure and security restrictions bypass.
Upgrade Adobe Flash Player to the following versions to address the issue. The upgrade can be obtained by using the auto-update mechanism or by downloading at the following URLs:
If you have multiple browsers, you are required to perform the Adobe Flash Player upgrade for each browser, the Flash Player version can be checked at http://www.adobe.com/software/flash/about/
https://helpx.adobe.com/security/products/flash-player/apsb15-16.html
https://www.hkcert.org/my_url/en/alert/15070901 https://www.us-cert.gov/ncas/current-activity/2015/07/08/Adobe-Releases-Security-Updates-Flash-Player
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0578
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3097
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3114 (to CVE-2015-3137)
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4428 (to CVE-2015-4433)
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5116 (to CVE-2015-5119)