PT-2014-2027 · Adobe+3 · Flash Player+3

Published

2014-12-09

·

Updated

2025-11-17

·

CVE-2014-9163

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Adobe Flash Player versions prior to 13.0.0.259 Adobe Flash Player versions 14.x Adobe Flash Player versions 15.x prior to 15.0.0.246 Adobe Flash Player versions prior to 11.2.202.425 on Linux
Description The issue is related to a stack-based buffer overflow in Adobe Flash Player, which can be exploited by a remote attacker to execute arbitrary code via unspecified vectors. This vulnerability has been exploited in the wild in December 2014.
Recommendations For Adobe Flash Player versions prior to 13.0.0.259, update to version 13.0.0.259 or later. For Adobe Flash Player versions 14.x, update to a version that is not affected by this issue. For Adobe Flash Player versions 15.x prior to 15.0.0.246, update to version 15.0.0.246 or later. For Adobe Flash Player versions prior to 11.2.202.425 on Linux, update to version 11.2.202.425 or later.

Fix

Buffer Overflow

Stack Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2014-2435
BDU:2021-04945
CVE-2014-9163
MGASA-2014-0521
OPENSUSE-SU-2014_1629-1
RHSA-2014:1981
RHSA-2014_1981
ZDI-14-417

Affected Products

Alt Linux
Flash Player
Red Hat
Suse