CVE-2014-0492: Critical severity Adobe Flash Player vulnerability
Adobe Flash Player before 11.7.700.260 and 11.8.x and 11.9.x before 12.0.0.38 on Windows and Mac OS X and before 11.2.202.335 on Linux, Adobe AIR before 4.0.0.1390, Adobe AIR SDK before 4.0.0.1390, and Adobe AIR SDK & Compiler before 4.0.0.1390 allow attackers to defeat the ASLR protection mechanism by leveraging an "address leak."
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0492?
CVE-2014-0492 has a moderate severity rating due to the bypassing of ASLR protections allowing potential exploitation.
How do I fix CVE-2014-0492?
To fix CVE-2014-0492, upgrade Adobe Flash Player to version 11.7.700.261 or later, or to version 12.0.0.38 or later.
What versions of Adobe Flash Player are affected by CVE-2014-0492?
CVE-2014-0492 affects Adobe Flash Player versions before 11.7.700.260, 11.8.x before 11.8.800.175, and 11.9.x before 12.0.0.38.
Which Adobe AIR versions are vulnerable to CVE-2014-0492?
Adobe AIR prior to version 4.0.0.1390 is vulnerable to CVE-2014-0492.
Can CVE-2014-0492 affect all operating systems?
CVE-2014-0492 is relevant to Windows, Mac OS X, and Linux systems with the affected versions of Adobe Flash Player and Adobe AIR.