First published: Wed May 14 2014(Updated: )
Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR SDK before 13.0.0.111, and Adobe AIR SDK & Compiler before 13.0.0.111 allow attackers to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2014-0517, CVE-2014-0519, and CVE-2014-0520.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | >=13.0<13.0.0.214 | |
Apple iOS and macOS | ||
Microsoft Windows | ||
Adobe Acrobat Reader | >=11.0<11.2.202.359 | |
Linux Kernel | ||
Adobe AIR SDK | <13.0.0.111 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0518 is considered a critical vulnerability due to its ability to allow attackers to bypass access restrictions.
To fix CVE-2014-0518, update Adobe Flash Player to version 13.0.0.214 or later, and Adobe AIR SDK to version 13.0.0.111 or later.
Adobe Flash Player versions before 13.0.0.214 on Windows and OS X, and before 11.2.202.359 on Linux, along with Adobe AIR SDK versions before 13.0.0.111 are affected by CVE-2014-0518.
The vulnerable platforms for CVE-2014-0518 include Windows, OS X, and certain Linux distributions running affected versions of Adobe Flash Player and Adobe AIR SDK.
Yes, CVE-2014-0518 is a different vulnerability from CVE-2014-0517, even though both affect Adobe Flash Player.