Adobe is aware of a report that an exploit for CVE-2016-1010 is being used in limited, targeted attacks and recommends users update their product installations to the latest versions:
- Users of Adobe Flash Player 20.0.0.306 and earlier versions for IE should update to Adobe Flash Player 21.0.0.182.
- Users of Adobe Flash Player 20.0.0.306 and earlier versions for Firefox (Windows) should update to Adobe Flash Player 21.0.0.182
- Users of Adobe Flash Player 20.0.0.306 and earlier versions for Macintosh should update to Adobe Flash Player 21.0.0.182
- Adobe Flash Player installed with Google Chrome will be automatically updated to the current version.
- Adobe Flash Player installed for Internet Explorer on Windows 8.1 will be automatically updated to the current version.
- Adobe Flash Player installed for Microsoft Edge and Internet Explorer 11 on Windows 10 will be automatically updated to the current version.
- Users of Adobe Flash Player 11.2.202.559 and earlier versions for Linux should update to Adobe Flash Player 11.2.202.577
Overview
Adobe Flash Player 21 drives innovation for rich, engaging digital experiences with new features for cross-platform browser-based viewing of expressive rich internet applications, content, and videos across devices. This release provides access to the Flash Player 21 runtime for Windows desktop, Mac OS, iOS and Android environments.
What's new in Flash Player 21
Adobe Flash Player 21 includes the following:
- GPU Memory Information In Context3D
- Support for Browser Zoom Factor in Firefox
- PPAPI vector printing on MAC OSX
- Simplified LSO UI
- Media Auto Play for iOS & Android
- Android StageWebView debugging
For a full list of features in Flash Player and AIR, including features introduced in previous releases, please review the document here.
Download Flash Player 21.0.0.182
The following downloads provide the Adobe Flash Player 21.0.0.182 installers for Windows, Linux and Mac OS X. Download the files appropriate for you:
Security fixes:
This release contains the following security fixes:
- Fixed integer overflow vulnerabilities that could lead to code execution (CVE-2016-0963, CVE-2016-0993, CVE-2016-1010).
- Fixed use-after-free vulnerabilities that could lead to code execution (CVE-2016-0987, CVE-2016-0988, CVE-2016-0990, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, CVE-2016-1000).
- Fixed a heap overflow vulnerability that could lead to code execution (CVE-2016-1001).
- Fixed memory corruption vulnerabilities that could lead to code execution (CVE-2016-0960, CVE-2016-0961, CVE-2016-0962, CVE-2016-0986, CVE-2016-0989, CVE-2016-0992, CVE-2016-1002, CVE-2016-1005).
Sources:
Adobe Flash Player 21 Release Notes
Adobe Security Bulletins and Advisories
APSB16-08 Security updates available for Adobe Flash Player
No comments:
Post a Comment