Adobe Flash Player 22.0.0.192 is now available for download

Adobe has released Flash Player 22.0.0.192 for Windows, Macintosh and Chrome OS, and Flash Player 11.2.202.626 for Linux. Flash Player 22 includes new and improved functionality and important bug fixes. These updates also address multiple critical-risk vulnerabilities that could potentially allow an attacker to take control of the affected system.

Adobe is aware of a report that an exploit for CVE-2016-4171 is being used in limited, targeted attacks and recommends users update their product installations to the latest versions:
  • Users of Adobe Flash Player 21.0.0.242 and earlier versions for IE should update to Adobe Flash Player 22.0.0.192.
  • Users of Adobe Flash Player 21.0.0.242 and earlier versions for Firefox (Windows) should update to Adobe Flash Player 22.0.0.192
  • Users of Adobe Flash Player 21.0.0.242 and earlier versions for Macintosh should update to Adobe Flash Player 22.0.0.192
  • Adobe Flash Player installed with Google Chrome will be automatically updated to the current version.
  • Adobe Flash Player installed for Internet Explorer on Windows 8.1 will be automatically updated to the current version.
  • Adobe Flash Player installed for Microsoft Edge and Internet Explorer 11 on Windows 10 will be automatically updated to the current version.
  • Users of Adobe Flash Player 11.2.202.621 and earlier versions for Linux should update to Adobe Flash Player 11.2.202.626

Overview
Adobe Flash Player 22 drives innovation for rich, engaging digital experiences with new features for cross-platform browser-based viewing of expressive rich internet applications, content, and videos across devices. This release provides access to the Flash Player 22 runtime for Windows desktop, Mac OS, iOS and Android environments.

What's new in Flash Player 22
Adobe Flash Player 22 includes the following:
  • Video Pipeline Changes for Android AIR
  • Prevent Flash Player Cross-Channel Installation on OS X
  • EnableLocalAppData
  • HiDPI support for AIR Windows
  • stage.contentsScaleFactor
  • Anti-Aliasing (Render to texture) for AIR Mobile
  • Echo Cancellation on AIR iOS
  • Multitasking Enhancements Support in AIR iOS - Beta
  • Support for Android N Beta
  • System level Flash Player support for AIR desktop applications
  • Override Flash Player's default language via mms.cfg

For a full list of features in Flash Player and AIR, including features introduced in previous releases, please review the document here.

Download Flash Player 22.0.0.192
The following downloads provide the Adobe Flash Player 22.0.0.192 installers for Windows, Linux and Mac OS X. Download the files appropriate for you:


Security fixes:
This release contains the following security fixes:
  • Fixed type confusion vulnerabilities that could lead to code execution (CVE-2016-4144, CVE-2016-4149).
  • Fixed use-after-free vulnerabilities that could lead to code execution (CVE-2016-4142, CVE-2016-4143, CVE-2016-4145, CVE-2016-4146, CVE-2016-4147, CVE-2016-4148).
  • Fixed heap buffer overflow vulnerabilities that could lead to code execution (CVE-2016-4135, CVE-2016-4136, CVE-2016-4138).
  • Fixed memory corruption vulnerabilities that could lead to code execution (CVE-2016-4122, CVE-2016-4123, CVE-2016-4124, CVE-2016-4125, CVE-2016-4127, CVE-2016-4128, CVE-2016-4129, CVE-2016-4130, CVE-2016-4131, CVE-2016-4132, CVE-2016-4133, CVE-2016-4134, CVE-2016-4137, CVE-2016-4141, CVE-2016-4150, CVE-2016-4151, CVE-2016-4152, CVE-2016-4153, CVE-2016-4154, CVE-2016-4155, CVE-2016-4156, CVE-2016-4166, CVE-2016-4171).
  • Fixed a vulnerability in the directory search path used to find resources that could lead to code execution (CVE-2016-4140).
  • Fixed a vulnerability that could be exploited to bypass the same-origin-policy and lead to information disclosure (CVE-2016-4139).

Sources:
Adobe Flash Player 22 Release Notes
Adobe Security Bulletins and Advisories
APSB16-18 Security updates available for Adobe Flash Player

No comments: