Adobe Flash Player 23.0.0.207 Security Updates

Adobe has released Flash Player 23.0.0.207 for Windows, Macintosh and Chrome OS, and Flash Player 11.2.202.644 for Linux. These updates includes stability improvements and also address multiple critical-risk vulnerabilities that could potentially allow an attacker to take control of the affected system.

Adobe recommends users update their product installations to the latest versions:
  • Users of Adobe Flash Player 23.0.0.205 and earlier versions for IE should update to Adobe Flash Player 23.0.0.207.
  • Users of Adobe Flash Player 23.0.0.205 and earlier versions for Firefox (Windows) should update to Adobe Flash Player 23.0.0.207
  • Users of Adobe Flash Player 23.0.0.205 and earlier versions for Macintosh should update to Adobe Flash Player 23.0.0.207
  • Adobe Flash Player installed with Google Chrome will be automatically updated to the current version.
  • Adobe Flash Player installed for Internet Explorer on Windows 8.1 will be automatically updated to the current version.
  • Adobe Flash Player installed for Microsoft Edge and Internet Explorer 11 on Windows 10 will be automatically updated to the current version.
  • Users of Adobe Flash Player 11.2.202.643 and earlier versions for Linux should update to Adobe Flash Player 11.2.202.644

Overview
Adobe Flash Player 23 drives innovation for rich, engaging digital experiences with new features for cross-platform browser-based viewing of expressive rich internet applications, content, and videos across devices. This release provides access to the Flash Player 23 runtime for Windows desktop, Mac OS, iOS and Android environments.

What's new in Flash Player 23
Adobe Flash Player 23 includes the following:
  • Mozilla NPAPI AsyncDrawing Support
  • HSTS Support in Flash Player
  • Disabling local-with-filesystem access in Flash Player by default
  • Video and Camera support for Stage3D by VideoTexture for Flash Player (Release)
  • GameInput API for iOS
  • Echo Cancellation on AIR for Android
  • The StageText clear button is now optional on iOS
  • Windows: Add HiDPI support for AIR desktop (Release)

For a full list of features in Flash Player and AIR, including features introduced in previous releases, please review the document here.

Download Flash Player 23.0.0.207
The following downloads provide the Adobe Flash Player 23.0.0.207 installers for Windows, Linux and Mac OS X. Download the files appropriate for you:

Security fixes:
This release contains the following security fixes:
  • Fixed type confusion vulnerabilities that could lead to code execution (CVE-2016-7860, CVE-2016-7861, CVE-2016-7865).
  • Fixed use-after-free vulnerabilities that could lead to code execution (CVE-2016-7857, CVE-2016-7858, CVE-2016-7859, CVE-2016-7862, CVE-2016-7863, CVE-2016-7864).

Sources:
Adobe Flash Player 23 Release Notes
Adobe Security Bulletins and Advisories
APSB16-37 Security updates available for Adobe Flash Player

No comments: