openSUSE Security Update: Security update for flash-player
______________________________________________________________________________

Announcement ID:    openSUSE-SU-2014:1622-1
Rating:             critical
References:         
Cross-References:   CVE-2014-0580 CVE-2014-0587 CVE-2014-8443
                    CVE-2014-9162 CVE-2014-9163 CVE-2014-9164
                   
Affected Products:
                    openSUSE Evergreen 11.4
______________________________________________________________________________

   An update that fixes 6 vulnerabilities is now available.

Description:

   Flash-player was updated to version 11.2.202.245 fixing numerous
   vulnerabilities:
    *memory corruption vulnerabilities that could lead to code execution
     (CVE-2014-0587, CVE-2014-9164).
    *use-after-free vulnerability that could lead to code execution
     (CVE-2014-8443).
    *stack-based buffer overflow vulnerability that could lead to code
     execution (CVE-2014-9163).
    *information disclosure vulnerability (CVE-2014-9162).
    *vulnerability that could be exploited to circumvent the same-origin
     policy (CVE-2014-0580).


Patch Instructions:

   To install this openSUSE Security Update use YaST online_update.
   Alternatively you can run the command listed for your product:

   - openSUSE Evergreen 11.4:

      zypper in -t patch 2014-92

   To bring your system up-to-date, use "zypper patch".


Package List:

   - openSUSE Evergreen 11.4 (i586 x86_64):

      flash-player-11.2.202.425-135.1
      flash-player-gnome-11.2.202.425-135.1
      flash-player-kde4-11.2.202.425-135.1


References:

   https://www.suse.com/security/cve/CVE-2014-0580.html
   https://www.suse.com/security/cve/CVE-2014-0587.html
   https://www.suse.com/security/cve/CVE-2014-8443.html
   https://www.suse.com/security/cve/CVE-2014-9162.html
   https://www.suse.com/security/cve/CVE-2014-9163.html
   https://www.suse.com/security/cve/CVE-2014-9164.html

-- 

openSUSE: 2014:1622-1: critical: flash-player

December 12, 2014
An update that fixes 6 vulnerabilities is now available.

Description

Flash-player was updated to version 11.2.202.245 fixing numerous vulnerabilities: *memory corruption vulnerabilities that could lead to code execution (CVE-2014-0587, CVE-2014-9164). *use-after-free vulnerability that could lead to code execution (CVE-2014-8443). *stack-based buffer overflow vulnerability that could lead to code execution (CVE-2014-9163). *information disclosure vulnerability (CVE-2014-9162). *vulnerability that could be exploited to circumvent the same-origin policy (CVE-2014-0580).

 

Patch

Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE Evergreen 11.4: zypper in -t patch 2014-92 To bring your system up-to-date, use "zypper patch".


Package List

- openSUSE Evergreen 11.4 (i586 x86_64): flash-player-11.2.202.425-135.1 flash-player-gnome-11.2.202.425-135.1 flash-player-kde4-11.2.202.425-135.1


References

https://www.suse.com/security/cve/CVE-2014-0580.html https://www.suse.com/security/cve/CVE-2014-0587.html https://www.suse.com/security/cve/CVE-2014-8443.html https://www.suse.com/security/cve/CVE-2014-9162.html https://www.suse.com/security/cve/CVE-2014-9163.html https://www.suse.com/security/cve/CVE-2014-9164.html--


Severity
Announcement ID: openSUSE-SU-2014:1622-1
Rating: critical
Affected Products: openSUSE Evergreen 11.4

Related News