openSUSE Security Update: Security update for Adobe Flash Player
______________________________________________________________________________

Announcement ID:    openSUSE-SU-2015:0718-1
Rating:             important
References:         #927089 
Cross-References:   CVE-2015-0346 CVE-2015-0347 CVE-2015-0348
                    CVE-2015-0349 CVE-2015-0350 CVE-2015-0351
                    CVE-2015-0352 CVE-2015-0353 CVE-2015-0354
                    CVE-2015-0355 CVE-2015-0356 CVE-2015-0357
                    CVE-2015-0358 CVE-2015-0359 CVE-2015-0360
                    CVE-2015-3038 CVE-2015-3039 CVE-2015-3040
                    CVE-2015-3041 CVE-2015-3042 CVE-2015-3043
                    CVE-2015-3044
Affected Products:
                    openSUSE 13.2:NonFree
                    openSUSE 13.1:NonFree
______________________________________________________________________________

   An update that fixes 22 vulnerabilities is now available.

Description:

   Adobe Flash Player was updated to 11.2.202.457 to fix several security
   issues that could lead to remote code execution.

   An exploit for CVE-2015-3043 was reported to exist in the wild.

   The following vulnerabilities were fixed:

   * Memory corruption vulnerabilities that could lead to code execution
     (CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353,
     CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038,
     CVE-2015-3041, CVE-2015-3042, CVE-2015-3043).
   * Type confusion vulnerability that could lead to code execution
     (CVE-2015-0356).
   * Buffer overflow vulnerability that could lead to code execution
     (CVE-2015-0348).
   * Use-after-free vulnerabilities that could lead to code execution
     (CVE-2015-0349, CVE-2015-0351, CVE-2015-0358, CVE-2015-3039).
   * Double-free vulnerabilities that could lead to code execution
     (CVE-2015-0346, CVE-2015-0359).
   * Memory leak vulnerabilities that could be used to bypass ASLR
     (CVE-2015-0357, CVE-2015-3040).
   * Security bypass vulnerability that could lead to information disclosure
     (CVE-2015-3044).


Patch Instructions:

   To install this openSUSE Security Update use YaST online_update.
   Alternatively you can run the command listed for your product:

   - openSUSE 13.2:NonFree:

      zypper in -t patch openSUSE-2015-304=1

   - openSUSE 13.1:NonFree:

      zypper in -t patch openSUSE-2015-304=1

   To bring your system up-to-date, use "zypper patch".


Package List:

   - openSUSE 13.2:NonFree (i586 x86_64):

      flash-player-11.2.202.457-2.48.1
      flash-player-gnome-11.2.202.457-2.48.1
      flash-player-kde4-11.2.202.457-2.48.1

   - openSUSE 13.1:NonFree (i586 x86_64):

      flash-player-11.2.202.457-113.1
      flash-player-gnome-11.2.202.457-113.1
      flash-player-kde4-11.2.202.457-113.1


References:

   https://www.suse.com/security/cve/CVE-2015-0346.html
   https://www.suse.com/security/cve/CVE-2015-0347.html
   https://www.suse.com/security/cve/CVE-2015-0348.html
   https://www.suse.com/security/cve/CVE-2015-0349.html
   https://www.suse.com/security/cve/CVE-2015-0350.html
   https://www.suse.com/security/cve/CVE-2015-0351.html
   https://www.suse.com/security/cve/CVE-2015-0352.html
   https://www.suse.com/security/cve/CVE-2015-0353.html
   https://www.suse.com/security/cve/CVE-2015-0354.html
   https://www.suse.com/security/cve/CVE-2015-0355.html
   https://www.suse.com/security/cve/CVE-2015-0356.html
   https://www.suse.com/security/cve/CVE-2015-0357.html
   https://www.suse.com/security/cve/CVE-2015-0358.html
   https://www.suse.com/security/cve/CVE-2015-0359.html
   https://www.suse.com/security/cve/CVE-2015-0360.html
   https://www.suse.com/security/cve/CVE-2015-3038.html
   https://www.suse.com/security/cve/CVE-2015-3039.html
   https://www.suse.com/security/cve/CVE-2015-3040.html
   https://www.suse.com/security/cve/CVE-2015-3041.html
   https://www.suse.com/security/cve/CVE-2015-3042.html
   https://www.suse.com/security/cve/CVE-2015-3043.html
   https://www.suse.com/security/cve/CVE-2015-3044.html
   https://bugzilla.suse.com/927089

openSUSE: 2015:0718-1: important: Adobe Flash Player

April 15, 2015
An update that fixes 22 vulnerabilities is now available

Description

Adobe Flash Player was updated to 11.2.202.457 to fix several security issues that could lead to remote code execution. An exploit for CVE-2015-3043 was reported to exist in the wild. The following vulnerabilities were fixed: * Memory corruption vulnerabilities that could lead to code execution (CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, CVE-2015-3042, CVE-2015-3043). * Type confusion vulnerability that could lead to code execution (CVE-2015-0356). * Buffer overflow vulnerability that could lead to code execution (CVE-2015-0348). * Use-after-free vulnerabilities that could lead to code execution (CVE-2015-0349, CVE-2015-0351, CVE-2015-0358, CVE-2015-3039). * Double-free vulnerabilities that could lead to code execution (CVE-2015-0346, CVE-2015-0359). * Memory leak vulnerabilities that could be used to bypass ASLR (CVE-2015-0357, CVE-2015-3040). * Security bypass vulnerability that could lead to information disclosure (CVE-2015-3044).

 

Patch

Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE 13.2:NonFree: zypper in -t patch openSUSE-2015-304=1 - openSUSE 13.1:NonFree: zypper in -t patch openSUSE-2015-304=1 To bring your system up-to-date, use "zypper patch".


Package List

- openSUSE 13.2:NonFree (i586 x86_64): flash-player-11.2.202.457-2.48.1 flash-player-gnome-11.2.202.457-2.48.1 flash-player-kde4-11.2.202.457-2.48.1 - openSUSE 13.1:NonFree (i586 x86_64): flash-player-11.2.202.457-113.1 flash-player-gnome-11.2.202.457-113.1 flash-player-kde4-11.2.202.457-113.1


References

https://www.suse.com/security/cve/CVE-2015-0346.html https://www.suse.com/security/cve/CVE-2015-0347.html https://www.suse.com/security/cve/CVE-2015-0348.html https://www.suse.com/security/cve/CVE-2015-0349.html https://www.suse.com/security/cve/CVE-2015-0350.html https://www.suse.com/security/cve/CVE-2015-0351.html https://www.suse.com/security/cve/CVE-2015-0352.html https://www.suse.com/security/cve/CVE-2015-0353.html https://www.suse.com/security/cve/CVE-2015-0354.html https://www.suse.com/security/cve/CVE-2015-0355.html https://www.suse.com/security/cve/CVE-2015-0356.html https://www.suse.com/security/cve/CVE-2015-0357.html https://www.suse.com/security/cve/CVE-2015-0358.html https://www.suse.com/security/cve/CVE-2015-0359.html https://www.suse.com/security/cve/CVE-2015-0360.html https://www.suse.com/security/cve/CVE-2015-3038.html https://www.suse.com/security/cve/CVE-2015-3039.html https://www.suse.com/security/cve/CVE-2015-3040.html https://www.suse.com/security/cve/CVE-2015-3041.html https://www.suse.com/security/cve/CVE-2015-3042.html https://www.suse.com/security/cve/CVE-2015-3043.html https://www.suse.com/security/cve/CVE-2015-3044.html https://bugzilla.suse.com/927089


Severity
Announcement ID: openSUSE-SU-2015:0718-1
Rating: important
Affected Products: openSUSE 13.2:NonFree openSUSE 13.1:NonFree .

Related News