Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 510
Alerts This Week
Warning Icon 1 510

openSUSE 13.2 Important: Adobe Flash Player Security Update

opensuse
Calendar Grey October 14, 2015
Scroller Opensuse
A significant patch for Adobe Flash Player on openSUSE addresses 13 severe vulnerabilities, among them a buffer overflow.
An update that fixes 13 vulnerabilities is now available

Description

Adobe Flash Player was updated to 11.2.202.535 to fix a number of security

issues. (boo#950169, APSB15-25)

The following vulnerabilities were fixed:

* CVE-2015-7628: Vulnerability that could be exploited to bypass the

same-origin-policy and lead to information disclosure

* CVE-2015-5569: Defense-in-depth feature in the Flash broker API

* CVE-2015-7629, CVE-2015-7631, CVE-2015-7643, CVE-2015-7644:

Use-after-free vulnerabilities that could lead to code execution

* CVE-2015-7632: Buffer overflow vulnerability that could lead to code

execution

* CVE-2015-7625, CVE-2015-7626, CVE-2015-7627, CVE-2015-7630,

CVE-2015-7633, CVE-2015-7634: Memory corruption vulnerabilities that

could lead to code execution

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 13.2:NonFree:

zypper in -t patch openSUSE-2015-656=1

- openSUSE 13.1:NonFree:

zypper in -t patch openSUSE-2015-656=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 13.2:NonFree (i586 x86_64):

flash-player-11.2.202.535-2.73.2

flash-player-gnome-11.2.202.535-2.73.2

flash-player-kde4-11.2.202.535-2.73.2

- openSUSE 13.1:NonFree (i586 x86_64):

flash-player-11.2.202.535-138.2

flash-player-gnome-11.2.202.535-138.2

flash-player-kde4-11.2.202.535-138.2

References

https://www.suse.com/security/cve/CVE-2015-5569.html

https://www.suse.com/security/cve/CVE-2015-7625.html

https://www.suse.com/security/cve/CVE-2015-7626.html

https://www.suse.com/security/cve/CVE-2015-7627.html

https://www.suse.com/security/cve/CVE-2015-7628.html

https://www.suse.com/security/cve/CVE-2015-7629.html

https://www.suse.com/security/cve/CVE-2015-7630.html

https://www.suse.com/security/cve/CVE-2015-7631.html

https://www.suse.com/security/cve/CVE-2015-7632.html

https://www.suse.com/security/cve/CVE-2015-7633.html

https://www.suse.com/security/cve/CVE-2015-7634.html

https://www.suse.com/security/cve/CVE-2015-7643.html

https://www.suse.com/security/cve/CVE-2015-7644.html

https://bugzilla.suse.com/show_bug.cgi?id=950169

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2015:1744-1
Rating: important
Affected Products: openSUSE 13.2:NonFree openSUSE 13.1:NonFree .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.