Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

openSUSE: 2015:2239-1 Important: Flash Player Code Execution Risk

opensuse
Calendar Grey December 10, 2015
Scroller Opensuse
The security update for Flash Player on openSUSE addresses 75 vulnerabilities. A significant patch has been released including CVE identifiers.
An update that fixes 77 vulnerabilities is now available

Description

This update for flash-player to version 11.2.202.554 fixes the following

security issues in Adobe security advisory APSB15-32.

* These updates resolve heap buffer overflow vulnerabilities that could

lead to code execution (CVE-2015-8438, CVE-2015-8446).

* These updates resolve memory corruption vulnerabilities that could lead

to code execution (CVE-2015-8444, CVE-2015-8443, CVE-2015-8417,

CVE-2015-8416, CVE-2015-8451, CVE-2015-8047, CVE-2015-8455,

CVE-2015-8045, CVE-2015-8418, CVE-2015-8060, CVE-2015-8419,

CVE-2015-8408).

* These updates resolve security bypass vulnerabilities (CVE-2015-8453,

CVE-2015-8440, CVE-2015-8409).

* These updates resolve a stack overflow vulnerability that could lead to

code execution (CVE-2015-8407).

* These updates resolve a type confusion vulnerability that could lead to

code execution (CVE-2015-8439).

* These updates resolve an integer overflow vulnerability that could lead

to code...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 13.2 NonFree:

zypper in -t patch openSUSE-2015-882=1

- openSUSE 13.1 NonFree:

zypper in -t patch openSUSE-2015-882=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 13.2 NonFree (i586 x86_64):

flash-player-11.2.202.554-2.82.1

flash-player-gnome-11.2.202.554-2.82.1

flash-player-kde4-11.2.202.554-2.82.1

- openSUSE 13.1 NonFree (i586 x86_64):

flash-player-11.2.202.554-147.1

flash-player-gnome-11.2.202.554-147.1

flash-player-kde4-11.2.202.554-147.1

References

https://www.suse.com/security/cve/CVE-2015-8045.html

https://www.suse.com/security/cve/CVE-2015-8047.html

https://www.suse.com/security/cve/CVE-2015-8048.html

https://www.suse.com/security/cve/CVE-2015-8049.html

https://www.suse.com/security/cve/CVE-2015-8050.html

https://www.suse.com/security/cve/CVE-2015-8055.html

https://www.suse.com/security/cve/CVE-2015-8056.html

https://www.suse.com/security/cve/CVE-2015-8057.html

https://www.suse.com/security/cve/CVE-2015-8058.html

https://www.suse.com/security/cve/CVE-2015-8059.html

https://www.suse.com/security/cve/CVE-2015-8060.html

https://www.suse.com/security/cve/CVE-2015-8061.html

https://www.suse.com/security/cve/CVE-2015-8062.html

https://www.suse.com/security/cve/CVE-2015-8063.html

https://www.suse.com/security/cve/CVE-2015-8064.html

https://www.suse.com/security/cve/CVE-2015-8065.html

https://www.suse.com/security/cve/CVE-2015-8066.html

https://www.suse.com/security/cve/CVE-2015-8067.html

https://www.suse.com/security/cve/CVE-2015-8068.html

https://www....

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2015:2239-1
Rating: important
Affected Products: openSUSE 13.2 NonFree openSUSE 13.1 NonFree .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.