Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

SUSE: 2014:1442-1 Important: Flash-Player Code Execution Risks

suse
Calendar Grey November 18, 2014
Scroller Suse
SUSE patches tackle 18 vulnerabilities in the flash-player, mitigating severe execution threats for its user base.
An update that fixes 18 vulnerabilities is now available

Summary

flash-player was updated to version 11.2.202.418 to fix 18 security issues: * Memory corruption vulnerabilities that could lead to code execution (CVE-2014-0576, CVE-2014-0581, CVE-2014-8440, CVE-2014-8441). * Use-after-free vulnerabilities that could lead to code execution (CVE-2014-0573, CVE-2014-0588, CVE-2014-8438). * A double free vulnerability that could lead to code execution (CVE-2014-0574). * Type confusion vulnerabilities that could lead to code execution (CVE-2014-0577, CVE-2014-0584, CVE-2014-0585, CVE-2014-0586, CVE-2014-0590). * Heap buffer overflow vulnerabilities that could lead to code execution (CVE-2014-0582, CVE-2014-0589). * An information disclosure vulnerability that could be exploited to disclose session tokens (CVE-2014-8437).

References

#905032

Cross- CVE-2014-0573 CVE-2014-0574 CVE-2014-0576

CVE-2014-0577 CVE-2014-0581 CVE-2014-0582

CVE-2014-0583 CVE-2014-0584 CVE-2014-0585

CVE-2014-0586 CVE-2014-0588 CVE-2014-0589

CVE-2014-0590 CVE-2014-8437 CVE-2014-8438

CVE-2014-8440 CVE-2014-8441 CVE-2014-8442

Affected Products:

SUSE Linux Enterprise Desktop 11 SP3

https://www.suse.com/security/cve/CVE-2014-0573.html

https://www.suse.com/security/cve/CVE-2014-0574.html

https://www.suse.com/security/cve/CVE-2014-0576.html

https://www.suse.com/security/cve/CVE-2014-0577.html

https://www.suse.com/security/cve/CVE-2014-0581.html

https://www.suse.com/security/cve/CVE-2014-0582.html

https://www.suse.com/security/cve/CVE-2014-0583.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:1442-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.