Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

SUSE: 2015:0236-1 Critical: Flash Player Code Execution Risks

suse
Calendar Grey February 7, 2015
Dist Suse Esm H88
SUSE Security Update 2015-0236-1 addresses critical flaws in flash-player, fixing 18 vulnerabilities with solutions.
An update that fixes 18 vulnerabilities is now available

Summary

flash-player was updated to version 11.2.202.442 to fix 18 security issues. These security issues were fixed: - Use-after-free vulnerabilities that could lead to code execution (CVE-2015-0313, CVE-2015-0315, CVE-2015-0320, CVE-2015-0322). - Memory corruption vulnerabilities that could lead to code execution (CVE-2015-0314, CVE-2015-0316, CVE-2015-0318, CVE-2015-0321, CVE-2015-0329, CVE-2015-0330). - Type confusion vulnerabilities that could lead to code execution (CVE-2015-0317, CVE-2015-0319). - Heap buffer overflow vulnerabilities that could lead to code execution (CVE-2015-0323, CVE-2015-0327). - Buffer overflow vulnerability that could lead to code execution (CVE-2015-0324). - Null pointer dereference issues (CVE-2015-0325, CVE-2015-0326, CVE-2015-0328).

References

#915918

Cross- CVE-2015-0313 CVE-2015-0314 CVE-2015-0315

CVE-2015-0316 CVE-2015-0317 CVE-2015-0318

CVE-2015-0319 CVE-2015-0320 CVE-2015-0321

CVE-2015-0322 CVE-2015-0323 CVE-2015-0324

CVE-2015-0325 CVE-2015-0326 CVE-2015-0327

CVE-2015-0328 CVE-2015-0329 CVE-2015-0330

Affected Products:

SUSE Linux Enterprise Workstation Extension 12

SUSE Linux Enterprise Desktop 12

https://www.suse.com/security/cve/CVE-2015-0313.html

https://www.suse.com/security/cve/CVE-2015-0314.html

https://www.suse.com/security/cve/CVE-2015-0315.html

https://www.suse.com/security/cve/CVE-2015-0316.html

https://www.suse.com/security/cve/CVE-2015-0317.html

https://www.suse.com/security/cve/CVE-2015-0318.html

https://www.suse.com/security/cve/CVE-2015-0319.html

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:0236-1
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here