Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: 2015:0239-1 Important: Flash Player Security Vulnerabilities

suse
Calendar Grey February 7, 2015
Dist Suse Esm H88
SUSE Security Alert: urgent updates for flash-player tackling various vulnerabilities along with recommended procedures.
An update that fixes 18 vulnerabilities is now available

Summary

flash-player was updated to version 11.2.202.442 to fix 18 security issues. These security issues were fixed: - Use-after-free vulnerabilities that could lead to code execution (CVE-2015-0313, CVE-2015-0315, CVE-2015-0320, CVE-2015-0322). - Memory corruption vulnerabilities that could lead to code execution (CVE-2015-0314, CVE-2015-0316, CVE-2015-0318, CVE-2015-0321, CVE-2015-0329, CVE-2015-0330). - Type confusion vulnerabilities that could lead to code execution (CVE-2015-0317, CVE-2015-0319). - Heap buffer overflow vulnerabilities that could lead to code execution (CVE-2015-0323, CVE-2015-0327). - Buffer overflow vulnerability that could lead to code execution (CVE-2015-0324). - Null pointer dereference issues (CVE-2015-0325, CVE-2015-0326, CVE-2015-0328).

References

#915918

Cross- CVE-2015-0313 CVE-2015-0314 CVE-2015-0315

CVE-2015-0316 CVE-2015-0317 CVE-2015-0318

CVE-2015-0319 CVE-2015-0320 CVE-2015-0321

CVE-2015-0322 CVE-2015-0323 CVE-2015-0324

CVE-2015-0325 CVE-2015-0326 CVE-2015-0327

CVE-2015-0328 CVE-2015-0329 CVE-2015-0330

Affected Products:

SUSE Linux Enterprise Desktop 11 SP3

https://www.suse.com/security/cve/CVE-2015-0313.html

https://www.suse.com/security/cve/CVE-2015-0314.html

https://www.suse.com/security/cve/CVE-2015-0315.html

https://www.suse.com/security/cve/CVE-2015-0316.html

https://www.suse.com/security/cve/CVE-2015-0317.html

https://www.suse.com/security/cve/CVE-2015-0318.html

https://www.suse.com/security/cve/CVE-2015-0319.html

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:0239-1
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here