Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

SUSE: 2015:0489-1 High: Java Runtime File Handling Issues

suse
Calendar Grey March 13, 2015
Dist Suse Esm H88
A patch rollout addresses 11 significant vulnerabilities in Flash Player for SUSE Linux. Make sure to adhere to the guidelines to apply the required updates.
An update that fixes 11 vulnerabilities is now available

Summary

Adobe Flash Player was updated to 11.2.202.451 (bsc#922033). These security issues were fixed: - Memory corruption vulnerabilities that could lead to code execution (CVE-2016-0332, CVE-2015-0333, CVE-2015-0335, CVE-2015-0339). - Type confusion vulnerabilities that could lead to code execution (CVE-2015-0334, CVE-2015-0336). - A vulnerability that could lead to a cross-domain policy bypass (CVE-2015-0337). - A vulnerability that could lead to a file upload restriction bypass (CVE-2015-0340). - An integer overflow vulnerability that could lead to code execution (CVE-2015-0338). - Use-after-free vulnerabilities that could lead to code execution (CVE-2015-0341, CVE-2015-0342). Patch Instructions: To install this SUSE Security Update use YaST online_update.

References

#922033

Cross- CVE-2015-0333 CVE-2015-0334 CVE-2015-0335

CVE-2015-0336 CVE-2015-0337 CVE-2015-0338

CVE-2015-0339 CVE-2015-0340 CVE-2015-0341

CVE-2015-0342 CVE-2016-0332

Affected Products:

SUSE Linux Enterprise Workstation Extension 12

SUSE Linux Enterprise Desktop 12

https://www.suse.com/security/cve/CVE-2015-0333.html

https://www.suse.com/security/cve/CVE-2015-0334.html

https://www.suse.com/security/cve/CVE-2015-0335.html

https://www.suse.com/security/cve/CVE-2015-0336.html

https://www.suse.com/security/cve/CVE-2015-0337.html

https://www.suse.com/security/cve/CVE-2015-0338.html

https://www.suse.com/security/cve/CVE-2015-0339.html

https://www.suse.com/security/cve/CVE-2015-0340.html

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:0491-1
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here