Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

SUSE: 2015:0723-1 Important: Flash Player Remote Code Exec Threat

suse
Calendar Grey April 16, 2015
Scroller Suse
SUSE Security Bulletin addresses vital Flash Player update to mitigate risks. Prompt measures are recommended for protection.
An update that fixes 22 vulnerabilities is now available

Summary

Adobe Flash Player was updated to version 11.2.202.457 to fix several security issues that could have lead to remote code execution. An exploit for CVE-2015-3043 was reported to exist in the wild. The following vulnerabilities have been fixed: * Memory corruption vulnerabilities that could have lead to code execution (CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, CVE-2015-3042, CVE-2015-3043). * Type confusion vulnerability that could have lead to code execution (CVE-2015-0356). * Buffer overflow vulnerability that could have lead to code execution (CVE-2015-0348). * Use-after-free vulnerabilities that could have lead to code execution (CVE-2015-0349, CVE-2015-0351, CVE-2015-0358, CVE-2015-3039).

References

#927089

Cross- CVE-2015-0346 CVE-2015-0347 CVE-2015-0348

CVE-2015-0349 CVE-2015-0350 CVE-2015-0351

CVE-2015-0352 CVE-2015-0353 CVE-2015-0354

CVE-2015-0355 CVE-2015-0356 CVE-2015-0357

CVE-2015-0358 CVE-2015-0359 CVE-2015-0360

CVE-2015-3038 CVE-2015-3039 CVE-2015-3040

CVE-2015-3041 CVE-2015-3042 CVE-2015-3043

CVE-2015-3044

Affected Products:

SUSE Linux Enterprise Desktop 11 SP3

https://www.suse.com/security/cve/CVE-2015-0346.html

https://www.suse.com/security/cve/CVE-2015-0347.html

https://www.suse.com/security/cve/CVE-2015-0348.html

https://www.suse.com/security/cve/CVE-2015-0349.html

https://www.suse.com/security/cve/CVE-2015-0350.html

https://www.suse.com/security/cve/CVE-2015-0351.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:0723-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.