Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

SUSE: SUSE-SU-2015:1043-1 Important: Flash-Player Code Execution

suse
Calendar Grey June 11, 2015
Scroller Suse
Important security patch for flash-player addresses various vulnerabilities in SUSE environments. Adhere to guidelines to update your systems.
An update that fixes 11 vulnerabilities is now available

Summary

The following issues are fixed by this updated: * CVE-2015-3096: These updates resolve a vulnerability that could be exploited to bypass the fix for CVE-2014-5333. * CVE-2015-3098, CVE-2015-3099, CVE-2015-3102:These updates resolve vulnerabilities that could be exploited to bypass the same-origin-policy and lead to information disclosure. * CVE-2015-3100: These updates resolve a stack overflow vulnerability that could lead to code execution. * CVE-2015-3103, CVE-2015-3106, CVE-2015-3107: These updates resolve use-after-free vulnerabilities that could lead to code execution. * CVE-2015-3104: These updates resolve an integer overflow vulnerability that could lead to code execution. * CVE-2015-3105: These updates resolve a memory corruption vulnerability that could lead to code execution.

References

#934088

Cross- CVE-2015-3096 CVE-2015-3098 CVE-2015-3099

CVE-2015-3100 CVE-2015-3102 CVE-2015-3103

CVE-2015-3104 CVE-2015-3105 CVE-2015-3106

CVE-2015-3107 CVE-2015-3108

Affected Products:

SUSE Linux Enterprise Workstation Extension 12

SUSE Linux Enterprise Desktop 12

https://www.suse.com/security/cve/CVE-2015-3096.html

https://www.suse.com/security/cve/CVE-2015-3098.html

https://www.suse.com/security/cve/CVE-2015-3099.html

https://www.suse.com/security/cve/CVE-2015-3100.html

https://www.suse.com/security/cve/CVE-2015-3102.html

https://www.suse.com/security/cve/CVE-2015-3103.html

https://www.suse.com/security/cve/CVE-2015-3104.html

https://www.suse.com/security/cve/CVE-2015-3105.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:1043-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.