flash-player was updated to fix two security issues. These security issues were fixed: - CVE-2015-5123: Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allowed remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function (bsc#937752). - CVE-2015-5122: Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allowed remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that leverages improper handling of the opaqueBackground property (bsc#937752). Patch Instructions:
#937752
Cross- CVE-2015-5122 CVE-2015-5123
Affected Products:
SUSE Linux Enterprise Workstation Extension 12
SUSE Linux Enterprise Desktop 12
https://www.suse.com/security/cve/CVE-2015-5122.html
https://www.suse.com/security/cve/CVE-2015-5123.html
https://bugzilla.suse.com/937752
Get the latest Linux and open source security news straight to your inbox.