Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

SUSE Linux 12: 2015:1255-1 Critical: Flash Player Remote Code Execution

suse
Calendar Grey July 17, 2015
Dist Suse Esm H88
Debian patch resolves major vulnerabilities in video-player. Safeguard your device by installing this vital update.
An update that fixes two vulnerabilities is now available

Summary

flash-player was updated to fix two security issues. These security issues were fixed: - CVE-2015-5123: Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allowed remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function (bsc#937752). - CVE-2015-5122: Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allowed remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that leverages improper handling of the opaqueBackground property (bsc#937752). Patch Instructions:

References

#937752

Cross- CVE-2015-5122 CVE-2015-5123

Affected Products:

SUSE Linux Enterprise Workstation Extension 12

SUSE Linux Enterprise Desktop 12

https://www.suse.com/security/cve/CVE-2015-5122.html

https://www.suse.com/security/cve/CVE-2015-5123.html

https://bugzilla.suse.com/937752

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:1255-1
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here