Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

SUSE Linux 11-SP4: 2015:1258-1 Critical Flash Player Memory Issues

suse
Calendar Grey July 17, 2015
Dist Suse Esm H88
Important SUSE flash-player patch resolves two significant vulnerabilities. Installation instructions and impacted products are provided.
An update that fixes two vulnerabilities is now available

Summary

flash-player was updated to fix two security issues. These security issues were fixed: - CVE-2015-5123: Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allowed remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function (bsc#937752). - CVE-2015-5122: Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allowed remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that leverages improper handling of the opaqueBackground property (bsc#937752). Patch Instructions:

References

#937752

Cross- CVE-2015-5122 CVE-2015-5123

Affected Products:

SUSE Linux Enterprise Desktop 11-SP4

SUSE Linux Enterprise Desktop 11-SP3

https://www.suse.com/security/cve/CVE-2015-5122.html

https://www.suse.com/security/cve/CVE-2015-5123.html

https://bugzilla.suse.com/937752

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:1258-1
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here