Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

SUSE 11-SP4 & 11-SP3: 2015:2402-1 Critical Threat to Flash Player Execution

suse
Calendar Grey December 30, 2015
Scroller Suse
Critical SUSE Security Patch released for flash-player addressing various vulnerabilities that impact desktop editions.
An update that fixes 19 vulnerabilities is now available

Summary

This update for flash-player fixes the following issues: - CVE-2015-8644: Type confusion vulnerability that could lead to code execution. - CVE-2015-8651: Integer overflow vulnerability that could lead to code execution. - CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, CVE-2015-8650: Use-after-free vulnerabilities that could lead to code execution. - CVE-2015-8459, CVE-2015-8460, CVE-2015-8636, CVE-2015-8645: Memory corruption vulnerabilities that could lead to code execution. Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product:

References

#960317

Cross- CVE-2015-8459 CVE-2015-8460 CVE-2015-8634

CVE-2015-8635 CVE-2015-8636 CVE-2015-8638

CVE-2015-8639 CVE-2015-8640 CVE-2015-8641

CVE-2015-8642 CVE-2015-8643 CVE-2015-8644

CVE-2015-8645 CVE-2015-8646 CVE-2015-8647

CVE-2015-8648 CVE-2015-8649 CVE-2015-8650

CVE-2015-8651

Affected Products:

SUSE Linux Enterprise Desktop 11-SP4

SUSE Linux Enterprise Desktop 11-SP3

https://www.suse.com/security/cve/CVE-2015-8459.html

https://www.suse.com/security/cve/CVE-2015-8460.html

https://www.suse.com/security/cve/CVE-2015-8634.html

https://www.suse.com/security/cve/CVE-2015-8635.html

https://www.suse.com/security/cve/CVE-2015-8636.html

https://www.suse.com/security/cve/CVE-2015-8638.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:2402-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.