An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for libqt5-qtvirtualkeyboard ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:1259-1 Rating: moderate References: #1118593 Cross-References: CVE-2018-19865 Affected Products: openSUSE Leap 15.0 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libqt5-qtvirtualkeyboard fixes the following issues: Security issue fixed: - CVE-2018-19865: Fixed an issue with verbose keypress logging (boo#1118593). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.0: zypper in -t patch openSUSE-2019-1259=1 Package List: - openSUSE Leap 15.0 (x86_64): libqt5-qtvirtualkeyboard-5.9.4-lp150.2.3.1 libqt5-qtvirtualkeyboard-debuginfo-5.9.4-lp150.2.3.1 libqt5-qtvirtualkeyboard-debugsource-5.9.4-lp150.2.3.1 libqt5-qtvirtualkeyboard-devel-5.9.4-lp150.2.3.1 libqt5-qtvirtualkeyboard-examples-5.9.4-lp150.2.3.1 libqt5-qtvirtualkeyboard-examples-debuginfo-5.9.4-lp150.2.3.1 References: https://www.suse.com/security/cve/CVE-2018-19865.html https://bugzilla.suse.com/1118593 -- . openSUSE Security Patch for libqt5-qtvirtualkeyboard resolves key input tracking vulnerability (CVE-2018-19865) successfully.. openSUSE Update, Linux Security, Keylogging Fix, libqt5 Security, Vulnerability Management. . LinuxSecurity.com Team
The package flashplugin before version 11.2.202.440-1 is vulnerable to multiple issues including remote code execution, denial of service, keylogging and memory leaks. . Arch Linux Security Advisory ASA-201501-22 ========================================= Severity: Critical Date : 2015-01-23 CVE-ID : CVE-2015-0311 CVE-2015-0301 CVE-2015-0302 CVE-2015-0303 CVE-2015-0304 CVE-2015-0305 CVE-2015-0306 CVE-2015-0307 CVE-2015-0308 CVE-2015-0309 Package : flashplugin Type : multiple issues Remote : Yes Link : https://wiki.archlinux.org/title/CVE Summary ====== The package flashplugin before version 11.2.202.440-1 is vulnerable to multiple issues including remote code execution, denial of service, keylogging and memory leaks. Resolution ========= Upgrade to 11.2.202.440-1. # pacman -Syu "flashplugin> =11.2.202.440-1" The problems have been fixed upstream in version 11.2.202.440. Workaround ========= None. Description ========== - CVE-2015-0311 (remote code execution) Unspecified vulnerability allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in January 2015. - CVE-2015-0309 (remote code execution) Heap-based buffer overflow allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0304. - CVE-2015-0308 (remote code execution) Use-after-free vulnerability allows attackers to execute arbitrary code via unspecified vectors. - CVE-2015-0307 (memory leaks, denial of service) A vulnerability allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via unspecified vectors. - CVE-2015-0306 (remote code execution, denial of service) A vulnerability allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0303. - CVE-2015-0305 (remote code execution) Avulnerability allows attackers to execute arbitrary code by leveraging an unspecified "type confusion". - CVE-2015-0304 (remote code execution) Heap-based buffer overflow allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0309. - CVE-2015-0303 (remote code execution, denial of service) A vulnerability allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0306. - CVE-2015-0302 (keylogging) A vulnerability allows attackers to obtain sensitive keystroke information via unspecified vectors. - CVE-2015-0301 (file validation) The flashplugin does not properly validate files, which has unspecified impact and attack vectors. Impact ===== A remote attacker is able to perform remote code execution, keylogging, denial of service and resource consumption through memory leaks. References ========= https://malware.dontneedcoffee.com/2015/01/unpatched-vulnerability-0day-in-flash.html http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0311 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0309 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0308 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0307 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0306 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0305 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0304 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0303 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0302 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0301 . Urgent security vulnerabilities in Flash Plugin on Arch Linux necessitate swift remediation to avert potential remote code execution and keystroke capture.. Arch Linux Flashplugin Issues, Remote Code Execution Risks, Security Advisory for Flashplugin. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.