SUSE-SU-2015:0722-1
Dashboard / Vulnerabilities / SUSE-SU-2015:0722-1
SUSE-SU-2015:0722-1
Summary: Security update for Adobe Flash Player
Details: Adobe Flash Player was updated to 11.2.202.457 to fix several security issues that could lead to remote code execution. An exploit for CVE-2015-3043 was reported to exist in the wild. The following vulnerabilities were fixed: * Memory corruption vulnerabilities that could lead to code execution (CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, CVE-2015-3042, CVE-2015-3043). * Type confusion vulnerability that could lead to code execution (CVE-2015-0356). * Buffer overflow vulnerability that could lead to code execution (CVE-2015-0348). * Use-after-free vulnerabilities that could lead to code execution (CVE-2015-0349, CVE-2015-0351, CVE-2015-0358, CVE-2015-3039). * Double-free vulnerabilities that could lead to code execution (CVE-2015-0346, CVE-2015-0359). * Memory leak vulnerabilities that could be used to bypass ASLR (CVE-2015-0357, CVE-2015-3040). * Security bypass vulnerability that could lead to information disclosure (CVE-2015-3044).
References: https://www.suse.com/support/update/announcement/2015/suse-su-20150722-1/, https://bugzilla.suse.com/927089, https://www.suse.com/security/cve/CVE-2015-0346, https://www.suse.com/security/cve/CVE-2015-0347, https://www.suse.com/security/cve/CVE-2015-0348, https://www.suse.com/security/cve/CVE-2015-0349, https://www.suse.com/security/cve/CVE-2015-0350, https://www.suse.com/security/cve/CVE-2015-0351, https://www.suse.com/security/cve/CVE-2015-0352, https://www.suse.com/security/cve/CVE-2015-0353, https://www.suse.com/security/cve/CVE-2015-0354, https://www.suse.com/security/cve/CVE-2015-0355, https://www.suse.com/security/cve/CVE-2015-0356, https://www.suse.com/security/cve/CVE-2015-0357, https://www.suse.com/security/cve/CVE-2015-0358, https://www.suse.com/security/cve/CVE-2015-0359, https://www.suse.com/security/cve/CVE-2015-0360, https://www.suse.com/security/cve/CVE-2015-3038, https://www.suse.com/security/cve/CVE-2015-3039, https://www.suse.com/security/cve/CVE-2015-3040, https://www.suse.com/security/cve/CVE-2015-3041, https://www.suse.com/security/cve/CVE-2015-3042, https://www.suse.com/security/cve/CVE-2015-3043, https://www.suse.com/security/cve/CVE-2015-3044
Affected packages
Package
Name: flash-player
Purl: pkg:rpm/suse/flash-player&distro=SUSE%20Linux%20Enterprise%20Desktop%2012
Affected ranges
Type: ECOSYSTEM
Events:
