SUSE-SU-2015:1742-1
Dashboard / Vulnerabilities / SUSE-SU-2015:1742-1
SUSE-SU-2015:1742-1
Summary: Security update for flash-player
Details: flash-player was updated to version 11.2.202.535 to fix 13 security issues (bsc#950169). These security issues were fixed: - A vulnerability that could be exploited to bypass the same-origin-policy and lead to information disclosure (CVE-2015-7628). - A defense-in-depth feature in the Flash broker API (CVE-2015-5569). - Use-after-free vulnerabilities that could lead to code execution (CVE-2015-7629, CVE-2015-7631, CVE-2015-7643, CVE-2015-7644). - A buffer overflow vulnerability that could lead to code execution (CVE-2015-7632). - Memory corruption vulnerabilities that could lead to code execution (CVE-2015-7625, CVE-2015-7626, CVE-2015-7627, CVE-2015-7630, CVE-2015-7633, CVE-2015-7634).
References: https://www.suse.com/support/update/announcement/2015/suse-su-20151742-1/, https://bugzilla.suse.com/950169, https://www.suse.com/security/cve/CVE-2015-5569, https://www.suse.com/security/cve/CVE-2015-7625, https://www.suse.com/security/cve/CVE-2015-7626, https://www.suse.com/security/cve/CVE-2015-7627, https://www.suse.com/security/cve/CVE-2015-7628, https://www.suse.com/security/cve/CVE-2015-7629, https://www.suse.com/security/cve/CVE-2015-7630, https://www.suse.com/security/cve/CVE-2015-7631, https://www.suse.com/security/cve/CVE-2015-7632, https://www.suse.com/security/cve/CVE-2015-7633, https://www.suse.com/security/cve/CVE-2015-7634, https://www.suse.com/security/cve/CVE-2015-7643, https://www.suse.com/security/cve/CVE-2015-7644
Affected packages
Package
Name: flash-player
Purl: pkg:rpm/suse/flash-player&distro=SUSE%20Linux%20Enterprise%20Desktop%2011%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
