Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2015:1614-1

Опубликовано: 22 сент. 2015
Источник: suse-cvrf

Описание

Security update for flash-player

Adobe Flash Player was updated to 11.2.202.521 (APSB15-23 bsc#946880) fixing several security issues:

More information can be found on:

https://helpx.adobe.com/security/products/flash-player/apsb15-23.html

Список пакетов

SUSE Linux Enterprise Desktop 11 SP3
flash-player-11.2.202.521-0.17.1
flash-player-gnome-11.2.202.521-0.17.1
flash-player-kde4-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP4
flash-player-11.2.202.521-0.17.1
flash-player-gnome-11.2.202.521-0.17.1
flash-player-kde4-11.2.202.521-0.17.1

Ссылки

Описание

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5579.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:flash-player-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-gnome-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-kde4-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP4:flash-player-11.2.202.521-0.17.1

Ссылки

Описание

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to cause a denial of service (vector-length corruption) or possibly have unspecified other impact via unknown vectors.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:flash-player-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-gnome-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-kde4-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP4:flash-player-11.2.202.521-0.17.1

Ссылки

Описание

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5574, CVE-2015-5581, CVE-2015-5584, and CVE-2015-6682.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:flash-player-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-gnome-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-kde4-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP4:flash-player-11.2.202.521-0.17.1

Ссылки

Описание

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API. NOTE: this issue exists because of an incomplete fix for CVE-2014-4671 and CVE-2014-5333.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:flash-player-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-gnome-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-kde4-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP4:flash-player-11.2.202.521-0.17.1

Ссылки

Описание

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:flash-player-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-gnome-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-kde4-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP4:flash-player-11.2.202.521-0.17.1

Ссылки

Описание

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execute arbitrary code by leveraging an unspecified "type confusion."


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:flash-player-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-gnome-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-kde4-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP4:flash-player-11.2.202.521-0.17.1

Ссылки

Описание

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5570, CVE-2015-5581, CVE-2015-5584, and CVE-2015-6682.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:flash-player-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-gnome-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-kde4-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP4:flash-player-11.2.202.521-0.17.1

Ссылки

Описание

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5577, CVE-2015-5578, CVE-2015-5580, CVE-2015-5582, CVE-2015-5588, and CVE-2015-6677.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:flash-player-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-gnome-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-kde4-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP4:flash-player-11.2.202.521-0.17.1

Ссылки

Описание

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 do not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:flash-player-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-gnome-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-kde4-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP4:flash-player-11.2.202.521-0.17.1

Ссылки

Описание

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5575, CVE-2015-5578, CVE-2015-5580, CVE-2015-5582, CVE-2015-5588, and CVE-2015-6677.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:flash-player-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-gnome-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-kde4-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP4:flash-player-11.2.202.521-0.17.1

Ссылки

Описание

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5575, CVE-2015-5577, CVE-2015-5580, CVE-2015-5582, CVE-2015-5588, and CVE-2015-6677.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:flash-player-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-gnome-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-kde4-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP4:flash-player-11.2.202.521-0.17.1

Ссылки

Описание

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5567.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:flash-player-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-gnome-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-kde4-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP4:flash-player-11.2.202.521-0.17.1

Ссылки

Описание

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5575, CVE-2015-5577, CVE-2015-5578, CVE-2015-5582, CVE-2015-5588, and CVE-2015-6677.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:flash-player-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-gnome-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-kde4-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP4:flash-player-11.2.202.521-0.17.1

Ссылки

Описание

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5570, CVE-2015-5574, CVE-2015-5584, and CVE-2015-6682.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:flash-player-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-gnome-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-kde4-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP4:flash-player-11.2.202.521-0.17.1

Ссылки

Описание

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5575, CVE-2015-5577, CVE-2015-5578, CVE-2015-5580, CVE-2015-5588, and CVE-2015-6677.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:flash-player-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-gnome-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-kde4-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP4:flash-player-11.2.202.521-0.17.1

Ссылки

Описание

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5570, CVE-2015-5574, CVE-2015-5581, and CVE-2015-6682.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:flash-player-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-gnome-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-kde4-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP4:flash-player-11.2.202.521-0.17.1

Ссылки

Описание

Stack-based buffer overflow in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:flash-player-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-gnome-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-kde4-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP4:flash-player-11.2.202.521-0.17.1

Ссылки

Описание

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5575, CVE-2015-5577, CVE-2015-5578, CVE-2015-5580, CVE-2015-5582, and CVE-2015-6677.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:flash-player-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-gnome-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-kde4-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP4:flash-player-11.2.202.521-0.17.1

Ссылки

Описание

Buffer overflow in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-6678.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:flash-player-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-gnome-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-kde4-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP4:flash-player-11.2.202.521-0.17.1

Ссылки

Описание

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5575, CVE-2015-5577, CVE-2015-5578, CVE-2015-5580, CVE-2015-5582, and CVE-2015-5588.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:flash-player-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-gnome-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-kde4-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP4:flash-player-11.2.202.521-0.17.1

Ссылки

Описание

Buffer overflow in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-6676.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:flash-player-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-gnome-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-kde4-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP4:flash-player-11.2.202.521-0.17.1

Ссылки

Описание

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to bypass the Same Origin Policy and obtain sensitive information via unspecified vectors.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:flash-player-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-gnome-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-kde4-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP4:flash-player-11.2.202.521-0.17.1

Ссылки

Описание

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5570, CVE-2015-5574, CVE-2015-5581, and CVE-2015-5584.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:flash-player-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-gnome-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP3:flash-player-kde4-11.2.202.521-0.17.1
SUSE Linux Enterprise Desktop 11 SP4:flash-player-11.2.202.521-0.17.1

Ссылки
Уязвимость SUSE-SU-2015:1614-1