Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2015:1618-1

Опубликовано: 22 сент. 2015
Источник: suse-cvrf

Описание

Security update for flash-player

Adobe Flash Player was updated to 11.2.202.521 (APSB15-23 bsc#946880) fixing several security issues:

More information can be found on:

https://helpx.adobe.com/security/products/flash-player/apsb15-23.html

Список пакетов

SUSE Linux Enterprise Desktop 12
flash-player-11.2.202.521-102.1
flash-player-gnome-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12
flash-player-11.2.202.521-102.1
flash-player-gnome-11.2.202.521-102.1

Ссылки

Описание

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5579.


Затронутые продукты
SUSE Linux Enterprise Desktop 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Desktop 12:flash-player-gnome-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-gnome-11.2.202.521-102.1

Ссылки

Описание

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to cause a denial of service (vector-length corruption) or possibly have unspecified other impact via unknown vectors.


Затронутые продукты
SUSE Linux Enterprise Desktop 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Desktop 12:flash-player-gnome-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-gnome-11.2.202.521-102.1

Ссылки

Описание

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5574, CVE-2015-5581, CVE-2015-5584, and CVE-2015-6682.


Затронутые продукты
SUSE Linux Enterprise Desktop 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Desktop 12:flash-player-gnome-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-gnome-11.2.202.521-102.1

Ссылки

Описание

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API. NOTE: this issue exists because of an incomplete fix for CVE-2014-4671 and CVE-2014-5333.


Затронутые продукты
SUSE Linux Enterprise Desktop 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Desktop 12:flash-player-gnome-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-gnome-11.2.202.521-102.1

Ссылки

Описание

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors.


Затронутые продукты
SUSE Linux Enterprise Desktop 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Desktop 12:flash-player-gnome-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-gnome-11.2.202.521-102.1

Ссылки

Описание

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execute arbitrary code by leveraging an unspecified "type confusion."


Затронутые продукты
SUSE Linux Enterprise Desktop 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Desktop 12:flash-player-gnome-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-gnome-11.2.202.521-102.1

Ссылки

Описание

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5570, CVE-2015-5581, CVE-2015-5584, and CVE-2015-6682.


Затронутые продукты
SUSE Linux Enterprise Desktop 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Desktop 12:flash-player-gnome-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-gnome-11.2.202.521-102.1

Ссылки

Описание

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5577, CVE-2015-5578, CVE-2015-5580, CVE-2015-5582, CVE-2015-5588, and CVE-2015-6677.


Затронутые продукты
SUSE Linux Enterprise Desktop 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Desktop 12:flash-player-gnome-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-gnome-11.2.202.521-102.1

Ссылки

Описание

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 do not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors.


Затронутые продукты
SUSE Linux Enterprise Desktop 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Desktop 12:flash-player-gnome-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-gnome-11.2.202.521-102.1

Ссылки

Описание

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5575, CVE-2015-5578, CVE-2015-5580, CVE-2015-5582, CVE-2015-5588, and CVE-2015-6677.


Затронутые продукты
SUSE Linux Enterprise Desktop 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Desktop 12:flash-player-gnome-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-gnome-11.2.202.521-102.1

Ссылки

Описание

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5575, CVE-2015-5577, CVE-2015-5580, CVE-2015-5582, CVE-2015-5588, and CVE-2015-6677.


Затронутые продукты
SUSE Linux Enterprise Desktop 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Desktop 12:flash-player-gnome-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-gnome-11.2.202.521-102.1

Ссылки

Описание

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5567.


Затронутые продукты
SUSE Linux Enterprise Desktop 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Desktop 12:flash-player-gnome-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-gnome-11.2.202.521-102.1

Ссылки

Описание

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5575, CVE-2015-5577, CVE-2015-5578, CVE-2015-5582, CVE-2015-5588, and CVE-2015-6677.


Затронутые продукты
SUSE Linux Enterprise Desktop 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Desktop 12:flash-player-gnome-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-gnome-11.2.202.521-102.1

Ссылки

Описание

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5570, CVE-2015-5574, CVE-2015-5584, and CVE-2015-6682.


Затронутые продукты
SUSE Linux Enterprise Desktop 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Desktop 12:flash-player-gnome-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-gnome-11.2.202.521-102.1

Ссылки

Описание

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5575, CVE-2015-5577, CVE-2015-5578, CVE-2015-5580, CVE-2015-5588, and CVE-2015-6677.


Затронутые продукты
SUSE Linux Enterprise Desktop 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Desktop 12:flash-player-gnome-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-gnome-11.2.202.521-102.1

Ссылки

Описание

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5570, CVE-2015-5574, CVE-2015-5581, and CVE-2015-6682.


Затронутые продукты
SUSE Linux Enterprise Desktop 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Desktop 12:flash-player-gnome-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-gnome-11.2.202.521-102.1

Ссылки

Описание

Stack-based buffer overflow in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors.


Затронутые продукты
SUSE Linux Enterprise Desktop 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Desktop 12:flash-player-gnome-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-gnome-11.2.202.521-102.1

Ссылки

Описание

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5575, CVE-2015-5577, CVE-2015-5578, CVE-2015-5580, CVE-2015-5582, and CVE-2015-6677.


Затронутые продукты
SUSE Linux Enterprise Desktop 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Desktop 12:flash-player-gnome-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-gnome-11.2.202.521-102.1

Ссылки

Описание

Buffer overflow in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-6678.


Затронутые продукты
SUSE Linux Enterprise Desktop 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Desktop 12:flash-player-gnome-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-gnome-11.2.202.521-102.1

Ссылки

Описание

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5575, CVE-2015-5577, CVE-2015-5578, CVE-2015-5580, CVE-2015-5582, and CVE-2015-5588.


Затронутые продукты
SUSE Linux Enterprise Desktop 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Desktop 12:flash-player-gnome-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-gnome-11.2.202.521-102.1

Ссылки

Описание

Buffer overflow in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-6676.


Затронутые продукты
SUSE Linux Enterprise Desktop 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Desktop 12:flash-player-gnome-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-gnome-11.2.202.521-102.1

Ссылки

Описание

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to bypass the Same Origin Policy and obtain sensitive information via unspecified vectors.


Затронутые продукты
SUSE Linux Enterprise Desktop 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Desktop 12:flash-player-gnome-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-gnome-11.2.202.521-102.1

Ссылки

Описание

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5570, CVE-2015-5574, CVE-2015-5581, and CVE-2015-5584.


Затронутые продукты
SUSE Linux Enterprise Desktop 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Desktop 12:flash-player-gnome-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-11.2.202.521-102.1
SUSE Linux Enterprise Workstation Extension 12:flash-player-gnome-11.2.202.521-102.1

Ссылки
Уязвимость SUSE-SU-2015:1618-1