Upstream information

CVE-2014-0509 at MITRE

Description

Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 11.7.700.275 and 11.8.x through 13.0.x before 13.0.0.182 on Windows and OS X and before 11.2.202.350 on Linux, Adobe AIR before 13.0.0.83 on Android, Adobe AIR SDK before 13.0.0.83, and Adobe AIR SDK & Compiler before 13.0.0.83 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having moderate severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 4.3
Vector AV:N/AC:M/Au:N/C:N/I:P/A:N
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact None
Integrity Impact Partial
Availability Impact None
SUSE Bugzilla entry: 872692 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Desktop 11 SP3
  • flash-player >= 11.2.202.350-0.3.1
  • flash-player-gnome >= 11.2.202.350-0.3.1
  • flash-player-kde4 >= 11.2.202.350-0.3.1
Patchnames:
sledsp3-flash-player
SUSE Linux Enterprise Desktop 12
  • flash-player >= 11.2.202.406-1.3
  • flash-player-gnome >= 11.2.202.406-1.3
Patchnames:
SUSE Linux Enterprise Desktop 12 GA flash-player
SUSE Linux Enterprise Desktop 12 SP1
  • flash-player >= 11.2.202.548-111.1
  • flash-player-gnome >= 11.2.202.548-111.1
Patchnames:
SUSE Linux Enterprise Desktop 12 SP1 GA flash-player
SUSE Linux Enterprise Workstation Extension 12
  • flash-player >= 11.2.202.406-1.3
  • flash-player-gnome >= 11.2.202.406-1.3
Patchnames:
SUSE Linux Enterprise Workstation Extension 12 GA flash-player
SUSE Linux Enterprise Workstation Extension 12 SP1
  • flash-player >= 11.2.202.548-111.1
  • flash-player-gnome >= 11.2.202.548-111.1
Patchnames:
SUSE Linux Enterprise Workstation Extension 12 SP1 GA flash-player
SUSE Linux Enterprise Desktop 11 SP3
  • flash-player >= 11.2.202.350-0.3.1
  • flash-player-gnome >= 11.2.202.350-0.3.1
  • flash-player-kde4 >= 11.2.202.350-0.3.1
Builds
SAT Patch Nr: 9120


Status of this issue by product and package

Product(s) Source package State
SUSE Linux Enterprise Desktop 11 SP3 flash-player Released