Security update for flash-player

SUSE Security Update: Security update for flash-player
Announcement ID: SUSE-SU-2014:1035-1
Rating: important
References: #891688
Affected Products:
  • SUSE Linux Enterprise Desktop 11 SP3

  • An update that fixes 7 vulnerabilities is now available. It includes one version update.

    Description:


    This flash-player update fixes the following security issues:

    * These updates resolve memory leakage vulnerabilities that could have
    been used to bypass memory address randomization (CVE-2014-0540,
    CVE-2014-0542, CVE-2014-0543, CVE-2014-0544, CVE-2014-0545).
    * These updates resolve a security bypass vulnerability
    (CVE-2014-0541).
    * These updates resolve a use-after-free vulnerability that could have
    lead to code execution (CVE-2014-0538).

    Find more details under
    http://helpx.adobe.com/security/products/flash-player/apsb14-18.html


    Security Issues:

    * CVE-2014-0538

    * CVE-2014-0540

    * CVE-2014-0541

    * CVE-2014-0542

    * CVE-2014-0543

    * CVE-2014-0544

    * CVE-2014-0545

    Patch Instructions:

    To install this SUSE Security Update use YaST online_update.
    Alternatively you can run the command listed for your product:

    • SUSE Linux Enterprise Desktop 11 SP3:
      zypper in -t patch sledsp3-flash-player-9612

    To bring your system up-to-date, use "zypper patch".

    Package List:

    • SUSE Linux Enterprise Desktop 11 SP3 (i586 x86_64) [New Version: 11.2.202.400]:
      • flash-player-11.2.202.400-0.3.1
      • flash-player-gnome-11.2.202.400-0.3.1
      • flash-player-kde4-11.2.202.400-0.3.1

    References:

    • http://support.novell.com/security/cve/CVE-2014-0538.html
    • http://support.novell.com/security/cve/CVE-2014-0540.html
    • http://support.novell.com/security/cve/CVE-2014-0541.html
    • http://support.novell.com/security/cve/CVE-2014-0542.html
    • http://support.novell.com/security/cve/CVE-2014-0543.html
    • http://support.novell.com/security/cve/CVE-2014-0544.html
    • http://support.novell.com/security/cve/CVE-2014-0545.html
    • https://bugzilla.novell.com/891688
    • http://download.suse.com/patch/finder/?keywords=45b3cfc443642a9e3f85e156ff8996b7