Security update for flash-player

SUSE Security Update: Security update for flash-player
Announcement ID: SUSE-SU-2015:1214-1
Rating: critical
References: #937339
Affected Products:
  • SUSE Linux Enterprise Desktop 11-SP4
  • SUSE Linux Enterprise Desktop 11-SP3

  • An update that fixes 35 vulnerabilities is now available.

    Description:

    flash-player was updated to fix 35 security issues.

    These security issues were fixed:
    - CVE-2015-3135, CVE-2015-4432, CVE-2015-5118: Heap buffer overflow
    vulnerabilities that could lead to code execution (bsc#937339).
    - CVE-2015-3117, CVE-2015-3123, CVE-2015-3130, CVE-2015-3133,
    CVE-2015-3134, CVE-2015-4431: Memory corruption vulnerabilities that
    could lead to code execution (bsc#937339).
    - CVE-2015-3126, CVE-2015-4429: Null pointer dereference issues
    (bsc#937339).
    - CVE-2015-3114: A security bypass vulnerability that could lead to
    information disclosure (bsc#937339).
    - CVE-2015-3119, CVE-2015-3120, CVE-2015-3121, CVE-2015-3122,
    CVE-2015-4433: Type confusion vulnerabilities that could lead to code
    execution (bsc#937339).
    - CVE-2015-3118, CVE-2015-3124, CVE-2015-5117, CVE-2015-3127,
    CVE-2015-3128, CVE-2015-3129, CVE-2015-3131, CVE-2015-3132,
    CVE-2015-3136, CVE-2015-3137, CVE-2015-4428, CVE-2015-4430,
    CVE-2015-5119: Use-after-free vulnerabilities that could lead to code
    execution (bsc#937339).
    - CVE-2014-0578, CVE-2015-3115, CVE-2015-3116, CVE-2015-3125,
    CVE-2015-5116: Vulnerabilities that could be exploited to bypass the
    same-origin-policy and lead to information disclosure (bsc#937339).

    Patch Instructions:

    To install this SUSE Security Update use YaST online_update.
    Alternatively you can run the command listed for your product:

    • SUSE Linux Enterprise Desktop 11-SP4:
      zypper in -t patch sledsp4-flash-player-20150708-1=1
    • SUSE Linux Enterprise Desktop 11-SP3:
      zypper in -t patch sledsp3-flash-player-20150708-1=1

    To bring your system up-to-date, use "zypper patch".

    Package List:

    • SUSE Linux Enterprise Desktop 11-SP4 (i586 x86_64):
      • flash-player-11.2.202.481-0.5.1
      • flash-player-gnome-11.2.202.481-0.5.1
      • flash-player-kde4-11.2.202.481-0.5.1
    • SUSE Linux Enterprise Desktop 11-SP3 (i586 x86_64):
      • flash-player-11.2.202.481-0.5.1
      • flash-player-gnome-11.2.202.481-0.5.1
      • flash-player-kde4-11.2.202.481-0.5.1

    References: