MGASA-2015-0043

Source
https://advisories.mageia.org/MGASA-2015-0043.html
Import Source
https://advisories.mageia.org/MGASA-2015-0043.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2015-0043
Upstream
  • CVE-2015-0311
  • CVE-2015-0312
Published
2015-01-27T21:08:29Z
Modified
2026-04-16T06:24:07.218195504Z
Summary
Updated flash-player-plugin packages fix security vulnerabilities
Details

Adobe Flash Player 11.2.202.440 contains fixes to critical security vulnerabilities found in earlier versions that could cause a crash and potentially allow an attacker to take control of the affected system.

Adobe reports that CVE-2015-0311 is already being actively exploited in the wild via drive-by-download attacks against systems running Internet Explorer and Firefox on Windows.

This update resolves a use-after-free vulnerability that could lead to code execution (CVE-2015-0311).

This update resolves a double-free vulnerability that could lead to code execution (CVE-2015-0312).

References
Credits

Affected packages

Mageia:4 / flash-player-plugin

Package

Name
flash-player-plugin
Purl
pkg:rpm/mageia/flash-player-plugin?arch=source&distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
11.2.202.440-1.1.mga4.nonfree

Ecosystem specific

{
    "section": "nonfree"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2015-0043.json"