SUSE-SU-2015:0722-1

Source
https://www.suse.com/support/update/announcement/2015/suse-su-20150722-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2015:0722-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2015:0722-1
Upstream
  • CVE-2015-0346
  • CVE-2015-0347
  • CVE-2015-0348
  • CVE-2015-0349
  • CVE-2015-0350
  • CVE-2015-0351
  • CVE-2015-0352
  • CVE-2015-0353
  • CVE-2015-0354
  • CVE-2015-0355
  • CVE-2015-0356
  • CVE-2015-0357
  • CVE-2015-0358
  • CVE-2015-0359
  • CVE-2015-0360
  • CVE-2015-3038
  • CVE-2015-3039
  • CVE-2015-3040
  • CVE-2015-3041
  • CVE-2015-3042
  • CVE-2015-3043
  • CVE-2015-3044
Related
  • CVE-2015-0346
  • CVE-2015-0347
  • CVE-2015-0348
  • CVE-2015-0349
  • CVE-2015-0350
  • CVE-2015-0351
  • CVE-2015-0352
  • CVE-2015-0353
  • CVE-2015-0354
  • CVE-2015-0355
  • CVE-2015-0356
  • CVE-2015-0357
  • CVE-2015-0358
  • CVE-2015-0359
  • CVE-2015-0360
  • CVE-2015-3038
  • CVE-2015-3039
  • CVE-2015-3040
  • CVE-2015-3041
  • CVE-2015-3042
  • CVE-2015-3043
  • CVE-2015-3044
Published
2015-04-15T06:50:02Z
Modified
2026-02-04T04:10:57Z
Summary
Security update for Adobe Flash Player
Details

Adobe Flash Player was updated to 11.2.202.457 to fix several security issues that could lead to remote code execution.

An exploit for CVE-2015-3043 was reported to exist in the wild.

The following vulnerabilities were fixed:

  • Memory corruption vulnerabilities that could lead to code execution (CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, CVE-2015-3042, CVE-2015-3043).
  • Type confusion vulnerability that could lead to code execution (CVE-2015-0356).
  • Buffer overflow vulnerability that could lead to code execution (CVE-2015-0348).
  • Use-after-free vulnerabilities that could lead to code execution (CVE-2015-0349, CVE-2015-0351, CVE-2015-0358, CVE-2015-3039).
  • Double-free vulnerabilities that could lead to code execution (CVE-2015-0346, CVE-2015-0359).
  • Memory leak vulnerabilities that could be used to bypass ASLR (CVE-2015-0357, CVE-2015-3040).
  • Security bypass vulnerability that could lead to information disclosure (CVE-2015-3044).
References

Affected packages

SUSE:Linux Enterprise Desktop 12 / flash-player

Package

Name
flash-player
Purl
pkg:rpm/suse/flash-player&distro=SUSE%20Linux%20Enterprise%20Desktop%2012

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
11.2.202.457-80.1

Ecosystem specific

{
    "binaries": [
        {
            "flash-player": "11.2.202.457-80.1",
            "flash-player-gnome": "11.2.202.457-80.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2015:0722-1.json"

SUSE:Linux Enterprise Workstation Extension 12 / flash-player

Package

Name
flash-player
Purl
pkg:rpm/suse/flash-player&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
11.2.202.457-80.1

Ecosystem specific

{
    "binaries": [
        {
            "flash-player": "11.2.202.457-80.1",
            "flash-player-gnome": "11.2.202.457-80.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2015:0722-1.json"