SuSE: 2011:1063-1: important: flash-player
Summary
SUSE Security Update: Security update for flash-player
______________________________________________________________________________
Announcement ID: SUSE-SU-2011:1063-1
Rating: important
References: #719400
Cross-References: CVE-2011-2426 CVE-2011-2427 CVE-2011-2428
CVE-2011-2429 CVE-2011-2430 CVE-2011-2444
Affected Products:
SUSE Linux Enterprise Desktop 11 SP1
SUSE Linux Enterprise Desktop 10 SP4
______________________________________________________________________________
An update that fixes 6 vulnerabilities is now available. It
includes one version update.
Description:
This update resolves
*
a universal cross-site scripting issue that could be
used to take actions on a user's behalf on any website or
webmail provider if the user visits a malicious website
(CVE-2011-2444).
Note: There are reports that this issue is being
exploited in the wild in active targeted attacks designed
to trick the user into clicking on a malicious link
delivered in an email message.
*
an AVM stack overflow issue that may allow for remote
code execution. (CVE-2011-2426).
*
an AVM stack overflow issue that may lead to denial
of service and code execution. (CVE-2011-2427).
*
a logic error issue which causes a browser crash and
may lead to code execution. (CVE-2011- 2428).
*
a Flash Player security control bypass which could
allow information disclosure. (CVE-2011-2429).
*
a streaming media logic error vulnerability which
could lead to code execution. (CVE-2011-2430).
Security Issue references:
* CVE-2011-2426
References