SUSE Security Update: Security update for flash-player
______________________________________________________________________________

Announcement ID:    SUSE-SU-2013:1896-1
Rating:             important
References:         #854881 
Cross-References:   CVE-2013-5331 CVE-2013-5332
Affected Products:
                    SUSE Linux Enterprise Desktop 11 SP3
                    SUSE Linux Enterprise Desktop 11 SP2
______________________________________________________________________________

   An update that fixes two vulnerabilities is now available.
   It includes one version update.

Description:


   This update fixes the following security issues with
   flash-player:

   * bnc#854881: flash-plugin: multiple code execution
   flaws (APSB13-28) o These updates resolve a type confusion
   vulnerability that could lead to code execution
   (CVE-2013-5331). o These updates resolve a memory
   corruption vulnerability that could lead to code execution
   (CVE-2013-5332). o Ref:
      -28.html
   

   Security Issue references:

   * CVE-2013-5332
   
   * CVE-2013-5331
   


Patch Instructions:

   To install this SUSE Security Update use YaST online_update.
   Alternatively you can run the command listed for your product:

   - SUSE Linux Enterprise Desktop 11 SP3:

      zypper in -t patch sledsp3-flash-player-8640

   - SUSE Linux Enterprise Desktop 11 SP2:

      zypper in -t patch sledsp2-flash-player-8639

   To bring your system up-to-date, use "zypper patch".


Package List:

   - SUSE Linux Enterprise Desktop 11 SP3 (i586 x86_64) [New Version: 11.2.202.332]:

      flash-player-11.2.202.332-0.3.1
      flash-player-gnome-11.2.202.332-0.3.1
      flash-player-kde4-11.2.202.332-0.3.1

   - SUSE Linux Enterprise Desktop 11 SP2 (i586 x86_64) [New Version: 11.2.202.332]:

      flash-player-11.2.202.332-0.3.1
      flash-player-gnome-11.2.202.332-0.3.1
      flash-player-kde4-11.2.202.332-0.3.1


References:

   https://www.suse.com/security/cve/CVE-2013-5331.html
   https://www.suse.com/security/cve/CVE-2013-5332.html
   https://bugzilla.novell.com/854881
   https://login.microfocus.com/nidp/app/login
   https://login.microfocus.com/nidp/app/login

SuSE: 2013:1896-1: important: flash-player

December 17, 2013
An update that fixes two vulnerabilities is now available

Summary

This update fixes the following security issues with flash-player: * bnc#854881: flash-plugin: multiple code execution flaws (APSB13-28) o These updates resolve a type confusion vulnerability that could lead to code execution (CVE-2013-5331). o These updates resolve a memory corruption vulnerability that could lead to code execution (CVE-2013-5332). o Ref: -28.html Security Issue references: * CVE-2013-5332 * CVE-2013-5331 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Desktop 11 SP3: zypper in -t patch sledsp3-flash-player-8640 - SUSE Linux Enterprise Desktop 11 SP2: zypper in -t patch sledsp2-flash-player-8639 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Desktop 11 SP3 (i586 x86_64) [New Version: 11.2.202.332]: fl...

Read the Full Advisory

References

#854881

Cross- CVE-2013-5331 CVE-2013-5332

Affected Products:

SUSE Linux Enterprise Desktop 11 SP3

SUSE Linux Enterprise Desktop 11 SP2

https://www.suse.com/security/cve/CVE-2013-5331.html

https://www.suse.com/security/cve/CVE-2013-5332.html

https://bugzilla.novell.com/854881

https://login.microfocus.com/nidp/app/login

https://login.microfocus.com/nidp/app/login

Severity
Announcement ID: SUSE-SU-2013:1896-1
Rating: important

Related News