SUSE Security Update: Security update for flash-player
______________________________________________________________________________

Announcement ID:    SUSE-SU-2014:0221-1
Rating:             important
References:         #862288 
Cross-References:   CVE-2014-0497
Affected Products:
                    SUSE Linux Enterprise Desktop 11 SP3
                    SUSE Linux Enterprise Desktop 11 SP2
______________________________________________________________________________

   An update that fixes one vulnerability is now available. It
   includes one version update.

Description:


   This update resolves an integer underflow vulnerability
   that could have  been exploited to execute arbitrary code
   on the affected system  (CVE-2014-0497).

   More information:
      -04.html
   

   Security Issue references:

   * CVE-2014-0497
   


Patch Instructions:

   To install this SUSE Security Update use YaST online_update.
   Alternatively you can run the command listed for your product:

   - SUSE Linux Enterprise Desktop 11 SP3:

      zypper in -t patch sledsp3-flash-player-8880

   - SUSE Linux Enterprise Desktop 11 SP2:

      zypper in -t patch sledsp2-flash-player-8876

   To bring your system up-to-date, use "zypper patch".


Package List:

   - SUSE Linux Enterprise Desktop 11 SP3 (i586 x86_64) [New Version: 11.2.202.336]:

      flash-player-11.2.202.336-0.3.1
      flash-player-gnome-11.2.202.336-0.3.1
      flash-player-kde4-11.2.202.336-0.3.1

   - SUSE Linux Enterprise Desktop 11 SP2 (i586 x86_64) [New Version: 11.2.202.336]:

      flash-player-11.2.202.336-0.3.1
      flash-player-gnome-11.2.202.336-0.3.1
      flash-player-kde4-11.2.202.336-0.3.1


References:

   https://www.suse.com/security/cve/CVE-2014-0497.html
   https://bugzilla.novell.com/862288
   https://login.microfocus.com/nidp/app/login
   https://login.microfocus.com/nidp/app/login

SuSE: 2014:0221-1: important: flash-player

February 11, 2014
An update that fixes one vulnerability is now available

Summary

This update resolves an integer underflow vulnerability that could have been exploited to execute arbitrary code on the affected system (CVE-2014-0497). More information: -04.html Security Issue references: * CVE-2014-0497 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Desktop 11 SP3: zypper in -t patch sledsp3-flash-player-8880 - SUSE Linux Enterprise Desktop 11 SP2: zypper in -t patch sledsp2-flash-player-8876 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Desktop 11 SP3 (i586 x86_64) [New Version: 11.2.202.336]: flash-player-11.2.202.336-0.3.1 flash-player-gnome-11.2.202.336-0.3.1 flash-player-kde4-11.2.202.336-0.3.1 - SUSE Linux Enterprise Desktop 11 SP2 (i586 x86_64) [New Version: 11.2.202.336]: flash-playe...

Read the Full Advisory

References

#862288

Cross- CVE-2014-0497

Affected Products:

SUSE Linux Enterprise Desktop 11 SP3

SUSE Linux Enterprise Desktop 11 SP2

https://www.suse.com/security/cve/CVE-2014-0497.html

https://bugzilla.novell.com/862288

https://login.microfocus.com/nidp/app/login

https://login.microfocus.com/nidp/app/login

Severity
Announcement ID: SUSE-SU-2014:0221-1
Rating: important

Related News