LWN.net Logo

flash-player: multiple vulnerabilities

Package(s):Flash-Player CVE #(s):CVE-2011-2426 CVE-2011-2427 CVE-2011-2428 CVE-2011-2429 CVE-2011-2430 CVE-2011-2444
Created:September 23, 2011 Updated:November 8, 2011
Description: From the openSUSE advisory:

This update resolves a universal cross-site scripting issue that could be used to take actions on a user's behalf on any website or webmail provider if the user visits a malicious website (CVE-2011-2444).

Note: There are reports that this issue is being exploited in the wild in active targeted attacks designed to trick the user into clicking on a malicious link delivered in an email message.

This update resolves an AVM stack overflow issue that may allow for remote code execution. (CVE-2011-2426).

This update resolves an AVM stack overflow issue that may lead to denial of service and code execution. (CVE-2011-2427).

This update resolves a logic error issue which causes a browser crash and may lead to code execution. (CVE-2011- 2428).

This update resolves a Flash Player security control bypass which could allow information disclosure. (CVE-2011-2429).

This update resolves a streaming media logic error vulnerability which could lead to code execution. (CVE-2011-2430).

Alerts:
Red Hat RHSA-2011:1434-01 2011-11-08
Gentoo 201110-11 2011-10-13
Red Hat RHSA-2011:1333-01 2011-09-22
SUSE SUSE-SU-2011:1063-1 2011-09-23
openSUSE openSUSE-SU-2011:1060-1 2011-09-23

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds