Mageia alert MGASA-2018-0478 (flash-player-plugin)
From: | Mageia Updates <buildsystem-daemon@mageia.org> | |
To: | updates-announce@ml.mageia.org | |
Subject: | [updates-announce] MGASA-2018-0478: Updated flash-player-plugin packages fix security vulnerability | |
Date: | Fri, 7 Dec 2018 13:54:00 +0100 | |
Message-ID: | <20181207125400.5F6029FDA4@duvel.mageia.org> |
MGASA-2018-0478 - Updated flash-player-plugin packages fix security vulnerability Publication date: 07 Dec 2018 URL: https://advisories.mageia.org/MGASA-2018-0478.html Type: security Affected Mageia releases: 6 CVE: CVE-2018-15982, CVE-2018-15983 Description: Use after free flaw enabling arbitrary code execution. (CVE-2018-15982) Insecure Library Loading (DLL hijacking) flaw enabling privilege escalation. (CVE-2018-15983) References: - https://bugs.mageia.org/show_bug.cgi?id=23950 - https://helpx.adobe.com/security/products/flash-player/ap... - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1... - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1... SRPMS: - 6/nonfree/flash-player-plugin-32.0.0.101-1.mga6.nonfree