{"affected":[{"ecosystem_specific":{"binaries":[{"flash-player":"11.2.202.457-80.1","flash-player-gnome":"11.2.202.457-80.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Desktop 12","name":"flash-player","purl":"pkg:rpm/suse/flash-player&distro=SUSE%20Linux%20Enterprise%20Desktop%2012"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"11.2.202.457-80.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"flash-player":"11.2.202.457-80.1","flash-player-gnome":"11.2.202.457-80.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Workstation Extension 12","name":"flash-player","purl":"pkg:rpm/suse/flash-player&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"11.2.202.457-80.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"Adobe Flash Player was updated to 11.2.202.457 to fix several security issues that could lead to remote code execution.\n\nAn exploit for CVE-2015-3043 was reported to exist in the wild.\n\nThe following vulnerabilities were fixed:\n\n* Memory corruption vulnerabilities that could lead to code execution (CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, CVE-2015-3042, CVE-2015-3043).\n* Type confusion vulnerability that could lead to code execution (CVE-2015-0356).\n* Buffer overflow vulnerability that could lead to code execution (CVE-2015-0348).\n* Use-after-free vulnerabilities that could lead to code execution (CVE-2015-0349, CVE-2015-0351, CVE-2015-0358, CVE-2015-3039).\n* Double-free vulnerabilities that could lead to code execution (CVE-2015-0346, CVE-2015-0359).\n* Memory leak vulnerabilities that could be used to bypass ASLR (CVE-2015-0357, CVE-2015-3040).\n* Security bypass vulnerability that could lead to information disclosure (CVE-2015-3044).","id":"SUSE-SU-2015:0722-1","modified":"2015-04-15T06:50:02Z","published":"2015-04-15T06:50:02Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2015/suse-su-20150722-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/927089"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-0346"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-0347"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-0348"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-0349"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-0350"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-0351"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-0352"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-0353"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-0354"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-0355"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-0356"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-0357"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-0358"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-0359"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-0360"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-3038"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-3039"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-3040"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-3041"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-3042"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-3043"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-3044"}],"related":["CVE-2015-0346","CVE-2015-0347","CVE-2015-0348","CVE-2015-0349","CVE-2015-0350","CVE-2015-0351","CVE-2015-0352","CVE-2015-0353","CVE-2015-0354","CVE-2015-0355","CVE-2015-0356","CVE-2015-0357","CVE-2015-0358","CVE-2015-0359","CVE-2015-0360","CVE-2015-3038","CVE-2015-3039","CVE-2015-3040","CVE-2015-3041","CVE-2015-3042","CVE-2015-3043","CVE-2015-3044"],"summary":"Security update for Adobe Flash Player","upstream":["CVE-2015-0346","CVE-2015-0347","CVE-2015-0348","CVE-2015-0349","CVE-2015-0350","CVE-2015-0351","CVE-2015-0352","CVE-2015-0353","CVE-2015-0354","CVE-2015-0355","CVE-2015-0356","CVE-2015-0357","CVE-2015-0358","CVE-2015-0359","CVE-2015-0360","CVE-2015-3038","CVE-2015-3039","CVE-2015-3040","CVE-2015-3041","CVE-2015-3042","CVE-2015-3043","CVE-2015-3044"]}