Otkrivena su dva nova sigurnosna propusta radu programskog paketa Flash Player. Napadač ih može iskoristiti za proizvoljno pokretanje programskog koda, DoS (eng. Denial of Service) napad te otkrivanje osjetljivih podataka.
Paket:
Flash Player 10.x
Operacijski sustavi:
openSUSE 11.4
Kritičnost:
7.4
Problem:
neodgovarajuća provjera ulaznih podataka, pogreška u programskoj komponenti
openSUSE Security Update: flash-player
______________________________________________________________________________
Announcement ID: openSUSE-SU-2012:0331-1
Rating: important
References: #750614
Cross-References: CVE-2012-0768 CVE-2012-0769
Affected Products:
openSUSE 11.4
______________________________________________________________________________
An update that fixes two vulnerabilities is now available.
It includes one version update.
Description:
flash-player 11.1.102.63 fixes two security issues:
- memory corruption vulnerability in Matrix3D could lead to
code executionn (CVE-2012-0768)
- integer errors that could lead to information disclosure
(CVE-2012-0769)
Patch Instructions:
To install this openSUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE 11.4:
zypper in -t patch flash-player-5927
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE 11.4 (i586 x86_64) [New Version: 11.1.102.63]:
flash-player-11.1.102.63-0.2.1
References:
http://support.novell.com/security/cve/CVE-2012-0768.html
http://support.novell.com/security/cve/CVE-2012-0769.html
https://bugzilla.novell.com/750614
--
To unsubscribe, e-mail: Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
For additional commands, e-mail: Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
Posljednje sigurnosne preporuke