Bug 950474 (CVE-2015-7645) - VUL-0: CVE-2015-7645: flash-player: critical vulnerability affecting 11.2.202.535 used in Pawn Storm (APSA15-05)
Summary: VUL-0: CVE-2015-7645: flash-player: critical vulnerability affecting 11.2.202...
Status: RESOLVED FIXED
Alias: CVE-2015-7645
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P1 - Urgent : Critical
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard: CVSSv2:RedHat:CVE-2015-7645:6.8:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2015-10-15 07:35 UTC by Andreas Stieger
Modified: 2016-04-27 14:42 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2015-10-15 07:35:58 UTC
https://helpx.adobe.com/security/products/flash-player/apsa15-05.html

Security Advisory for Adobe Flash Player
Release date (of advisory): October 14, 2015
Vulnerability identifier: APSA15-05

CVE number: CVE-2015-7645

Platforms: Windows, Macintosh and Linux

Summary: A critical vulnerability (CVE-2015-7645) has been identified in Adobe Flash Player 19.0.0.207 and earlier versions for Windows, Macintosh and Linux. Successful exploitation could cause a crash and potentially allow an attacker to take control of the affected system.  

Adobe is aware of a report that an exploit for this vulnerability is being used in limited, targeted attacks.  Adobe expects to make an update available during the week of October 19.

Affected software versions: 

    Adobe Flash Player 19.0.0.207 and earlier versions for Windows and Macintosh
    Adobe Flash Player Extended Support Release version 18.0.0.252 and earlier 18.x versions
    Adobe Flash Player 11.2.202.535 and earlier 11.x versions for Linux
Comment 2 Stanislav Brabec 2015-10-15 12:16:40 UTC
The update is not yet available.

https://get.adobe.com/cz/flashplayer/
still points to 11.2.202.535, which is vulnerable according to APSA15-05:

Affected software versions
    Adobe Flash Player 11.2.202.535 and earlier 11.x versions for Linux
Comment 3 Andreas Stieger 2015-10-15 12:38:16 UTC
Update expected to be available week of October 19th.
Comment 4 Andreas Stieger 2015-10-16 10:49:08 UTC
Submitted 11.2.202.540
Comment 5 Bernhard Wiedemann 2015-10-16 11:00:08 UTC
This is an autogenerated message for OBS integration:
This bug (950474) was mentioned in
https://build.opensuse.org/request/show/339264 Factory:NonFree / flash-player
https://build.opensuse.org/request/show/339265 Leap:42.1:NonFree / flash-player
https://build.opensuse.org/request/show/339266 13.1:NonFree+13.2:NonFree+Leap:42.1:NonFree / flash-player.openSUSE_Leap_42.1+flash-player
https://build.opensuse.org/request/show/339267 Factory / flash-player
Comment 7 Swamp Workflow Management 2015-10-16 14:11:08 UTC
openSUSE-SU-2015:1768-1: An update that fixes one vulnerability is now available.

Category: security (critical)
Bug References: 950474
CVE References: CVE-2015-7645
Sources used:
openSUSE 13.2:NonFree (src):    flash-player-11.2.202.540-2.76.1
openSUSE 13.1:NonFree (src):    flash-player-11.2.202.540-141.1
Comment 8 Swamp Workflow Management 2015-10-16 15:10:36 UTC
SUSE-SU-2015:1770-1: An update that fixes one vulnerability is now available.

Category: security (critical)
Bug References: 950474
CVE References: CVE-2015-7645
Sources used:
SUSE Linux Enterprise Workstation Extension 12 (src):    flash-player-11.2.202.540-108.1
SUSE Linux Enterprise Desktop 12 (src):    flash-player-11.2.202.540-108.1
Comment 9 Swamp Workflow Management 2015-10-16 15:10:56 UTC
SUSE-SU-2015:1771-1: An update that fixes one vulnerability is now available.

Category: security (critical)
Bug References: 950474
CVE References: CVE-2015-7645
Sources used:
SUSE Linux Enterprise Desktop 11-SP4 (src):    flash-player-11.2.202.540-0.23.1
SUSE Linux Enterprise Desktop 11-SP3 (src):    flash-player-11.2.202.540-0.23.1
Comment 11 Swamp Workflow Management 2015-10-19 17:10:13 UTC
openSUSE-SU-2015:1781-1: An update that fixes 71 vulnerabilities is now available.

Category: security (critical)
Bug References: 941239,946880,950169,950474
CVE References: CVE-2015-3107,CVE-2015-5124,CVE-2015-5125,CVE-2015-5127,CVE-2015-5128,CVE-2015-5129,CVE-2015-5130,CVE-2015-5131,CVE-2015-5132,CVE-2015-5133,CVE-2015-5134,CVE-2015-5539,CVE-2015-5540,CVE-2015-5541,CVE-2015-5544,CVE-2015-5545,CVE-2015-5546,CVE-2015-5547,CVE-2015-5548,CVE-2015-5549,CVE-2015-5550,CVE-2015-5551,CVE-2015-5552,CVE-2015-5553,CVE-2015-5554,CVE-2015-5555,CVE-2015-5556,CVE-2015-5557,CVE-2015-5558,CVE-2015-5559,CVE-2015-5560,CVE-2015-5561,CVE-2015-5562,CVE-2015-5563,CVE-2015-5567,CVE-2015-5568,CVE-2015-5569,CVE-2015-5570,CVE-2015-5571,CVE-2015-5572,CVE-2015-5573,CVE-2015-5574,CVE-2015-5575,CVE-2015-5576,CVE-2015-5577,CVE-2015-5578,CVE-2015-5579,CVE-2015-5580,CVE-2015-5581,CVE-2015-5582,CVE-2015-5584,CVE-2015-5587,CVE-2015-5588,CVE-2015-6676,CVE-2015-6677,CVE-2015-6678,CVE-2015-6679,CVE-2015-6682,CVE-2015-7625,CVE-2015-7626,CVE-2015-7627,CVE-2015-7628,CVE-2015-7629,CVE-2015-7630,CVE-2015-7631,CVE-2015-7632,CVE-2015-7633,CVE-2015-7634,CVE-2015-7643,CVE-2015-7644,CVE-2015-7645
Sources used:
openSUSE Evergreen 11.4 (src):    flash-player-11.2.202.540-176.1