{
  "schema_version": "1.7.0",
  "id": "MGASA-2015-0379",
  "published": "2015-09-21T21:07:00Z",
  "modified": "2015-09-21T21:05:47Z",
  "summary": "Updated flash-player-plugin packages fix security vulnerabilities",
  "details": "Adobe Flash Player 11.2.202.521 contains fixes to critical security \nvulnerabilities found in earlier versions that could potentially allow an \nattacker to take control of the affected system.\n\nThis update resolves a type confusion vulnerability that could lead to code \nexecution (CVE-2015-5573). \n\nThis update resolves use-after-free vulnerabilities that could lead to code \nexecution (CVE-2015-5570, CVE-2015-5574, CVE-2015-5581, CVE-2015-5584, \nCVE-2015-6682). \n\nThis update resolves buffer overflow vulnerabilities that could lead to \ncode execution (CVE-2015-6676, CVE-2015-6678). \n\nThis update resolves memory corruption vulnerabilities that could lead to \ncode execution (CVE-2015-5575, CVE-2015-5577, CVE-2015-5578, CVE-2015-5580, \nCVE-2015-5582, CVE-2015-5588, CVE-2015-6677). \n\nThis update includes additional validation checks to ensure that Flash \nPlayer rejects malicious content from vulnerable JSONP callback APIs \n(CVE-2015-5571). \n\nThis update resolves a memory leak vulnerability (CVE-2015-5576). \n\nThis update includes further hardening to a mitigation to defend against \nvector length corruptions (CVE-2015-5568). \n\nThis update resolves stack corruption vulnerabilities that could lead to \ncode execution (CVE-2015-5567, CVE-2015-5579). \n\nThis update resolves a stack overflow vulnerability that could lead to code \nexecution (CVE-2015-5587). \n\nThis update resolves a security bypass vulnerability that could lead to \ninformation disclosure (CVE-2015-5572). \n\nThis update resolves a vulnerability that could be exploited to bypass the \nsame-origin-policy and lead to information disclosure (CVE-2015-6679).\n",
  "upstream": [
    "CVE-2015-5567",
    "CVE-2015-5568",
    "CVE-2015-5570",
    "CVE-2015-5571",
    "CVE-2015-5572",
    "CVE-2015-5573",
    "CVE-2015-5574",
    "CVE-2015-5575",
    "CVE-2015-5576",
    "CVE-2015-5577",
    "CVE-2015-5578",
    "CVE-2015-5579",
    "CVE-2015-5580",
    "CVE-2015-5581",
    "CVE-2015-5582",
    "CVE-2015-5584",
    "CVE-2015-5587",
    "CVE-2015-5588",
    "CVE-2015-6676",
    "CVE-2015-6677",
    "CVE-2015-6678",
    "CVE-2015-6679",
    "CVE-2015-6682"
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2015-0379.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=16792"
    },
    {
      "type": "WEB",
      "url": "https://helpx.adobe.com/security/products/flash-player/apsb15-23.html"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:5",
        "name": "flash-player-plugin",
        "purl": "pkg:rpm/mageia/flash-player-plugin?arch=source&distro=mageia-5"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "11.2.202.521-1.mga5.nonfree"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "nonfree"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
