{
  "schema_version": "1.7.0",
  "id": "MGASA-2015-0404",
  "published": "2015-10-17T08:53:25Z",
  "modified": "2015-10-17T08:52:26Z",
  "summary": "Updated flash-player-plugin package fix security vulnerabilities",
  "details": "Adobe Flash Player 11.2.202.540 contains fixes to critical security\nvulnerabilities found in earlier versions that could potentially allow\nan attacker to take control of the affected system.\n\nThis update resolves type confusion vulnerabilities that could lead to\ncode execution (CVE-2015-7645, CVE-2015-7647, CVE-2015-7648).\n\nAn exploit for CVE-2015-7645 is being used in the wild.\n",
  "upstream": [
    "CVE-2015-7645",
    "CVE-2015-7647",
    "CVE-2015-7648"
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2015-0404.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=16970"
    },
    {
      "type": "WEB",
      "url": "https://helpx.adobe.com/security/products/flash-player/apsb15-27.html"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:5",
        "name": "flash-player-plugin",
        "purl": "pkg:rpm/mageia/flash-player-plugin?arch=source&distro=mageia-5"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "11.2.202.540-1.mga5.nonfree"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "nonfree"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
