{
  "schema_version": "1.7.0",
  "id": "MGASA-2016-0173",
  "published": "2016-05-12T20:00:19Z",
  "modified": "2016-05-12T19:54:32Z",
  "summary": "Updated flash-player-plugin packages fix security vulnerability",
  "details": "Adobe Flash Player 11.2.202.621 contains fixes to critical security\nvulnerabilities found in earlier versions that could potentially allow an\nattacker to take control of the affected system.\n\nThis update resolves type confusion vulnerabilities that could lead to\ncode execution (CVE-2016-1105, CVE-2016-4117).\n\nThis update resolves use-after-free vulnerabilities that could lead to\ncode execution (CVE-2016-1097, CVE-2016-1106, CVE-2016-1107,\nCVE-2016-1108, CVE-2016-1109, CVE-2016-1110, CVE-2016-4108,\nCVE-2016-4110).\n\nThis update resolves a heap buffer overflow vulnerability that could lead\nto code execution (CVE-2016-1101).\n\nThis update resolves a buffer overflow vulnerability that could lead to\ncode execution (CVE-2016-1103).\n\nThis update resolves memory corruption vulnerabilities that could lead to\ncode execution (CVE-2016-1096, CVE-2016-1098, CVE-2016-1099,\nCVE-2016-1100, CVE-2016-1102, CVE-2016-1104, CVE-2016-4109, CVE-2016-4111,\nCVE-2016-4112, CVE-2016-4113, CVE-2016-4114, CVE-2016-4115).\n\nThis update resolves a vulnerability in the directory search path used to\nfind resources that could lead to code execution (CVE-2016-4116).\n\nAdobe reports that an exploit for CVE-2016-4117 exists in the wild.\n",
  "upstream": [
    "CVE-2016-1096",
    "CVE-2016-1097",
    "CVE-2016-1098",
    "CVE-2016-1099",
    "CVE-2016-1100",
    "CVE-2016-1101",
    "CVE-2016-1102",
    "CVE-2016-1103",
    "CVE-2016-1104",
    "CVE-2016-1105",
    "CVE-2016-1106",
    "CVE-2016-1107",
    "CVE-2016-1108",
    "CVE-2016-1109",
    "CVE-2016-1110",
    "CVE-2016-4108",
    "CVE-2016-4109",
    "CVE-2016-4110",
    "CVE-2016-4111",
    "CVE-2016-4112",
    "CVE-2016-4113",
    "CVE-2016-4114",
    "CVE-2016-4115",
    "CVE-2016-4116",
    "CVE-2016-4117"
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2016-0173.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=18448"
    },
    {
      "type": "WEB",
      "url": "https://helpx.adobe.com/security/products/flash-player/apsb16-15.html"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:5",
        "name": "flash-player-plugin",
        "purl": "pkg:rpm/mageia/flash-player-plugin?arch=source&distro=mageia-5"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "11.2.202.621-1.mga5.nonfree"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "nonfree"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
