{
  "schema_version": "1.7.0",
  "id": "MGASA-2016-0251",
  "published": "2016-07-12T19:49:52Z",
  "modified": "2016-07-12T19:46:24Z",
  "summary": "Updated flash-player-plugin packages fix 52 security vulnerabilities",
  "details": "Adobe Flash Player 11.2.202.632 contains fixes to critical security \nvulnerabilities found in earlier versions that could potentially allow an \nattacker to take control of the affected system.\n\nThis update resolves a race condition vulnerability that could lead to \ninformation disclosure (CVE-2016-4247).\n\nThis update resolves type confusion vulnerabilities that could lead to code \nexecution (CVE-2016-4223, CVE-2016-4224, CVE-2016-4225).\n\nThis update resolves use-after-free vulnerabilities that could lead to code \nexecution (CVE-2016-4173, CVE-2016-4174, CVE-2016-4222, CVE-2016-4226, \nCVE-2016-4227, CVE-2016-4228, CVE-2016-4229, CVE-2016-4230, CVE-2016-4231, \nCVE-2016-4248).\n\nThis update resolves a heap buffer overflow vulnerability that could lead \nto code execution (CVE-2016-4249).\n\nThis update resolves memory corruption vulnerabilities that could lead to \ncode execution (CVE-2016-4172, CVE-2016-4175, CVE-2016-4179, CVE-2016-4180, \nCVE-2016-4181, CVE-2016-4182, CVE-2016-4183, CVE-2016-4184, CVE-2016-4185, \nCVE-2016-4186, CVE-2016-4187, CVE-2016-4188, CVE-2016-4189, CVE-2016-4190, \nCVE-2016-4217, CVE-2016-4218, CVE-2016-4219, CVE-2016-4220, CVE-2016-4221, \nCVE-2016-4233, CVE-2016-4234, CVE-2016-4235, CVE-2016-4236, CVE-2016-4237, \nCVE-2016-4238, CVE-2016-4239, CVE-2016-4240, CVE-2016-4241, CVE-2016-4242, \nCVE-2016-4243, CVE-2016-4244, CVE-2016-4245, CVE-2016-4246).\n\nThis update resolves a memory leak vulnerability (CVE-2016-4232).\n\nThis update resolves stack corruption vulnerabilities that could lead to \ncode execution (CVE-2016-4176, CVE-2016-4177).\n\nThis update resolves a security bypass vulnerability that could lead to \ninformation disclosure (CVE-2016-4178)\n",
  "upstream": [
    "CVE-2016-4172",
    "CVE-2016-4173",
    "CVE-2016-4174",
    "CVE-2016-4175",
    "CVE-2016-4176",
    "CVE-2016-4177",
    "CVE-2016-4178",
    "CVE-2016-4179",
    "CVE-2016-4180",
    "CVE-2016-4181",
    "CVE-2016-4182",
    "CVE-2016-4183",
    "CVE-2016-4184",
    "CVE-2016-4185",
    "CVE-2016-4186",
    "CVE-2016-4187",
    "CVE-2016-4188",
    "CVE-2016-4189",
    "CVE-2016-4190",
    "CVE-2016-4217",
    "CVE-2016-4218",
    "CVE-2016-4219",
    "CVE-2016-4220",
    "CVE-2016-4221",
    "CVE-2016-4222",
    "CVE-2016-4223",
    "CVE-2016-4224",
    "CVE-2016-4225",
    "CVE-2016-4226",
    "CVE-2016-4227",
    "CVE-2016-4228",
    "CVE-2016-4229",
    "CVE-2016-4230",
    "CVE-2016-4231",
    "CVE-2016-4232",
    "CVE-2016-4233",
    "CVE-2016-4234",
    "CVE-2016-4235",
    "CVE-2016-4236",
    "CVE-2016-4237",
    "CVE-2016-4238",
    "CVE-2016-4239",
    "CVE-2016-4240",
    "CVE-2016-4241",
    "CVE-2016-4242",
    "CVE-2016-4243",
    "CVE-2016-4244",
    "CVE-2016-4245",
    "CVE-2016-4246",
    "CVE-2016-4247",
    "CVE-2016-4248",
    "CVE-2016-4249"
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2016-0251.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=18933"
    },
    {
      "type": "WEB",
      "url": "https://helpx.adobe.com/security/products/flash-player/apsb16-25.html"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:5",
        "name": "flash-player-plugin",
        "purl": "pkg:rpm/mageia/flash-player-plugin?arch=source&distro=mageia-5"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "11.2.202.632-1.mga5.nonfree"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "nonfree"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
