VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-201503-0378 CVE-2015-0333 Adobe Flash Player Vulnerable to arbitrary code execution CVSS V2: 10.0
CVSS V3: -
Severity: HIGH
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0332, CVE-2015-0335, and CVE-2015-0339. Failed exploit attempts will likely result in denial-of-service conditions. The product enables viewing of applications, content and video across screens and browsers. Background ========== The Adobe Flash Player is a renderer for the SWF file format, which is commonly used to provide interactive websites. Please review the CVE identifiers referenced below for details. Workaround ========== There is no known workaround at this time. Resolution ========== All adobe-flash users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v ">=www-plugins/adobe-flash-11.2.202.451" References ========== [ 1 ] CVE-2015-0332 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0332 [ 2 ] CVE-2015-0333 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0333 [ 3 ] CVE-2015-0334 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0334 [ 4 ] CVE-2015-0335 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0335 [ 5 ] CVE-2015-0336 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0336 [ 6 ] CVE-2015-0337 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0337 [ 7 ] CVE-2015-0338 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0338 [ 8 ] CVE-2015-0339 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0339 [ 9 ] CVE-2015-0340 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0340 [ 10 ] CVE-2015-0341 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0341 [ 11 ] CVE-2015-0342 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0342 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201503-09 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2015 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. http://creativecommons.org/licenses/by-sa/2.5 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ===================================================================== Red Hat Security Advisory Synopsis: Critical: flash-plugin security update Advisory ID: RHSA-2015:0697-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://rhn.redhat.com/errata/RHSA-2015-0697.html Issue date: 2015-03-17 CVE Names: CVE-2015-0332 CVE-2015-0333 CVE-2015-0334 CVE-2015-0335 CVE-2015-0336 CVE-2015-0337 CVE-2015-0338 CVE-2015-0339 CVE-2015-0340 CVE-2015-0341 CVE-2015-0342 ===================================================================== 1. Summary: An updated Adobe Flash Player package that fixes multiple security issues is now available for Red Hat Enterprise Linux 5 and 6 Supplementary. Red Hat Product Security has rated this update as having Critical security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop Supplementary (v. 5) - i386, x86_64 Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 5) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, x86_64 3. Description: The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. These vulnerabilities are detailed in the Adobe Security Bulletin APSB15-05 listed in the References section. Multiple flaws were found in the way flash-plugin displayed certain SWF content. An attacker could use these flaws to create a specially crafted SWF file that would cause flash-plugin to crash or, potentially, execute arbitrary code when the victim loaded a page containing the malicious SWF content. (CVE-2015-0332, CVE-2015-0333, CVE-2015-0335, CVE-2015-0339, CVE-2015-0334, CVE-2015-0336, CVE-2015-0338, CVE-2015-0341, CVE-2015-0342) This update also fixes a cross-domain policy bypass flaw and a file upload restriction bypass flaw. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1201636 - flash-plugin: multiple code execution issues fixed in APSB15-05 1201649 - CVE-2015-0337 flash-plugin: cross-domain policy bypass (APSB15-05) 1201651 - CVE-2015-0340 flash-plugin: file upload restriction bypass (APSB15-05) 6. Package List: Red Hat Enterprise Linux Desktop Supplementary (v. 5): i386: flash-plugin-11.2.202.451-1.el5.i386.rpm x86_64: flash-plugin-11.2.202.451-1.el5.i386.rpm Red Hat Enterprise Linux Server Supplementary (v. 5): i386: flash-plugin-11.2.202.451-1.el5.i386.rpm x86_64: flash-plugin-11.2.202.451-1.el5.i386.rpm Red Hat Enterprise Linux Desktop Supplementary (v. 6): i386: flash-plugin-11.2.202.451-1.el6.i686.rpm x86_64: flash-plugin-11.2.202.451-1.el6.i686.rpm Red Hat Enterprise Linux Server Supplementary (v. 6): i386: flash-plugin-11.2.202.451-1.el6.i686.rpm x86_64: flash-plugin-11.2.202.451-1.el6.i686.rpm Red Hat Enterprise Linux Workstation Supplementary (v. 6): i386: flash-plugin-11.2.202.451-1.el6.i686.rpm x86_64: flash-plugin-11.2.202.451-1.el6.i686.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2015-0332 https://access.redhat.com/security/cve/CVE-2015-0333 https://access.redhat.com/security/cve/CVE-2015-0334 https://access.redhat.com/security/cve/CVE-2015-0335 https://access.redhat.com/security/cve/CVE-2015-0336 https://access.redhat.com/security/cve/CVE-2015-0337 https://access.redhat.com/security/cve/CVE-2015-0338 https://access.redhat.com/security/cve/CVE-2015-0339 https://access.redhat.com/security/cve/CVE-2015-0340 https://access.redhat.com/security/cve/CVE-2015-0341 https://access.redhat.com/security/cve/CVE-2015-0342 https://access.redhat.com/security/updates/classification/#critical https://helpx.adobe.com/security/products/flash-player/apsb15-05.html 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2015 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFVCFmyXlSAg2UNWIIRArVvAKCjJLAKXJvnMOZ5a5IBxmKVEPZu6QCfemGc 9kdM+Q/ZOQRcHTfQ3iZRj3s= =8M6g -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce
VAR-201503-0071 CVE-2015-0982 Schneider Electric Pelco DS-NVs of DLL Vulnerable to buffer overflow CVSS V2: 7.5
CVSS V3: -
Severity: HIGH
Buffer overflow in an unspecified DLL in Schneider Electric Pelco DS-NVs before 7.8.90 allows remote attackers to execute arbitrary code via unspecified vectors. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.The specific flaw exists within the Rvctl.RVControl.1 ActiveX Control in rvctl.dll. The control does not check the length of an attacker-supplied string in the SetText method before copying it into a fixed length buffer on the stack. This allows an attacker to execute arbitrary code in the context of the browser process. Schneider Electric Pelco DS-NVs is a set of IP video management software from Schneider Electric of France. Schneider Electric DS-NVs are prone to a stack buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input before copying it into a fixed-size buffer. Failed exploit attempts will likely result in denial-of-service conditions
VAR-201503-0164 CVE-2015-0660 Cisco TelePresence Server on Virtual Machine In software root Any at authority OS Command execution vulnerability CVSS V2: 7.2
CVSS V3: -
Severity: HIGH
Cisco Virtual TelePresence Server Software does not properly restrict use of the serial port, which allows local users to execute arbitrary OS commands as root by leveraging vSphere controller administrative privileges, aka Bug ID CSCus61123. Supplementary information : CWE Vulnerability type by CWE-284: Improper Access Control ( Inappropriate access control ) Has been identified. A local attacker may exploit this issue to gain shell access of the underlying operating system with root privileges. Successful exploits may result in complete system compromise. This issue being tracked by Cisco Bug ID CSCus61123. The software provides functions such as audio and video spaces
VAR-201503-0387 CVE-2015-0342 Adobe Flash Player Vulnerable to arbitrary code execution CVSS V2: 10.0
CVSS V3: -
Severity: HIGH
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0341. This vulnerability CVE-2015-0341 Is a different vulnerability. Supplementary information : CWE Vulnerability type by CWE-416: Use-after-free ( Use of freed memory ) Has been identified. http://cwe.mitre.org/data/definitions/416.htmlAn attacker could execute arbitrary code. Failed exploit attempts will likely cause a denial-of-service condition. The product enables viewing of applications, content and video across screens and browsers. Background ========== The Adobe Flash Player is a renderer for the SWF file format, which is commonly used to provide interactive websites. Please review the CVE identifiers referenced below for details. Impact ====== A remote attacker could possibly execute arbitrary code with the privileges of the process, cause a Denial of Service condition, or bypass security restrictions. Workaround ========== There is no known workaround at this time. Resolution ========== All adobe-flash users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v ">=www-plugins/adobe-flash-11.2.202.451" References ========== [ 1 ] CVE-2015-0332 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0332 [ 2 ] CVE-2015-0333 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0333 [ 3 ] CVE-2015-0334 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0334 [ 4 ] CVE-2015-0335 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0335 [ 5 ] CVE-2015-0336 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0336 [ 6 ] CVE-2015-0337 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0337 [ 7 ] CVE-2015-0338 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0338 [ 8 ] CVE-2015-0339 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0339 [ 9 ] CVE-2015-0340 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0340 [ 10 ] CVE-2015-0341 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0341 [ 11 ] CVE-2015-0342 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0342 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201503-09 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2015 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. http://creativecommons.org/licenses/by-sa/2.5 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ===================================================================== Red Hat Security Advisory Synopsis: Critical: flash-plugin security update Advisory ID: RHSA-2015:0697-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://rhn.redhat.com/errata/RHSA-2015-0697.html Issue date: 2015-03-17 CVE Names: CVE-2015-0332 CVE-2015-0333 CVE-2015-0334 CVE-2015-0335 CVE-2015-0336 CVE-2015-0337 CVE-2015-0338 CVE-2015-0339 CVE-2015-0340 CVE-2015-0341 CVE-2015-0342 ===================================================================== 1. Summary: An updated Adobe Flash Player package that fixes multiple security issues is now available for Red Hat Enterprise Linux 5 and 6 Supplementary. Red Hat Product Security has rated this update as having Critical security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop Supplementary (v. 5) - i386, x86_64 Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 5) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, x86_64 3. Description: The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. These vulnerabilities are detailed in the Adobe Security Bulletin APSB15-05 listed in the References section. Multiple flaws were found in the way flash-plugin displayed certain SWF content. An attacker could use these flaws to create a specially crafted SWF file that would cause flash-plugin to crash or, potentially, execute arbitrary code when the victim loaded a page containing the malicious SWF content. (CVE-2015-0332, CVE-2015-0333, CVE-2015-0335, CVE-2015-0339, CVE-2015-0334, CVE-2015-0336, CVE-2015-0338, CVE-2015-0341, CVE-2015-0342) This update also fixes a cross-domain policy bypass flaw and a file upload restriction bypass flaw. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1201636 - flash-plugin: multiple code execution issues fixed in APSB15-05 1201649 - CVE-2015-0337 flash-plugin: cross-domain policy bypass (APSB15-05) 1201651 - CVE-2015-0340 flash-plugin: file upload restriction bypass (APSB15-05) 6. Package List: Red Hat Enterprise Linux Desktop Supplementary (v. 5): i386: flash-plugin-11.2.202.451-1.el5.i386.rpm x86_64: flash-plugin-11.2.202.451-1.el5.i386.rpm Red Hat Enterprise Linux Server Supplementary (v. 5): i386: flash-plugin-11.2.202.451-1.el5.i386.rpm x86_64: flash-plugin-11.2.202.451-1.el5.i386.rpm Red Hat Enterprise Linux Desktop Supplementary (v. 6): i386: flash-plugin-11.2.202.451-1.el6.i686.rpm x86_64: flash-plugin-11.2.202.451-1.el6.i686.rpm Red Hat Enterprise Linux Server Supplementary (v. 6): i386: flash-plugin-11.2.202.451-1.el6.i686.rpm x86_64: flash-plugin-11.2.202.451-1.el6.i686.rpm Red Hat Enterprise Linux Workstation Supplementary (v. 6): i386: flash-plugin-11.2.202.451-1.el6.i686.rpm x86_64: flash-plugin-11.2.202.451-1.el6.i686.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2015-0332 https://access.redhat.com/security/cve/CVE-2015-0333 https://access.redhat.com/security/cve/CVE-2015-0334 https://access.redhat.com/security/cve/CVE-2015-0335 https://access.redhat.com/security/cve/CVE-2015-0336 https://access.redhat.com/security/cve/CVE-2015-0337 https://access.redhat.com/security/cve/CVE-2015-0338 https://access.redhat.com/security/cve/CVE-2015-0339 https://access.redhat.com/security/cve/CVE-2015-0340 https://access.redhat.com/security/cve/CVE-2015-0341 https://access.redhat.com/security/cve/CVE-2015-0342 https://access.redhat.com/security/updates/classification/#critical https://helpx.adobe.com/security/products/flash-player/apsb15-05.html 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2015 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFVCFmyXlSAg2UNWIIRArVvAKCjJLAKXJvnMOZ5a5IBxmKVEPZu6QCfemGc 9kdM+Q/ZOQRcHTfQ3iZRj3s= =8M6g -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce
VAR-201503-0386 CVE-2015-0341 Adobe Flash Player Vulnerable to arbitrary code execution CVSS V2: 10.0
CVSS V3: -
Severity: HIGH
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0342. This vulnerability CVE-2015-0342 Is a different vulnerability. Supplementary information : CWE Vulnerability type by CWE-416: Use-after-free ( Use of freed memory ) Has been identified. http://cwe.mitre.org/data/definitions/416.htmlAn attacker could execute arbitrary code. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.The specific flaw exists within the handling of AVSS objects. By calling Load multiple times an attacker can force a dangling pointer to be reused after it has been freed. Failed exploit attempts will likely cause a denial-of-service condition. The product enables viewing of applications, content and video across screens and browsers. Background ========== The Adobe Flash Player is a renderer for the SWF file format, which is commonly used to provide interactive websites. Please review the CVE identifiers referenced below for details. Impact ====== A remote attacker could possibly execute arbitrary code with the privileges of the process, cause a Denial of Service condition, or bypass security restrictions. Workaround ========== There is no known workaround at this time. Resolution ========== All adobe-flash users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v ">=www-plugins/adobe-flash-11.2.202.451" References ========== [ 1 ] CVE-2015-0332 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0332 [ 2 ] CVE-2015-0333 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0333 [ 3 ] CVE-2015-0334 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0334 [ 4 ] CVE-2015-0335 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0335 [ 5 ] CVE-2015-0336 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0336 [ 6 ] CVE-2015-0337 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0337 [ 7 ] CVE-2015-0338 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0338 [ 8 ] CVE-2015-0339 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0339 [ 9 ] CVE-2015-0340 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0340 [ 10 ] CVE-2015-0341 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0341 [ 11 ] CVE-2015-0342 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0342 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201503-09 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2015 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. http://creativecommons.org/licenses/by-sa/2.5 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ===================================================================== Red Hat Security Advisory Synopsis: Critical: flash-plugin security update Advisory ID: RHSA-2015:0697-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://rhn.redhat.com/errata/RHSA-2015-0697.html Issue date: 2015-03-17 CVE Names: CVE-2015-0332 CVE-2015-0333 CVE-2015-0334 CVE-2015-0335 CVE-2015-0336 CVE-2015-0337 CVE-2015-0338 CVE-2015-0339 CVE-2015-0340 CVE-2015-0341 CVE-2015-0342 ===================================================================== 1. Summary: An updated Adobe Flash Player package that fixes multiple security issues is now available for Red Hat Enterprise Linux 5 and 6 Supplementary. Red Hat Product Security has rated this update as having Critical security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop Supplementary (v. 5) - i386, x86_64 Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 5) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, x86_64 3. Description: The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. These vulnerabilities are detailed in the Adobe Security Bulletin APSB15-05 listed in the References section. Multiple flaws were found in the way flash-plugin displayed certain SWF content. An attacker could use these flaws to create a specially crafted SWF file that would cause flash-plugin to crash or, potentially, execute arbitrary code when the victim loaded a page containing the malicious SWF content. (CVE-2015-0332, CVE-2015-0333, CVE-2015-0335, CVE-2015-0339, CVE-2015-0334, CVE-2015-0336, CVE-2015-0338, CVE-2015-0341, CVE-2015-0342) This update also fixes a cross-domain policy bypass flaw and a file upload restriction bypass flaw. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1201636 - flash-plugin: multiple code execution issues fixed in APSB15-05 1201649 - CVE-2015-0337 flash-plugin: cross-domain policy bypass (APSB15-05) 1201651 - CVE-2015-0340 flash-plugin: file upload restriction bypass (APSB15-05) 6. Package List: Red Hat Enterprise Linux Desktop Supplementary (v. 5): i386: flash-plugin-11.2.202.451-1.el5.i386.rpm x86_64: flash-plugin-11.2.202.451-1.el5.i386.rpm Red Hat Enterprise Linux Server Supplementary (v. 5): i386: flash-plugin-11.2.202.451-1.el5.i386.rpm x86_64: flash-plugin-11.2.202.451-1.el5.i386.rpm Red Hat Enterprise Linux Desktop Supplementary (v. 6): i386: flash-plugin-11.2.202.451-1.el6.i686.rpm x86_64: flash-plugin-11.2.202.451-1.el6.i686.rpm Red Hat Enterprise Linux Server Supplementary (v. 6): i386: flash-plugin-11.2.202.451-1.el6.i686.rpm x86_64: flash-plugin-11.2.202.451-1.el6.i686.rpm Red Hat Enterprise Linux Workstation Supplementary (v. 6): i386: flash-plugin-11.2.202.451-1.el6.i686.rpm x86_64: flash-plugin-11.2.202.451-1.el6.i686.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2015-0332 https://access.redhat.com/security/cve/CVE-2015-0333 https://access.redhat.com/security/cve/CVE-2015-0334 https://access.redhat.com/security/cve/CVE-2015-0335 https://access.redhat.com/security/cve/CVE-2015-0336 https://access.redhat.com/security/cve/CVE-2015-0337 https://access.redhat.com/security/cve/CVE-2015-0338 https://access.redhat.com/security/cve/CVE-2015-0339 https://access.redhat.com/security/cve/CVE-2015-0340 https://access.redhat.com/security/cve/CVE-2015-0341 https://access.redhat.com/security/cve/CVE-2015-0342 https://access.redhat.com/security/updates/classification/#critical https://helpx.adobe.com/security/products/flash-player/apsb15-05.html 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2015 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFVCFmyXlSAg2UNWIIRArVvAKCjJLAKXJvnMOZ5a5IBxmKVEPZu6QCfemGc 9kdM+Q/ZOQRcHTfQ3iZRj3s= =8M6g -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce
VAR-201503-0385 CVE-2015-0340 Adobe Flash Player Vulnerable to bypassing file upload restrictions CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows remote attackers to bypass intended file-upload restrictions via unspecified vectors. Adobe Flash Player Contains a vulnerability that bypasses file upload restrictions. Supplementary information : CWE Vulnerability type by CWE-434: Unrestricted Upload of File with Dangerous Type ( Unlimited upload of dangerous types of files ) Has been identified. http://cwe.mitre.org/data/definitions/434.htmlA third party may be able to bypass file upload restrictions. Attackers can exploit this issue to bypass certain security restrictions and perform unauthorized actions; this may aid in launching further attacks. The product enables viewing of applications, content and video across screens and browsers. Please review the CVE identifiers referenced below for details. Impact ====== A remote attacker could possibly execute arbitrary code with the privileges of the process, cause a Denial of Service condition, or bypass security restrictions. Workaround ========== There is no known workaround at this time. Resolution ========== All adobe-flash users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v ">=www-plugins/adobe-flash-11.2.202.451" References ========== [ 1 ] CVE-2015-0332 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0332 [ 2 ] CVE-2015-0333 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0333 [ 3 ] CVE-2015-0334 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0334 [ 4 ] CVE-2015-0335 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0335 [ 5 ] CVE-2015-0336 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0336 [ 6 ] CVE-2015-0337 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0337 [ 7 ] CVE-2015-0338 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0338 [ 8 ] CVE-2015-0339 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0339 [ 9 ] CVE-2015-0340 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0340 [ 10 ] CVE-2015-0341 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0341 [ 11 ] CVE-2015-0342 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0342 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201503-09 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2015 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. http://creativecommons.org/licenses/by-sa/2.5 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ===================================================================== Red Hat Security Advisory Synopsis: Critical: flash-plugin security update Advisory ID: RHSA-2015:0697-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://rhn.redhat.com/errata/RHSA-2015-0697.html Issue date: 2015-03-17 CVE Names: CVE-2015-0332 CVE-2015-0333 CVE-2015-0334 CVE-2015-0335 CVE-2015-0336 CVE-2015-0337 CVE-2015-0338 CVE-2015-0339 CVE-2015-0340 CVE-2015-0341 CVE-2015-0342 ===================================================================== 1. Summary: An updated Adobe Flash Player package that fixes multiple security issues is now available for Red Hat Enterprise Linux 5 and 6 Supplementary. Red Hat Product Security has rated this update as having Critical security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop Supplementary (v. 5) - i386, x86_64 Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 5) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, x86_64 3. These vulnerabilities are detailed in the Adobe Security Bulletin APSB15-05 listed in the References section. Multiple flaws were found in the way flash-plugin displayed certain SWF content. An attacker could use these flaws to create a specially crafted SWF file that would cause flash-plugin to crash or, potentially, execute arbitrary code when the victim loaded a page containing the malicious SWF content. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Package List: Red Hat Enterprise Linux Desktop Supplementary (v. 5): i386: flash-plugin-11.2.202.451-1.el5.i386.rpm x86_64: flash-plugin-11.2.202.451-1.el5.i386.rpm Red Hat Enterprise Linux Server Supplementary (v. 5): i386: flash-plugin-11.2.202.451-1.el5.i386.rpm x86_64: flash-plugin-11.2.202.451-1.el5.i386.rpm Red Hat Enterprise Linux Desktop Supplementary (v. 6): i386: flash-plugin-11.2.202.451-1.el6.i686.rpm x86_64: flash-plugin-11.2.202.451-1.el6.i686.rpm Red Hat Enterprise Linux Server Supplementary (v. 6): i386: flash-plugin-11.2.202.451-1.el6.i686.rpm x86_64: flash-plugin-11.2.202.451-1.el6.i686.rpm Red Hat Enterprise Linux Workstation Supplementary (v. 6): i386: flash-plugin-11.2.202.451-1.el6.i686.rpm x86_64: flash-plugin-11.2.202.451-1.el6.i686.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2015-0332 https://access.redhat.com/security/cve/CVE-2015-0333 https://access.redhat.com/security/cve/CVE-2015-0334 https://access.redhat.com/security/cve/CVE-2015-0335 https://access.redhat.com/security/cve/CVE-2015-0336 https://access.redhat.com/security/cve/CVE-2015-0337 https://access.redhat.com/security/cve/CVE-2015-0338 https://access.redhat.com/security/cve/CVE-2015-0339 https://access.redhat.com/security/cve/CVE-2015-0340 https://access.redhat.com/security/cve/CVE-2015-0341 https://access.redhat.com/security/cve/CVE-2015-0342 https://access.redhat.com/security/updates/classification/#critical https://helpx.adobe.com/security/products/flash-player/apsb15-05.html 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2015 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFVCFmyXlSAg2UNWIIRArVvAKCjJLAKXJvnMOZ5a5IBxmKVEPZu6QCfemGc 9kdM+Q/ZOQRcHTfQ3iZRj3s= =8M6g -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce
VAR-201503-0384 CVE-2015-0339 Adobe Flash Player Vulnerable to arbitrary code execution CVSS V2: 10.0
CVSS V3: -
Severity: HIGH
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0332, CVE-2015-0333, and CVE-2015-0335. Failed exploit attempts will likely result in denial-of-service conditions. The product enables viewing of applications, content and video across screens and browsers. Background ========== The Adobe Flash Player is a renderer for the SWF file format, which is commonly used to provide interactive websites. Please review the CVE identifiers referenced below for details. Workaround ========== There is no known workaround at this time. Resolution ========== All adobe-flash users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v ">=www-plugins/adobe-flash-11.2.202.451" References ========== [ 1 ] CVE-2015-0332 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0332 [ 2 ] CVE-2015-0333 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0333 [ 3 ] CVE-2015-0334 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0334 [ 4 ] CVE-2015-0335 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0335 [ 5 ] CVE-2015-0336 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0336 [ 6 ] CVE-2015-0337 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0337 [ 7 ] CVE-2015-0338 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0338 [ 8 ] CVE-2015-0339 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0339 [ 9 ] CVE-2015-0340 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0340 [ 10 ] CVE-2015-0341 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0341 [ 11 ] CVE-2015-0342 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0342 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201503-09 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2015 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. http://creativecommons.org/licenses/by-sa/2.5 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ===================================================================== Red Hat Security Advisory Synopsis: Critical: flash-plugin security update Advisory ID: RHSA-2015:0697-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://rhn.redhat.com/errata/RHSA-2015-0697.html Issue date: 2015-03-17 CVE Names: CVE-2015-0332 CVE-2015-0333 CVE-2015-0334 CVE-2015-0335 CVE-2015-0336 CVE-2015-0337 CVE-2015-0338 CVE-2015-0339 CVE-2015-0340 CVE-2015-0341 CVE-2015-0342 ===================================================================== 1. Summary: An updated Adobe Flash Player package that fixes multiple security issues is now available for Red Hat Enterprise Linux 5 and 6 Supplementary. Red Hat Product Security has rated this update as having Critical security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop Supplementary (v. 5) - i386, x86_64 Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 5) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, x86_64 3. Description: The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. These vulnerabilities are detailed in the Adobe Security Bulletin APSB15-05 listed in the References section. Multiple flaws were found in the way flash-plugin displayed certain SWF content. An attacker could use these flaws to create a specially crafted SWF file that would cause flash-plugin to crash or, potentially, execute arbitrary code when the victim loaded a page containing the malicious SWF content. (CVE-2015-0332, CVE-2015-0333, CVE-2015-0335, CVE-2015-0339, CVE-2015-0334, CVE-2015-0336, CVE-2015-0338, CVE-2015-0341, CVE-2015-0342) This update also fixes a cross-domain policy bypass flaw and a file upload restriction bypass flaw. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1201636 - flash-plugin: multiple code execution issues fixed in APSB15-05 1201649 - CVE-2015-0337 flash-plugin: cross-domain policy bypass (APSB15-05) 1201651 - CVE-2015-0340 flash-plugin: file upload restriction bypass (APSB15-05) 6. Package List: Red Hat Enterprise Linux Desktop Supplementary (v. 5): i386: flash-plugin-11.2.202.451-1.el5.i386.rpm x86_64: flash-plugin-11.2.202.451-1.el5.i386.rpm Red Hat Enterprise Linux Server Supplementary (v. 5): i386: flash-plugin-11.2.202.451-1.el5.i386.rpm x86_64: flash-plugin-11.2.202.451-1.el5.i386.rpm Red Hat Enterprise Linux Desktop Supplementary (v. 6): i386: flash-plugin-11.2.202.451-1.el6.i686.rpm x86_64: flash-plugin-11.2.202.451-1.el6.i686.rpm Red Hat Enterprise Linux Server Supplementary (v. 6): i386: flash-plugin-11.2.202.451-1.el6.i686.rpm x86_64: flash-plugin-11.2.202.451-1.el6.i686.rpm Red Hat Enterprise Linux Workstation Supplementary (v. 6): i386: flash-plugin-11.2.202.451-1.el6.i686.rpm x86_64: flash-plugin-11.2.202.451-1.el6.i686.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2015-0332 https://access.redhat.com/security/cve/CVE-2015-0333 https://access.redhat.com/security/cve/CVE-2015-0334 https://access.redhat.com/security/cve/CVE-2015-0335 https://access.redhat.com/security/cve/CVE-2015-0336 https://access.redhat.com/security/cve/CVE-2015-0337 https://access.redhat.com/security/cve/CVE-2015-0338 https://access.redhat.com/security/cve/CVE-2015-0339 https://access.redhat.com/security/cve/CVE-2015-0340 https://access.redhat.com/security/cve/CVE-2015-0341 https://access.redhat.com/security/cve/CVE-2015-0342 https://access.redhat.com/security/updates/classification/#critical https://helpx.adobe.com/security/products/flash-player/apsb15-05.html 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2015 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFVCFmyXlSAg2UNWIIRArVvAKCjJLAKXJvnMOZ5a5IBxmKVEPZu6QCfemGc 9kdM+Q/ZOQRcHTfQ3iZRj3s= =8M6g -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce
VAR-201503-0382 CVE-2015-0337 Adobe Flash Player Vulnerabilities that bypass the same origin policy CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows remote attackers to bypass the Same Origin Policy via unspecified vectors. An attacker can exploit this issue to bypass certain same-origin policy restrictions, which may aid in further attacks. The product enables viewing of applications, content and video across screens and browsers. Background ========== The Adobe Flash Player is a renderer for the SWF file format, which is commonly used to provide interactive websites. Please review the CVE identifiers referenced below for details. Impact ====== A remote attacker could possibly execute arbitrary code with the privileges of the process, cause a Denial of Service condition, or bypass security restrictions. Workaround ========== There is no known workaround at this time. Resolution ========== All adobe-flash users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v ">=www-plugins/adobe-flash-11.2.202.451" References ========== [ 1 ] CVE-2015-0332 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0332 [ 2 ] CVE-2015-0333 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0333 [ 3 ] CVE-2015-0334 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0334 [ 4 ] CVE-2015-0335 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0335 [ 5 ] CVE-2015-0336 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0336 [ 6 ] CVE-2015-0337 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0337 [ 7 ] CVE-2015-0338 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0338 [ 8 ] CVE-2015-0339 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0339 [ 9 ] CVE-2015-0340 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0340 [ 10 ] CVE-2015-0341 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0341 [ 11 ] CVE-2015-0342 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0342 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201503-09 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2015 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. http://creativecommons.org/licenses/by-sa/2.5 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ===================================================================== Red Hat Security Advisory Synopsis: Critical: flash-plugin security update Advisory ID: RHSA-2015:0697-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://rhn.redhat.com/errata/RHSA-2015-0697.html Issue date: 2015-03-17 CVE Names: CVE-2015-0332 CVE-2015-0333 CVE-2015-0334 CVE-2015-0335 CVE-2015-0336 CVE-2015-0337 CVE-2015-0338 CVE-2015-0339 CVE-2015-0340 CVE-2015-0341 CVE-2015-0342 ===================================================================== 1. Summary: An updated Adobe Flash Player package that fixes multiple security issues is now available for Red Hat Enterprise Linux 5 and 6 Supplementary. Red Hat Product Security has rated this update as having Critical security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop Supplementary (v. 5) - i386, x86_64 Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 5) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, x86_64 3. Description: The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. These vulnerabilities are detailed in the Adobe Security Bulletin APSB15-05 listed in the References section. Multiple flaws were found in the way flash-plugin displayed certain SWF content. An attacker could use these flaws to create a specially crafted SWF file that would cause flash-plugin to crash or, potentially, execute arbitrary code when the victim loaded a page containing the malicious SWF content. (CVE-2015-0332, CVE-2015-0333, CVE-2015-0335, CVE-2015-0339, CVE-2015-0334, CVE-2015-0336, CVE-2015-0338, CVE-2015-0341, CVE-2015-0342) This update also fixes a cross-domain policy bypass flaw and a file upload restriction bypass flaw. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1201636 - flash-plugin: multiple code execution issues fixed in APSB15-05 1201649 - CVE-2015-0337 flash-plugin: cross-domain policy bypass (APSB15-05) 1201651 - CVE-2015-0340 flash-plugin: file upload restriction bypass (APSB15-05) 6. Package List: Red Hat Enterprise Linux Desktop Supplementary (v. 5): i386: flash-plugin-11.2.202.451-1.el5.i386.rpm x86_64: flash-plugin-11.2.202.451-1.el5.i386.rpm Red Hat Enterprise Linux Server Supplementary (v. 5): i386: flash-plugin-11.2.202.451-1.el5.i386.rpm x86_64: flash-plugin-11.2.202.451-1.el5.i386.rpm Red Hat Enterprise Linux Desktop Supplementary (v. 6): i386: flash-plugin-11.2.202.451-1.el6.i686.rpm x86_64: flash-plugin-11.2.202.451-1.el6.i686.rpm Red Hat Enterprise Linux Server Supplementary (v. 6): i386: flash-plugin-11.2.202.451-1.el6.i686.rpm x86_64: flash-plugin-11.2.202.451-1.el6.i686.rpm Red Hat Enterprise Linux Workstation Supplementary (v. 6): i386: flash-plugin-11.2.202.451-1.el6.i686.rpm x86_64: flash-plugin-11.2.202.451-1.el6.i686.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2015-0332 https://access.redhat.com/security/cve/CVE-2015-0333 https://access.redhat.com/security/cve/CVE-2015-0334 https://access.redhat.com/security/cve/CVE-2015-0335 https://access.redhat.com/security/cve/CVE-2015-0336 https://access.redhat.com/security/cve/CVE-2015-0337 https://access.redhat.com/security/cve/CVE-2015-0338 https://access.redhat.com/security/cve/CVE-2015-0339 https://access.redhat.com/security/cve/CVE-2015-0340 https://access.redhat.com/security/cve/CVE-2015-0341 https://access.redhat.com/security/cve/CVE-2015-0342 https://access.redhat.com/security/updates/classification/#critical https://helpx.adobe.com/security/products/flash-player/apsb15-05.html 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2015 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFVCFmyXlSAg2UNWIIRArVvAKCjJLAKXJvnMOZ5a5IBxmKVEPZu6QCfemGc 9kdM+Q/ZOQRcHTfQ3iZRj3s= =8M6g -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce
VAR-201503-0381 CVE-2015-0336 Adobe Flash Player Vulnerable to arbitrary code execution CVSS V2: 9.3
CVSS V3: -
Severity: HIGH
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015-0334. Failed exploit attempts will likely cause a denial-of-service condition. The product enables viewing of applications, content and video across screens and browsers. Background ========== The Adobe Flash Player is a renderer for the SWF file format, which is commonly used to provide interactive websites. Please review the CVE identifiers referenced below for details. Impact ====== A remote attacker could possibly execute arbitrary code with the privileges of the process, cause a Denial of Service condition, or bypass security restrictions. Workaround ========== There is no known workaround at this time. Resolution ========== All adobe-flash users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v ">=www-plugins/adobe-flash-11.2.202.451" References ========== [ 1 ] CVE-2015-0332 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0332 [ 2 ] CVE-2015-0333 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0333 [ 3 ] CVE-2015-0334 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0334 [ 4 ] CVE-2015-0335 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0335 [ 5 ] CVE-2015-0336 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0336 [ 6 ] CVE-2015-0337 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0337 [ 7 ] CVE-2015-0338 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0338 [ 8 ] CVE-2015-0339 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0339 [ 9 ] CVE-2015-0340 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0340 [ 10 ] CVE-2015-0341 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0341 [ 11 ] CVE-2015-0342 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0342 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201503-09 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2015 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. http://creativecommons.org/licenses/by-sa/2.5 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ===================================================================== Red Hat Security Advisory Synopsis: Critical: flash-plugin security update Advisory ID: RHSA-2015:0697-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://rhn.redhat.com/errata/RHSA-2015-0697.html Issue date: 2015-03-17 CVE Names: CVE-2015-0332 CVE-2015-0333 CVE-2015-0334 CVE-2015-0335 CVE-2015-0336 CVE-2015-0337 CVE-2015-0338 CVE-2015-0339 CVE-2015-0340 CVE-2015-0341 CVE-2015-0342 ===================================================================== 1. Summary: An updated Adobe Flash Player package that fixes multiple security issues is now available for Red Hat Enterprise Linux 5 and 6 Supplementary. Red Hat Product Security has rated this update as having Critical security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop Supplementary (v. 5) - i386, x86_64 Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 5) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, x86_64 3. These vulnerabilities are detailed in the Adobe Security Bulletin APSB15-05 listed in the References section. Multiple flaws were found in the way flash-plugin displayed certain SWF content. An attacker could use these flaws to create a specially crafted SWF file that would cause flash-plugin to crash or, potentially, execute arbitrary code when the victim loaded a page containing the malicious SWF content. (CVE-2015-0332, CVE-2015-0333, CVE-2015-0335, CVE-2015-0339, CVE-2015-0334, CVE-2015-0336, CVE-2015-0338, CVE-2015-0341, CVE-2015-0342) This update also fixes a cross-domain policy bypass flaw and a file upload restriction bypass flaw. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1201636 - flash-plugin: multiple code execution issues fixed in APSB15-05 1201649 - CVE-2015-0337 flash-plugin: cross-domain policy bypass (APSB15-05) 1201651 - CVE-2015-0340 flash-plugin: file upload restriction bypass (APSB15-05) 6. Package List: Red Hat Enterprise Linux Desktop Supplementary (v. 5): i386: flash-plugin-11.2.202.451-1.el5.i386.rpm x86_64: flash-plugin-11.2.202.451-1.el5.i386.rpm Red Hat Enterprise Linux Server Supplementary (v. 5): i386: flash-plugin-11.2.202.451-1.el5.i386.rpm x86_64: flash-plugin-11.2.202.451-1.el5.i386.rpm Red Hat Enterprise Linux Desktop Supplementary (v. 6): i386: flash-plugin-11.2.202.451-1.el6.i686.rpm x86_64: flash-plugin-11.2.202.451-1.el6.i686.rpm Red Hat Enterprise Linux Server Supplementary (v. 6): i386: flash-plugin-11.2.202.451-1.el6.i686.rpm x86_64: flash-plugin-11.2.202.451-1.el6.i686.rpm Red Hat Enterprise Linux Workstation Supplementary (v. 6): i386: flash-plugin-11.2.202.451-1.el6.i686.rpm x86_64: flash-plugin-11.2.202.451-1.el6.i686.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2015-0332 https://access.redhat.com/security/cve/CVE-2015-0333 https://access.redhat.com/security/cve/CVE-2015-0334 https://access.redhat.com/security/cve/CVE-2015-0335 https://access.redhat.com/security/cve/CVE-2015-0336 https://access.redhat.com/security/cve/CVE-2015-0337 https://access.redhat.com/security/cve/CVE-2015-0338 https://access.redhat.com/security/cve/CVE-2015-0339 https://access.redhat.com/security/cve/CVE-2015-0340 https://access.redhat.com/security/cve/CVE-2015-0341 https://access.redhat.com/security/cve/CVE-2015-0342 https://access.redhat.com/security/updates/classification/#critical https://helpx.adobe.com/security/products/flash-player/apsb15-05.html 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2015 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFVCFmyXlSAg2UNWIIRArVvAKCjJLAKXJvnMOZ5a5IBxmKVEPZu6QCfemGc 9kdM+Q/ZOQRcHTfQ3iZRj3s= =8M6g -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce
VAR-201503-0379 CVE-2015-0334 Adobe Flash Player Vulnerable to arbitrary code execution CVSS V2: 9.3
CVSS V3: -
Severity: HIGH
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015-0336. Failed exploit attempts will likely cause a denial-of-service condition. The product enables viewing of applications, content and video across screens and browsers. Background ========== The Adobe Flash Player is a renderer for the SWF file format, which is commonly used to provide interactive websites. Please review the CVE identifiers referenced below for details. Impact ====== A remote attacker could possibly execute arbitrary code with the privileges of the process, cause a Denial of Service condition, or bypass security restrictions. Workaround ========== There is no known workaround at this time. Resolution ========== All adobe-flash users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v ">=www-plugins/adobe-flash-11.2.202.451" References ========== [ 1 ] CVE-2015-0332 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0332 [ 2 ] CVE-2015-0333 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0333 [ 3 ] CVE-2015-0334 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0334 [ 4 ] CVE-2015-0335 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0335 [ 5 ] CVE-2015-0336 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0336 [ 6 ] CVE-2015-0337 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0337 [ 7 ] CVE-2015-0338 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0338 [ 8 ] CVE-2015-0339 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0339 [ 9 ] CVE-2015-0340 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0340 [ 10 ] CVE-2015-0341 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0341 [ 11 ] CVE-2015-0342 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0342 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201503-09 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2015 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. http://creativecommons.org/licenses/by-sa/2.5 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ===================================================================== Red Hat Security Advisory Synopsis: Critical: flash-plugin security update Advisory ID: RHSA-2015:0697-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://rhn.redhat.com/errata/RHSA-2015-0697.html Issue date: 2015-03-17 CVE Names: CVE-2015-0332 CVE-2015-0333 CVE-2015-0334 CVE-2015-0335 CVE-2015-0336 CVE-2015-0337 CVE-2015-0338 CVE-2015-0339 CVE-2015-0340 CVE-2015-0341 CVE-2015-0342 ===================================================================== 1. Summary: An updated Adobe Flash Player package that fixes multiple security issues is now available for Red Hat Enterprise Linux 5 and 6 Supplementary. Red Hat Product Security has rated this update as having Critical security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop Supplementary (v. 5) - i386, x86_64 Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 5) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, x86_64 3. These vulnerabilities are detailed in the Adobe Security Bulletin APSB15-05 listed in the References section. Multiple flaws were found in the way flash-plugin displayed certain SWF content. An attacker could use these flaws to create a specially crafted SWF file that would cause flash-plugin to crash or, potentially, execute arbitrary code when the victim loaded a page containing the malicious SWF content. (CVE-2015-0332, CVE-2015-0333, CVE-2015-0335, CVE-2015-0339, CVE-2015-0334, CVE-2015-0336, CVE-2015-0338, CVE-2015-0341, CVE-2015-0342) This update also fixes a cross-domain policy bypass flaw and a file upload restriction bypass flaw. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1201636 - flash-plugin: multiple code execution issues fixed in APSB15-05 1201649 - CVE-2015-0337 flash-plugin: cross-domain policy bypass (APSB15-05) 1201651 - CVE-2015-0340 flash-plugin: file upload restriction bypass (APSB15-05) 6. Package List: Red Hat Enterprise Linux Desktop Supplementary (v. 5): i386: flash-plugin-11.2.202.451-1.el5.i386.rpm x86_64: flash-plugin-11.2.202.451-1.el5.i386.rpm Red Hat Enterprise Linux Server Supplementary (v. 5): i386: flash-plugin-11.2.202.451-1.el5.i386.rpm x86_64: flash-plugin-11.2.202.451-1.el5.i386.rpm Red Hat Enterprise Linux Desktop Supplementary (v. 6): i386: flash-plugin-11.2.202.451-1.el6.i686.rpm x86_64: flash-plugin-11.2.202.451-1.el6.i686.rpm Red Hat Enterprise Linux Server Supplementary (v. 6): i386: flash-plugin-11.2.202.451-1.el6.i686.rpm x86_64: flash-plugin-11.2.202.451-1.el6.i686.rpm Red Hat Enterprise Linux Workstation Supplementary (v. 6): i386: flash-plugin-11.2.202.451-1.el6.i686.rpm x86_64: flash-plugin-11.2.202.451-1.el6.i686.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2015-0332 https://access.redhat.com/security/cve/CVE-2015-0333 https://access.redhat.com/security/cve/CVE-2015-0334 https://access.redhat.com/security/cve/CVE-2015-0335 https://access.redhat.com/security/cve/CVE-2015-0336 https://access.redhat.com/security/cve/CVE-2015-0337 https://access.redhat.com/security/cve/CVE-2015-0338 https://access.redhat.com/security/cve/CVE-2015-0339 https://access.redhat.com/security/cve/CVE-2015-0340 https://access.redhat.com/security/cve/CVE-2015-0341 https://access.redhat.com/security/cve/CVE-2015-0342 https://access.redhat.com/security/updates/classification/#critical https://helpx.adobe.com/security/products/flash-player/apsb15-05.html 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2015 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFVCFmyXlSAg2UNWIIRArVvAKCjJLAKXJvnMOZ5a5IBxmKVEPZu6QCfemGc 9kdM+Q/ZOQRcHTfQ3iZRj3s= =8M6g -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce
VAR-201503-0383 CVE-2015-0338 Adobe Flash Player Integer overflow vulnerability CVSS V2: 10.0
CVSS V3: -
Severity: HIGH
Integer overflow in Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code via unspecified vectors. Adobe Flash Player Contains an integer overflow vulnerability. Supplementary information : CWE Vulnerability type by CWE-190: Integer Overflow or Wraparound ( Integer overflow or wraparound ) Has been identified. http://cwe.mitre.org/data/definitions/190.htmlAn attacker could execute arbitrary code. Failed exploit attempts will likely cause a denial-of-service condition. The product enables viewing of applications, content and video across screens and browsers. Background ========== The Adobe Flash Player is a renderer for the SWF file format, which is commonly used to provide interactive websites. Please review the CVE identifiers referenced below for details. Impact ====== A remote attacker could possibly execute arbitrary code with the privileges of the process, cause a Denial of Service condition, or bypass security restrictions. Workaround ========== There is no known workaround at this time. Resolution ========== All adobe-flash users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v ">=www-plugins/adobe-flash-11.2.202.451" References ========== [ 1 ] CVE-2015-0332 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0332 [ 2 ] CVE-2015-0333 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0333 [ 3 ] CVE-2015-0334 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0334 [ 4 ] CVE-2015-0335 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0335 [ 5 ] CVE-2015-0336 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0336 [ 6 ] CVE-2015-0337 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0337 [ 7 ] CVE-2015-0338 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0338 [ 8 ] CVE-2015-0339 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0339 [ 9 ] CVE-2015-0340 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0340 [ 10 ] CVE-2015-0341 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0341 [ 11 ] CVE-2015-0342 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0342 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201503-09 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2015 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. http://creativecommons.org/licenses/by-sa/2.5 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ===================================================================== Red Hat Security Advisory Synopsis: Critical: flash-plugin security update Advisory ID: RHSA-2015:0697-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://rhn.redhat.com/errata/RHSA-2015-0697.html Issue date: 2015-03-17 CVE Names: CVE-2015-0332 CVE-2015-0333 CVE-2015-0334 CVE-2015-0335 CVE-2015-0336 CVE-2015-0337 CVE-2015-0338 CVE-2015-0339 CVE-2015-0340 CVE-2015-0341 CVE-2015-0342 ===================================================================== 1. Summary: An updated Adobe Flash Player package that fixes multiple security issues is now available for Red Hat Enterprise Linux 5 and 6 Supplementary. Red Hat Product Security has rated this update as having Critical security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop Supplementary (v. 5) - i386, x86_64 Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 5) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, x86_64 3. Description: The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. These vulnerabilities are detailed in the Adobe Security Bulletin APSB15-05 listed in the References section. Multiple flaws were found in the way flash-plugin displayed certain SWF content. An attacker could use these flaws to create a specially crafted SWF file that would cause flash-plugin to crash or, potentially, execute arbitrary code when the victim loaded a page containing the malicious SWF content. (CVE-2015-0332, CVE-2015-0333, CVE-2015-0335, CVE-2015-0339, CVE-2015-0334, CVE-2015-0336, CVE-2015-0338, CVE-2015-0341, CVE-2015-0342) This update also fixes a cross-domain policy bypass flaw and a file upload restriction bypass flaw. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1201636 - flash-plugin: multiple code execution issues fixed in APSB15-05 1201649 - CVE-2015-0337 flash-plugin: cross-domain policy bypass (APSB15-05) 1201651 - CVE-2015-0340 flash-plugin: file upload restriction bypass (APSB15-05) 6. Package List: Red Hat Enterprise Linux Desktop Supplementary (v. 5): i386: flash-plugin-11.2.202.451-1.el5.i386.rpm x86_64: flash-plugin-11.2.202.451-1.el5.i386.rpm Red Hat Enterprise Linux Server Supplementary (v. 5): i386: flash-plugin-11.2.202.451-1.el5.i386.rpm x86_64: flash-plugin-11.2.202.451-1.el5.i386.rpm Red Hat Enterprise Linux Desktop Supplementary (v. 6): i386: flash-plugin-11.2.202.451-1.el6.i686.rpm x86_64: flash-plugin-11.2.202.451-1.el6.i686.rpm Red Hat Enterprise Linux Server Supplementary (v. 6): i386: flash-plugin-11.2.202.451-1.el6.i686.rpm x86_64: flash-plugin-11.2.202.451-1.el6.i686.rpm Red Hat Enterprise Linux Workstation Supplementary (v. 6): i386: flash-plugin-11.2.202.451-1.el6.i686.rpm x86_64: flash-plugin-11.2.202.451-1.el6.i686.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2015-0332 https://access.redhat.com/security/cve/CVE-2015-0333 https://access.redhat.com/security/cve/CVE-2015-0334 https://access.redhat.com/security/cve/CVE-2015-0335 https://access.redhat.com/security/cve/CVE-2015-0336 https://access.redhat.com/security/cve/CVE-2015-0337 https://access.redhat.com/security/cve/CVE-2015-0338 https://access.redhat.com/security/cve/CVE-2015-0339 https://access.redhat.com/security/cve/CVE-2015-0340 https://access.redhat.com/security/cve/CVE-2015-0341 https://access.redhat.com/security/cve/CVE-2015-0342 https://access.redhat.com/security/updates/classification/#critical https://helpx.adobe.com/security/products/flash-player/apsb15-05.html 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2015 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFVCFmyXlSAg2UNWIIRArVvAKCjJLAKXJvnMOZ5a5IBxmKVEPZu6QCfemGc 9kdM+Q/ZOQRcHTfQ3iZRj3s= =8M6g -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce
VAR-201503-0380 CVE-2015-0335 Adobe Flash Player Vulnerabilities in arbitrary code execution CVSS V2: 10.0
CVSS V3: -
Severity: HIGH
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0332, CVE-2015-0333, and CVE-2015-0339. An attacker can exploit this issue to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will likely result in denial-of-service conditions. The product enables viewing of applications, content and video across screens and browsers. Background ========== The Adobe Flash Player is a renderer for the SWF file format, which is commonly used to provide interactive websites. Please review the CVE identifiers referenced below for details. Workaround ========== There is no known workaround at this time. Resolution ========== All adobe-flash users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v ">=www-plugins/adobe-flash-11.2.202.451" References ========== [ 1 ] CVE-2015-0332 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0332 [ 2 ] CVE-2015-0333 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0333 [ 3 ] CVE-2015-0334 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0334 [ 4 ] CVE-2015-0335 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0335 [ 5 ] CVE-2015-0336 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0336 [ 6 ] CVE-2015-0337 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0337 [ 7 ] CVE-2015-0338 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0338 [ 8 ] CVE-2015-0339 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0339 [ 9 ] CVE-2015-0340 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0340 [ 10 ] CVE-2015-0341 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0341 [ 11 ] CVE-2015-0342 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0342 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201503-09 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2015 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. http://creativecommons.org/licenses/by-sa/2.5 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ===================================================================== Red Hat Security Advisory Synopsis: Critical: flash-plugin security update Advisory ID: RHSA-2015:0697-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://rhn.redhat.com/errata/RHSA-2015-0697.html Issue date: 2015-03-17 CVE Names: CVE-2015-0332 CVE-2015-0333 CVE-2015-0334 CVE-2015-0335 CVE-2015-0336 CVE-2015-0337 CVE-2015-0338 CVE-2015-0339 CVE-2015-0340 CVE-2015-0341 CVE-2015-0342 ===================================================================== 1. Summary: An updated Adobe Flash Player package that fixes multiple security issues is now available for Red Hat Enterprise Linux 5 and 6 Supplementary. Red Hat Product Security has rated this update as having Critical security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop Supplementary (v. 5) - i386, x86_64 Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 5) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, x86_64 3. Description: The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. These vulnerabilities are detailed in the Adobe Security Bulletin APSB15-05 listed in the References section. Multiple flaws were found in the way flash-plugin displayed certain SWF content. An attacker could use these flaws to create a specially crafted SWF file that would cause flash-plugin to crash or, potentially, execute arbitrary code when the victim loaded a page containing the malicious SWF content. (CVE-2015-0332, CVE-2015-0333, CVE-2015-0335, CVE-2015-0339, CVE-2015-0334, CVE-2015-0336, CVE-2015-0338, CVE-2015-0341, CVE-2015-0342) This update also fixes a cross-domain policy bypass flaw and a file upload restriction bypass flaw. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1201636 - flash-plugin: multiple code execution issues fixed in APSB15-05 1201649 - CVE-2015-0337 flash-plugin: cross-domain policy bypass (APSB15-05) 1201651 - CVE-2015-0340 flash-plugin: file upload restriction bypass (APSB15-05) 6. Package List: Red Hat Enterprise Linux Desktop Supplementary (v. 5): i386: flash-plugin-11.2.202.451-1.el5.i386.rpm x86_64: flash-plugin-11.2.202.451-1.el5.i386.rpm Red Hat Enterprise Linux Server Supplementary (v. 5): i386: flash-plugin-11.2.202.451-1.el5.i386.rpm x86_64: flash-plugin-11.2.202.451-1.el5.i386.rpm Red Hat Enterprise Linux Desktop Supplementary (v. 6): i386: flash-plugin-11.2.202.451-1.el6.i686.rpm x86_64: flash-plugin-11.2.202.451-1.el6.i686.rpm Red Hat Enterprise Linux Server Supplementary (v. 6): i386: flash-plugin-11.2.202.451-1.el6.i686.rpm x86_64: flash-plugin-11.2.202.451-1.el6.i686.rpm Red Hat Enterprise Linux Workstation Supplementary (v. 6): i386: flash-plugin-11.2.202.451-1.el6.i686.rpm x86_64: flash-plugin-11.2.202.451-1.el6.i686.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2015-0332 https://access.redhat.com/security/cve/CVE-2015-0333 https://access.redhat.com/security/cve/CVE-2015-0334 https://access.redhat.com/security/cve/CVE-2015-0335 https://access.redhat.com/security/cve/CVE-2015-0336 https://access.redhat.com/security/cve/CVE-2015-0337 https://access.redhat.com/security/cve/CVE-2015-0338 https://access.redhat.com/security/cve/CVE-2015-0339 https://access.redhat.com/security/cve/CVE-2015-0340 https://access.redhat.com/security/cve/CVE-2015-0341 https://access.redhat.com/security/cve/CVE-2015-0342 https://access.redhat.com/security/updates/classification/#critical https://helpx.adobe.com/security/products/flash-player/apsb15-05.html 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2015 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFVCFmyXlSAg2UNWIIRArVvAKCjJLAKXJvnMOZ5a5IBxmKVEPZu6QCfemGc 9kdM+Q/ZOQRcHTfQ3iZRj3s= =8M6g -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce
VAR-201503-0377 CVE-2015-0332 Adobe Flash Player Vulnerable to arbitrary code execution CVSS V2: 10.0
CVSS V3: -
Severity: HIGH
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0333, CVE-2015-0335, and CVE-2015-0339. Failed exploit attempts will likely result in denial-of-service conditions. The product enables viewing of applications, content and video across screens and browsers. Background ========== The Adobe Flash Player is a renderer for the SWF file format, which is commonly used to provide interactive websites. Please review the CVE identifiers referenced below for details. Workaround ========== There is no known workaround at this time. Resolution ========== All adobe-flash users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v ">=www-plugins/adobe-flash-11.2.202.451" References ========== [ 1 ] CVE-2015-0332 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0332 [ 2 ] CVE-2015-0333 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0333 [ 3 ] CVE-2015-0334 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0334 [ 4 ] CVE-2015-0335 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0335 [ 5 ] CVE-2015-0336 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0336 [ 6 ] CVE-2015-0337 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0337 [ 7 ] CVE-2015-0338 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0338 [ 8 ] CVE-2015-0339 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0339 [ 9 ] CVE-2015-0340 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0340 [ 10 ] CVE-2015-0341 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0341 [ 11 ] CVE-2015-0342 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0342 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201503-09 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2015 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. http://creativecommons.org/licenses/by-sa/2.5 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ===================================================================== Red Hat Security Advisory Synopsis: Critical: flash-plugin security update Advisory ID: RHSA-2015:0697-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://rhn.redhat.com/errata/RHSA-2015-0697.html Issue date: 2015-03-17 CVE Names: CVE-2015-0332 CVE-2015-0333 CVE-2015-0334 CVE-2015-0335 CVE-2015-0336 CVE-2015-0337 CVE-2015-0338 CVE-2015-0339 CVE-2015-0340 CVE-2015-0341 CVE-2015-0342 ===================================================================== 1. Summary: An updated Adobe Flash Player package that fixes multiple security issues is now available for Red Hat Enterprise Linux 5 and 6 Supplementary. Red Hat Product Security has rated this update as having Critical security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop Supplementary (v. 5) - i386, x86_64 Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 5) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, x86_64 3. Description: The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. These vulnerabilities are detailed in the Adobe Security Bulletin APSB15-05 listed in the References section. Multiple flaws were found in the way flash-plugin displayed certain SWF content. An attacker could use these flaws to create a specially crafted SWF file that would cause flash-plugin to crash or, potentially, execute arbitrary code when the victim loaded a page containing the malicious SWF content. (CVE-2015-0332, CVE-2015-0333, CVE-2015-0335, CVE-2015-0339, CVE-2015-0334, CVE-2015-0336, CVE-2015-0338, CVE-2015-0341, CVE-2015-0342) This update also fixes a cross-domain policy bypass flaw and a file upload restriction bypass flaw. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1201636 - flash-plugin: multiple code execution issues fixed in APSB15-05 1201649 - CVE-2015-0337 flash-plugin: cross-domain policy bypass (APSB15-05) 1201651 - CVE-2015-0340 flash-plugin: file upload restriction bypass (APSB15-05) 6. Package List: Red Hat Enterprise Linux Desktop Supplementary (v. 5): i386: flash-plugin-11.2.202.451-1.el5.i386.rpm x86_64: flash-plugin-11.2.202.451-1.el5.i386.rpm Red Hat Enterprise Linux Server Supplementary (v. 5): i386: flash-plugin-11.2.202.451-1.el5.i386.rpm x86_64: flash-plugin-11.2.202.451-1.el5.i386.rpm Red Hat Enterprise Linux Desktop Supplementary (v. 6): i386: flash-plugin-11.2.202.451-1.el6.i686.rpm x86_64: flash-plugin-11.2.202.451-1.el6.i686.rpm Red Hat Enterprise Linux Server Supplementary (v. 6): i386: flash-plugin-11.2.202.451-1.el6.i686.rpm x86_64: flash-plugin-11.2.202.451-1.el6.i686.rpm Red Hat Enterprise Linux Workstation Supplementary (v. 6): i386: flash-plugin-11.2.202.451-1.el6.i686.rpm x86_64: flash-plugin-11.2.202.451-1.el6.i686.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2015-0332 https://access.redhat.com/security/cve/CVE-2015-0333 https://access.redhat.com/security/cve/CVE-2015-0334 https://access.redhat.com/security/cve/CVE-2015-0335 https://access.redhat.com/security/cve/CVE-2015-0336 https://access.redhat.com/security/cve/CVE-2015-0337 https://access.redhat.com/security/cve/CVE-2015-0338 https://access.redhat.com/security/cve/CVE-2015-0339 https://access.redhat.com/security/cve/CVE-2015-0340 https://access.redhat.com/security/cve/CVE-2015-0341 https://access.redhat.com/security/cve/CVE-2015-0342 https://access.redhat.com/security/updates/classification/#critical https://helpx.adobe.com/security/products/flash-player/apsb15-05.html 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2015 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFVCFmyXlSAg2UNWIIRArVvAKCjJLAKXJvnMOZ5a5IBxmKVEPZu6QCfemGc 9kdM+Q/ZOQRcHTfQ3iZRj3s= =8M6g -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce
VAR-201503-0157 CVE-2015-0652 plural Cisco Product Session Description Protocol Denial of service in implementation (DoS) Vulnerability CVSS V2: 7.8
CVSS V3: -
Severity: HIGH
The Session Description Protocol (SDP) implementation in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X8.2 and Cisco TelePresence Conductor before XC2.4 allows remote attackers to cause a denial of service (mishandled exception and device reload) via a crafted media description, aka Bug IDs CSCus96593 and CSCun73192. Multiple Cisco products are prone to a remote denial-of-service vulnerability. An attacker can exploit this issue to reload an affected device, denying service to legitimate users. This issue is being tracked by Cisco Bug ID CSCus96593 and CSCun73192
VAR-201503-0158 CVE-2015-0653 plural Cisco Vulnerabilities that bypass authentication in the product management interface CVSS V2: 10.0
CVSS V3: -
Severity: HIGH
The management interface in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X7.2.4, X8 before X8.1.2, and X8.2 before X8.2.2 and Cisco TelePresence Conductor before X2.3.1 and XC2.4 before XC2.4.1 allows remote attackers to bypass authentication via crafted login parameters, aka Bug IDs CSCur02680 and CSCur05556. Vendors have confirmed this vulnerability Bug IDs CSCur02680 and CSCur05556 It is released as.Skillfully crafted by a third party login Authentication may be bypassed via parameters. Multiple Cisco Products are prone to multiple authentication-bypass vulnerabilities. An attacker can exploit these issues to bypass the authentication mechanism and gain unauthorized administrative access. This may aid in further attacks. These issues are being tracked by Cisco Bug ID's CSCur02680 and CSCur05556
VAR-201503-0159 CVE-2015-0654 Cisco Intrusion Prevention System Software management interface MainApp of TLS Service disruption in implementations (DoS) Vulnerabilities CVSS V2: 7.1
CVSS V3: -
Severity: HIGH
Race condition in the TLS implementation in MainApp in the management interface in Cisco Intrusion Prevention System (IPS) Software before 7.3(3)E4 allows remote attackers to cause a denial of service (process hang) by establishing many HTTPS sessions, aka Bug ID CSCuq40652. Cisco Intrusion Prevention System is prone to a remote denial-of-service vulnerability. Attackers can exploit this issue to cause the MainApp process to become unresponsive, denying service to legitimate users. This issue is being tracked by Cisco Bug ID CSCuq40652. The system can immediately interrupt, adjust or isolate some abnormal or harmful network data transmission behaviors
VAR-201708-0323 CVE-2015-4464 Kguard Digital Video Recorder 104 and 108 Authentication vulnerability CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
Kguard Digital Video Recorder 104, 108, v2 does not have any authorization or authentication between an ActiveX client and the application server. Kguard Digital Video Recorder 104 and 108 Contains an authentication vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. The Kguard Digital Video Recorder (DVR) is a digital hard disk recorder from Kguard. There is a command injection vulnerability in Kguard Digital Video Recorder. An attacker could exploit this vulnerability to execute arbitrary commands in the context of an affected application. KguardDVR has security bypass, information disclosure, denial of service, and command injection vulnerabilities. An information-disclosure vulnerability 3. Multiple denial-of-service vulnerability 4
VAR-201503-0334 CVE-2014-9207 Cimon CmnView DLL Hijacking vulnerability

Related entries in the VARIoT exploits database: VAR-E-201503-0456
CVSS V2: 6.9
CVSS V3: -
Severity: MEDIUM
Untrusted search path vulnerability in CmnView.exe in CIMON CmnView 2.14.0.1 and 3.x before UltimateAccess 3.02 allows local users to gain privileges via a Trojan horse DLL in the current working directory. CIMON CmnView and UltimateAccess of CmnView.exe Contains a vulnerability that allows it to get permission due to a flaw in search path processing. Supplementary information : CWE Vulnerability type by CWE-426: Untrusted Search Path ( Unreliable search path ) Has been identified. CmnView is a WEB-based SCADA application. The CmnView application contains a DLL that fails to specify an absolute path, allowing an attacker to exploit a vulnerability to build a malicious application, placed in a specific path, allowing the application to maliciously load the DLL and execute it. Cimon CmnView is prone to a vulnerability that lets attackers execute arbitrary code. Successful exploits will allow the attackers to execute arbitrary code in the context of the user running the affected application
VAR-201503-0371 CVE-2014-5409 GE Digital Energy Hydran M2 for 17046 Ethernet Vulnerability in a packet being spoofed CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
The 17046 Ethernet card before 94450214LFMT100SEM-L.R3-CL for the GE Digital Energy Hydran M2 does not properly generate random values for TCP Initial Sequence Numbers (ISNs), which makes it easier for remote attackers to spoof packets by predicting these values. Supplementary information : CWE Vulnerability type by CWE-330: Use of Insufficiently Random Values ( Insufficient random value used ) Has been identified. The GE Hydran M2 is a fault gas and moisture detection solution. General Electric (GE) Hydran M2 is prone to a predictable random number generator weakness
VAR-201503-0067 CVE-2015-0978 Telerik Analytics Monitor Library allows DLL hijacking CVSS V2: 6.9
CVSS V3: -
Severity: MEDIUM
Multiple untrusted search path vulnerabilities in (1) EQATEC.Analytics.Monitor.Win32_vc100.dll and (2) EQATEC.Analytics.Monitor.Win32_vc100-x64.dll in Elipse E3 4.5.232 through 4.6.161 allow local users to gain privileges via a Trojan horse DLL in an unspecified directory. NOTE: this may overlap CVE-2015-2264. Telerik Analytics Monitor Library is a third-party application analytics service that collects detailed application metrics for vendors. Some versions of the Telerik library allow DLL hijacking, allowing an attacker to load malicious code in the context of the Telerik-based application. Elipse E3 of (1) EQATEC.Analytics.Monitor.Win32_vc100.dll and (2) EQATEC.Analytics.Monitor.Win32_vc100-x64.dll Contains a vulnerability that allows it to get permission due to a flaw in search path processing. This vulnerability CVE-2015-2264 And may be duplicated. Supplementary information : CWE Vulnerability type by CWE-426: Untrusted Search Path ( Unreliable search path ) Has been identified. http://cwe.mitre.org/data/definitions/426.htmlLocal users can detect Trojans in unspecified directories DLL You may get permission through. Telerik Analytics Monitor Library is prone to multiple local arbitrary code-execution vulnerabilities. A local attacker can leverage these issues to execute arbitrary code with SYSTEM privileges. Failed attempts may lead to denial-of-service condition. Elipse Software E3 is a set of HMI/SCADA platform that provides support for distributed applications, mission-critical applications and control centers from Elipse Software in Brazil