Language:
https://bugzilla.opensuse.org/show_bug.cgi?id=856386
https://bugzilla.opensuse.org/show_bug.cgi?id=913057
https://bugzilla.opensuse.org/show_bug.cgi?id=914333
https://bugzilla.opensuse.org/show_bug.cgi?id=914463
https://lists.opensuse.org/opensuse-updates/2015-01/msg00086.html
Severity: Critical
ID: 81098
File Name: openSUSE-2015-81.nasl
Version: 1.16
Type: local
Agent: unix
Family: SuSE Local Security Checks
Published: 1/30/2015
Updated: 5/25/2022
Supported Sensors: Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus
Risk Factor: Critical
Score: 9.6
Risk Factor: Critical
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
CPE: p-cpe:/a:novell:opensuse:flash-player, cpe:/o:novell:opensuse:12.3, p-cpe:/a:novell:opensuse:flash-player-kde4, p-cpe:/a:novell:opensuse:flash-player-gnome
Required KB Items: Host/local_checks_enabled, Host/SuSE/release, Host/SuSE/rpm-list, Host/cpu
Exploit Available: true
Exploit Ease: Exploits are available
Patch Publication Date: 1/29/2015
CISA Known Exploited Vulnerability Due Dates: 5/4/2022, 6/15/2022
Core Impact
Metasploit (Adobe Flash Player ByteArray UncompressViaZlibVariant Use After Free)
CVE: CVE-2015-0301, CVE-2015-0302, CVE-2015-0303, CVE-2015-0304, CVE-2015-0305, CVE-2015-0306, CVE-2015-0307, CVE-2015-0308, CVE-2015-0309, CVE-2015-0310, CVE-2015-0311