ALT-BU-2016-3129-1
Branch p8 update bulletin.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2016-8568
The git_commit_message function in oid.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a cat-file command with a crafted object file.
- openSUSE-SU-2016:3097
- openSUSE-SU-2016:3097
- openSUSE-SU-2017:0184
- openSUSE-SU-2017:0184
- openSUSE-SU-2017:0195
- openSUSE-SU-2017:0195
- openSUSE-SU-2017:0208
- openSUSE-SU-2017:0208
- [oss-security] 20161008 Re: CVE request: invalid memory accesses parsing object files in libgit2
- [oss-security] 20161008 Re: CVE request: invalid memory accesses parsing object files in libgit2
- 93466
- 93466
- https://bugzilla.redhat.com/show_bug.cgi?id=1383211
- https://bugzilla.redhat.com/show_bug.cgi?id=1383211
- https://github.com/libgit2/libgit2/issues/3936
- https://github.com/libgit2/libgit2/issues/3936
- https://github.com/libgit2/libgit2/releases/tag/v0.24.3
- https://github.com/libgit2/libgit2/releases/tag/v0.24.3
- FEDORA-2016-bc51f4636f
- FEDORA-2016-bc51f4636f
- FEDORA-2016-616a35205b
- FEDORA-2016-616a35205b
- FEDORA-2016-505d7fe198
- FEDORA-2016-505d7fe198
Modified: 2024-11-21
CVE-2016-8569
The git_oid_nfmt function in commit.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a cat-file command with a crafted object file.
- openSUSE-SU-2016:3097
- openSUSE-SU-2016:3097
- openSUSE-SU-2017:0184
- openSUSE-SU-2017:0184
- openSUSE-SU-2017:0195
- openSUSE-SU-2017:0195
- openSUSE-SU-2017:0208
- openSUSE-SU-2017:0208
- [oss-security] 20161008 Re: CVE request: invalid memory accesses parsing object files in libgit2
- [oss-security] 20161008 Re: CVE request: invalid memory accesses parsing object files in libgit2
- 93465
- 93465
- https://bugzilla.redhat.com/show_bug.cgi?id=1383211
- https://bugzilla.redhat.com/show_bug.cgi?id=1383211
- https://github.com/libgit2/libgit2/issues/3937
- https://github.com/libgit2/libgit2/issues/3937
- https://github.com/libgit2/libgit2/releases/tag/v0.24.3
- https://github.com/libgit2/libgit2/releases/tag/v0.24.3
- FEDORA-2016-bc51f4636f
- FEDORA-2016-bc51f4636f
- FEDORA-2016-616a35205b
- FEDORA-2016-616a35205b
- FEDORA-2016-505d7fe198
- FEDORA-2016-505d7fe198
Package adobe-flash-player updated to version 11-alt68 for branch p8 in task 172078.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2016-7857
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution.
- RHSA-2016:2676
- RHSA-2016:2676
- 94153
- 94153
- 1037240
- 1037240
- http://www.zerodayinitiative.com/advisories/ZDI-16-596
- http://www.zerodayinitiative.com/advisories/ZDI-16-596
- MS16-141
- MS16-141
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- GLSA-201611-18
- GLSA-201611-18
Modified: 2024-11-21
CVE-2016-7858
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution.
- RHSA-2016:2676
- RHSA-2016:2676
- 94153
- 94153
- 1037240
- 1037240
- http://www.zerodayinitiative.com/advisories/ZDI-16-595
- http://www.zerodayinitiative.com/advisories/ZDI-16-595
- MS16-141
- MS16-141
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- GLSA-201611-18
- GLSA-201611-18
Modified: 2024-11-21
CVE-2016-7859
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution.
- RHSA-2016:2676
- RHSA-2016:2676
- 94153
- 94153
- 1037240
- 1037240
- http://www.zerodayinitiative.com/advisories/ZDI-16-602
- http://www.zerodayinitiative.com/advisories/ZDI-16-602
- MS16-141
- MS16-141
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- GLSA-201611-18
- GLSA-201611-18
Modified: 2024-11-21
CVE-2016-7860
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
- RHSA-2016:2676
- RHSA-2016:2676
- 94151
- 94151
- 1037240
- 1037240
- http://www.zerodayinitiative.com/advisories/ZDI-16-601
- http://www.zerodayinitiative.com/advisories/ZDI-16-601
- MS16-141
- MS16-141
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- GLSA-201611-18
- GLSA-201611-18
Modified: 2024-11-21
CVE-2016-7861
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
- RHSA-2016:2676
- RHSA-2016:2676
- 94151
- 94151
- 1037240
- 1037240
- http://www.zerodayinitiative.com/advisories/ZDI-16-600
- http://www.zerodayinitiative.com/advisories/ZDI-16-600
- MS16-141
- MS16-141
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- GLSA-201611-18
- GLSA-201611-18
Modified: 2024-11-21
CVE-2016-7862
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution.
- RHSA-2016:2676
- RHSA-2016:2676
- 94153
- 94153
- 1037240
- 1037240
- http://www.zerodayinitiative.com/advisories/ZDI-16-603
- http://www.zerodayinitiative.com/advisories/ZDI-16-603
- MS16-141
- MS16-141
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- GLSA-201611-18
- GLSA-201611-18
Modified: 2024-11-21
CVE-2016-7863
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution.
- RHSA-2016:2676
- RHSA-2016:2676
- 94153
- 94153
- 1037240
- 1037240
- http://www.zerodayinitiative.com/advisories/ZDI-16-599
- http://www.zerodayinitiative.com/advisories/ZDI-16-599
- MS16-141
- MS16-141
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- GLSA-201611-18
- GLSA-201611-18
Modified: 2024-11-21
CVE-2016-7864
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution.
- RHSA-2016:2676
- RHSA-2016:2676
- 94153
- 94153
- 1037240
- 1037240
- http://www.zerodayinitiative.com/advisories/ZDI-16-597
- http://www.zerodayinitiative.com/advisories/ZDI-16-597
- MS16-141
- MS16-141
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- GLSA-201611-18
- GLSA-201611-18
Modified: 2024-11-21
CVE-2016-7865
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
- RHSA-2016:2676
- RHSA-2016:2676
- 94151
- 94151
- 1037240
- 1037240
- http://www.zerodayinitiative.com/advisories/ZDI-16-598
- http://www.zerodayinitiative.com/advisories/ZDI-16-598
- MS16-141
- MS16-141
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- GLSA-201611-18
- GLSA-201611-18
Package adobe-flash-player-ppapi updated to version 23-alt7 for branch p8 in task 172082.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2016-7857
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution.
- RHSA-2016:2676
- RHSA-2016:2676
- 94153
- 94153
- 1037240
- 1037240
- http://www.zerodayinitiative.com/advisories/ZDI-16-596
- http://www.zerodayinitiative.com/advisories/ZDI-16-596
- MS16-141
- MS16-141
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- GLSA-201611-18
- GLSA-201611-18
Modified: 2024-11-21
CVE-2016-7858
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution.
- RHSA-2016:2676
- RHSA-2016:2676
- 94153
- 94153
- 1037240
- 1037240
- http://www.zerodayinitiative.com/advisories/ZDI-16-595
- http://www.zerodayinitiative.com/advisories/ZDI-16-595
- MS16-141
- MS16-141
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- GLSA-201611-18
- GLSA-201611-18
Modified: 2024-11-21
CVE-2016-7859
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution.
- RHSA-2016:2676
- RHSA-2016:2676
- 94153
- 94153
- 1037240
- 1037240
- http://www.zerodayinitiative.com/advisories/ZDI-16-602
- http://www.zerodayinitiative.com/advisories/ZDI-16-602
- MS16-141
- MS16-141
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- GLSA-201611-18
- GLSA-201611-18
Modified: 2024-11-21
CVE-2016-7860
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
- RHSA-2016:2676
- RHSA-2016:2676
- 94151
- 94151
- 1037240
- 1037240
- http://www.zerodayinitiative.com/advisories/ZDI-16-601
- http://www.zerodayinitiative.com/advisories/ZDI-16-601
- MS16-141
- MS16-141
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- GLSA-201611-18
- GLSA-201611-18
Modified: 2024-11-21
CVE-2016-7861
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
- RHSA-2016:2676
- RHSA-2016:2676
- 94151
- 94151
- 1037240
- 1037240
- http://www.zerodayinitiative.com/advisories/ZDI-16-600
- http://www.zerodayinitiative.com/advisories/ZDI-16-600
- MS16-141
- MS16-141
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- GLSA-201611-18
- GLSA-201611-18
Modified: 2024-11-21
CVE-2016-7862
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution.
- RHSA-2016:2676
- RHSA-2016:2676
- 94153
- 94153
- 1037240
- 1037240
- http://www.zerodayinitiative.com/advisories/ZDI-16-603
- http://www.zerodayinitiative.com/advisories/ZDI-16-603
- MS16-141
- MS16-141
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- GLSA-201611-18
- GLSA-201611-18
Modified: 2024-11-21
CVE-2016-7863
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution.
- RHSA-2016:2676
- RHSA-2016:2676
- 94153
- 94153
- 1037240
- 1037240
- http://www.zerodayinitiative.com/advisories/ZDI-16-599
- http://www.zerodayinitiative.com/advisories/ZDI-16-599
- MS16-141
- MS16-141
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- GLSA-201611-18
- GLSA-201611-18
Modified: 2024-11-21
CVE-2016-7864
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution.
- RHSA-2016:2676
- RHSA-2016:2676
- 94153
- 94153
- 1037240
- 1037240
- http://www.zerodayinitiative.com/advisories/ZDI-16-597
- http://www.zerodayinitiative.com/advisories/ZDI-16-597
- MS16-141
- MS16-141
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- GLSA-201611-18
- GLSA-201611-18
Modified: 2024-11-21
CVE-2016-7865
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
- RHSA-2016:2676
- RHSA-2016:2676
- 94151
- 94151
- 1037240
- 1037240
- http://www.zerodayinitiative.com/advisories/ZDI-16-598
- http://www.zerodayinitiative.com/advisories/ZDI-16-598
- MS16-141
- MS16-141
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- GLSA-201611-18
- GLSA-201611-18
Package 389-ds-base updated to version 1.3.6.1-alt0.M80P.1 for branch p8 in task 171902.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-2591
389-ds-base before version 1.3.6 is vulnerable to an improperly NULL terminated array in the uniqueness_entry_to_config() function in the "attribute uniqueness" plugin of 389 Directory Server. An authenticated, or possibly unauthenticated, attacker could use this flaw to force an out-of-bound heap memory read, possibly triggering a crash of the LDAP service.