ALT-BU-2016-3130-1
Branch sisyphus update bulletin.
Package adobe-flash-player updated to version 11-alt68 for branch sisyphus in task 172077.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2016-7857
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution.
- RHSA-2016:2676
- RHSA-2016:2676
- 94153
- 94153
- 1037240
- 1037240
- http://www.zerodayinitiative.com/advisories/ZDI-16-596
- http://www.zerodayinitiative.com/advisories/ZDI-16-596
- MS16-141
- MS16-141
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- GLSA-201611-18
- GLSA-201611-18
Modified: 2024-11-21
CVE-2016-7858
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution.
- RHSA-2016:2676
- RHSA-2016:2676
- 94153
- 94153
- 1037240
- 1037240
- http://www.zerodayinitiative.com/advisories/ZDI-16-595
- http://www.zerodayinitiative.com/advisories/ZDI-16-595
- MS16-141
- MS16-141
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- GLSA-201611-18
- GLSA-201611-18
Modified: 2024-11-21
CVE-2016-7859
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution.
- RHSA-2016:2676
- RHSA-2016:2676
- 94153
- 94153
- 1037240
- 1037240
- http://www.zerodayinitiative.com/advisories/ZDI-16-602
- http://www.zerodayinitiative.com/advisories/ZDI-16-602
- MS16-141
- MS16-141
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- GLSA-201611-18
- GLSA-201611-18
Modified: 2024-11-21
CVE-2016-7860
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
- RHSA-2016:2676
- RHSA-2016:2676
- 94151
- 94151
- 1037240
- 1037240
- http://www.zerodayinitiative.com/advisories/ZDI-16-601
- http://www.zerodayinitiative.com/advisories/ZDI-16-601
- MS16-141
- MS16-141
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- GLSA-201611-18
- GLSA-201611-18
Modified: 2024-11-21
CVE-2016-7861
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
- RHSA-2016:2676
- RHSA-2016:2676
- 94151
- 94151
- 1037240
- 1037240
- http://www.zerodayinitiative.com/advisories/ZDI-16-600
- http://www.zerodayinitiative.com/advisories/ZDI-16-600
- MS16-141
- MS16-141
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- GLSA-201611-18
- GLSA-201611-18
Modified: 2024-11-21
CVE-2016-7862
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution.
- RHSA-2016:2676
- RHSA-2016:2676
- 94153
- 94153
- 1037240
- 1037240
- http://www.zerodayinitiative.com/advisories/ZDI-16-603
- http://www.zerodayinitiative.com/advisories/ZDI-16-603
- MS16-141
- MS16-141
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- GLSA-201611-18
- GLSA-201611-18
Modified: 2024-11-21
CVE-2016-7863
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution.
- RHSA-2016:2676
- RHSA-2016:2676
- 94153
- 94153
- 1037240
- 1037240
- http://www.zerodayinitiative.com/advisories/ZDI-16-599
- http://www.zerodayinitiative.com/advisories/ZDI-16-599
- MS16-141
- MS16-141
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- GLSA-201611-18
- GLSA-201611-18
Modified: 2024-11-21
CVE-2016-7864
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution.
- RHSA-2016:2676
- RHSA-2016:2676
- 94153
- 94153
- 1037240
- 1037240
- http://www.zerodayinitiative.com/advisories/ZDI-16-597
- http://www.zerodayinitiative.com/advisories/ZDI-16-597
- MS16-141
- MS16-141
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- GLSA-201611-18
- GLSA-201611-18
Modified: 2024-11-21
CVE-2016-7865
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
- RHSA-2016:2676
- RHSA-2016:2676
- 94151
- 94151
- 1037240
- 1037240
- http://www.zerodayinitiative.com/advisories/ZDI-16-598
- http://www.zerodayinitiative.com/advisories/ZDI-16-598
- MS16-141
- MS16-141
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- GLSA-201611-18
- GLSA-201611-18
Package adobe-flash-player-ppapi updated to version 23-alt7 for branch sisyphus in task 172081.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2016-7857
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution.
- RHSA-2016:2676
- RHSA-2016:2676
- 94153
- 94153
- 1037240
- 1037240
- http://www.zerodayinitiative.com/advisories/ZDI-16-596
- http://www.zerodayinitiative.com/advisories/ZDI-16-596
- MS16-141
- MS16-141
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- GLSA-201611-18
- GLSA-201611-18
Modified: 2024-11-21
CVE-2016-7858
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution.
- RHSA-2016:2676
- RHSA-2016:2676
- 94153
- 94153
- 1037240
- 1037240
- http://www.zerodayinitiative.com/advisories/ZDI-16-595
- http://www.zerodayinitiative.com/advisories/ZDI-16-595
- MS16-141
- MS16-141
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- GLSA-201611-18
- GLSA-201611-18
Modified: 2024-11-21
CVE-2016-7859
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution.
- RHSA-2016:2676
- RHSA-2016:2676
- 94153
- 94153
- 1037240
- 1037240
- http://www.zerodayinitiative.com/advisories/ZDI-16-602
- http://www.zerodayinitiative.com/advisories/ZDI-16-602
- MS16-141
- MS16-141
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- GLSA-201611-18
- GLSA-201611-18
Modified: 2024-11-21
CVE-2016-7860
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
- RHSA-2016:2676
- RHSA-2016:2676
- 94151
- 94151
- 1037240
- 1037240
- http://www.zerodayinitiative.com/advisories/ZDI-16-601
- http://www.zerodayinitiative.com/advisories/ZDI-16-601
- MS16-141
- MS16-141
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- GLSA-201611-18
- GLSA-201611-18
Modified: 2024-11-21
CVE-2016-7861
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
- RHSA-2016:2676
- RHSA-2016:2676
- 94151
- 94151
- 1037240
- 1037240
- http://www.zerodayinitiative.com/advisories/ZDI-16-600
- http://www.zerodayinitiative.com/advisories/ZDI-16-600
- MS16-141
- MS16-141
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- GLSA-201611-18
- GLSA-201611-18
Modified: 2024-11-21
CVE-2016-7862
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution.
- RHSA-2016:2676
- RHSA-2016:2676
- 94153
- 94153
- 1037240
- 1037240
- http://www.zerodayinitiative.com/advisories/ZDI-16-603
- http://www.zerodayinitiative.com/advisories/ZDI-16-603
- MS16-141
- MS16-141
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- GLSA-201611-18
- GLSA-201611-18
Modified: 2024-11-21
CVE-2016-7863
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution.
- RHSA-2016:2676
- RHSA-2016:2676
- 94153
- 94153
- 1037240
- 1037240
- http://www.zerodayinitiative.com/advisories/ZDI-16-599
- http://www.zerodayinitiative.com/advisories/ZDI-16-599
- MS16-141
- MS16-141
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- GLSA-201611-18
- GLSA-201611-18
Modified: 2024-11-21
CVE-2016-7864
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution.
- RHSA-2016:2676
- RHSA-2016:2676
- 94153
- 94153
- 1037240
- 1037240
- http://www.zerodayinitiative.com/advisories/ZDI-16-597
- http://www.zerodayinitiative.com/advisories/ZDI-16-597
- MS16-141
- MS16-141
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- GLSA-201611-18
- GLSA-201611-18
Modified: 2024-11-21
CVE-2016-7865
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
- RHSA-2016:2676
- RHSA-2016:2676
- 94151
- 94151
- 1037240
- 1037240
- http://www.zerodayinitiative.com/advisories/ZDI-16-598
- http://www.zerodayinitiative.com/advisories/ZDI-16-598
- MS16-141
- MS16-141
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- https://helpx.adobe.com/security/products/flash-player/apsb16-37.html
- GLSA-201611-18
- GLSA-201611-18
Package 389-ds-base updated to version 1.3.6.1-alt1 for branch sisyphus in task 171806.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-2591
389-ds-base before version 1.3.6 is vulnerable to an improperly NULL terminated array in the uniqueness_entry_to_config() function in the "attribute uniqueness" plugin of 389 Directory Server. An authenticated, or possibly unauthenticated, attacker could use this flaw to force an out-of-bound heap memory read, possibly triggering a crash of the LDAP service.
Closed vulnerabilities
BDU:2017-01148
Уязвимость системы управления базами данных MySQL, позволяющая злоумышленнику нарушить конфиденциальность информации
Modified: 2024-11-21
CVE-2016-5584
Unspecified vulnerability in Oracle MySQL 5.5.52 and earlier, 5.6.33 and earlier, and 5.7.15 and earlier allows remote administrators to affect confidentiality via vectors related to Server: Security: Encryption.
- DSA-3706
- DSA-3706
- http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
- 93735
- 93735
- 1037050
- 1037050
- https://mariadb.com/kb/en/mariadb/mariadb-10028-release-notes/
- https://mariadb.com/kb/en/mariadb/mariadb-10028-release-notes/
- GLSA-201701-01
- GLSA-201701-01
Modified: 2024-11-21
CVE-2016-7440
The C software implementation of AES Encryption and Decryption in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover AES keys by leveraging cache-bank timing differences.
- DSA-3706
- DSA-3706
- http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
- 93659
- 93659
- 1037050
- 1037050
- https://mariadb.com/kb/en/mariadb/mariadb-10028-release-notes/
- https://mariadb.com/kb/en/mariadb/mariadb-10028-release-notes/
- https://wolfssl.com/wolfSSL/Blog/Entries/2016/9/26_wolfSSL_3.9.10_Vulnerability_Fixes.html
- https://wolfssl.com/wolfSSL/Blog/Entries/2016/9/26_wolfSSL_3.9.10_Vulnerability_Fixes.html
Modified: 2024-11-21
CVE-2017-3600
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client mysqldump). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in takeover of MySQL Server. Note: CVE-2017-3600 is equivalent to CVE-2016-5483. CVSS 3.0 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).
- RHSA-2016:2927
- RHSA-2016:2927
- RHSA-2016:2928
- RHSA-2016:2928
- DSA-3834
- DSA-3834
- http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html
- http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html
- 97765
- 97765
- 1038287
- 1038287
- RHSA-2017:2192
- RHSA-2017:2192
- RHSA-2017:2787
- RHSA-2017:2787
- RHSA-2017:2886
- RHSA-2017:2886
Modified: 2024-11-21
CVE-2017-3651
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client mysqldump). Supported versions that are affected are 5.5.56 and earlier, 5.6.36 and earlier and 5.7.18 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.0 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).
- RHSA-2016:2927
- RHSA-2016:2927
- RHSA-2016:2928
- RHSA-2016:2928
- DSA-3922
- DSA-3922
- http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
- 99802
- 99802
- 1038928
- 1038928
- RHSA-2017:2192
- RHSA-2017:2192
- RHSA-2017:2787
- RHSA-2017:2787
- RHSA-2017:2886
- RHSA-2017:2886
- RHSA-2018:2439
- RHSA-2018:2439
- RHSA-2018:2729
- RHSA-2018:2729
Closed bugs
Неправильное имя пакета библиотеки
Closed bugs
/etc/opensc.conf должен принадлежать пакету libopensc