Upstream information
Description
The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, does not properly restrict privileges, which makes it easier for remote attackers to execute arbitrary code via crafted SWF content, as exploited in the wild in February 2013.NVD CVSS v2 Base Score: 9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)
Novell/SUSE information
Novell Bugzilla entry: 806415 SUSE Security Advisories:- SUSE-SU-2013:0373-1, published Thu, 28 Feb 2013 22:04:26 +0100 (CET)
- openSUSE-SU-2013:0359-1, published Thu, 28 Feb 2013 14:05:45 +0100 (CET)
- openSUSE-SU-2013:0359-2, published Thu, 28 Feb 2013 18:26:44 +0100 (CET)
- openSUSE-SU-2013:0360-1, published Thu, 28 Feb 2013 17:05:42 +0100 (CET)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE Linux Enterprise Desktop 10 SP4 for AMD64 and Intel EM64T SUSE Linux Enterprise Desktop 10 SP4 for x86 |
| Builds ZYPP Patch Nr: 8476 |
| SUSE Linux Enterprise Desktop 11 SP2 |
| Builds SAT Patch Nr: 7431 |
