2024-06-28 13:17:52 +00:00

675 lines
38 KiB
JSON

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20151803",
"Version": "oval:org.altlinux.errata:def:20151803",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2015-1803: package `adobe-flash-player` update to version 11-alt53",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c10f1"
],
"Products": [
"ALT SP Workstation",
"ALT SP Server"
]
}
],
"References": [
{
"RefID": "ALT-PU-2015-1803",
"RefURL": "https://errata.altlinux.org/ALT-PU-2015-1803",
"Source": "ALTPU"
},
{
"RefID": "BDU:2015-11487",
"RefURL": "https://bdu.fstec.ru/vul/2015-11487",
"Source": "BDU"
},
{
"RefID": "BDU:2015-11488",
"RefURL": "https://bdu.fstec.ru/vul/2015-11488",
"Source": "BDU"
},
{
"RefID": "BDU:2015-11489",
"RefURL": "https://bdu.fstec.ru/vul/2015-11489",
"Source": "BDU"
},
{
"RefID": "BDU:2015-11490",
"RefURL": "https://bdu.fstec.ru/vul/2015-11490",
"Source": "BDU"
},
{
"RefID": "BDU:2015-11491",
"RefURL": "https://bdu.fstec.ru/vul/2015-11491",
"Source": "BDU"
},
{
"RefID": "BDU:2015-11492",
"RefURL": "https://bdu.fstec.ru/vul/2015-11492",
"Source": "BDU"
},
{
"RefID": "BDU:2015-11493",
"RefURL": "https://bdu.fstec.ru/vul/2015-11493",
"Source": "BDU"
},
{
"RefID": "BDU:2015-11494",
"RefURL": "https://bdu.fstec.ru/vul/2015-11494",
"Source": "BDU"
},
{
"RefID": "BDU:2015-11495",
"RefURL": "https://bdu.fstec.ru/vul/2015-11495",
"Source": "BDU"
},
{
"RefID": "BDU:2015-11496",
"RefURL": "https://bdu.fstec.ru/vul/2015-11496",
"Source": "BDU"
},
{
"RefID": "BDU:2015-11497",
"RefURL": "https://bdu.fstec.ru/vul/2015-11497",
"Source": "BDU"
},
{
"RefID": "BDU:2015-11498",
"RefURL": "https://bdu.fstec.ru/vul/2015-11498",
"Source": "BDU"
},
{
"RefID": "BDU:2015-11499",
"RefURL": "https://bdu.fstec.ru/vul/2015-11499",
"Source": "BDU"
},
{
"RefID": "BDU:2015-11500",
"RefURL": "https://bdu.fstec.ru/vul/2015-11500",
"Source": "BDU"
},
{
"RefID": "BDU:2015-11501",
"RefURL": "https://bdu.fstec.ru/vul/2015-11501",
"Source": "BDU"
},
{
"RefID": "BDU:2015-11502",
"RefURL": "https://bdu.fstec.ru/vul/2015-11502",
"Source": "BDU"
},
{
"RefID": "BDU:2015-11503",
"RefURL": "https://bdu.fstec.ru/vul/2015-11503",
"Source": "BDU"
},
{
"RefID": "BDU:2015-11504",
"RefURL": "https://bdu.fstec.ru/vul/2015-11504",
"Source": "BDU"
},
{
"RefID": "BDU:2015-11505",
"RefURL": "https://bdu.fstec.ru/vul/2015-11505",
"Source": "BDU"
},
{
"RefID": "BDU:2015-11527",
"RefURL": "https://bdu.fstec.ru/vul/2015-11527",
"Source": "BDU"
},
{
"RefID": "BDU:2015-11528",
"RefURL": "https://bdu.fstec.ru/vul/2015-11528",
"Source": "BDU"
},
{
"RefID": "BDU:2015-11529",
"RefURL": "https://bdu.fstec.ru/vul/2015-11529",
"Source": "BDU"
},
{
"RefID": "BDU:2015-11531",
"RefURL": "https://bdu.fstec.ru/vul/2015-11531",
"Source": "BDU"
},
{
"RefID": "CVE-2015-5567",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2015-5567",
"Source": "CVE"
},
{
"RefID": "CVE-2015-5568",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2015-5568",
"Source": "CVE"
},
{
"RefID": "CVE-2015-5570",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2015-5570",
"Source": "CVE"
},
{
"RefID": "CVE-2015-5571",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2015-5571",
"Source": "CVE"
},
{
"RefID": "CVE-2015-5572",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2015-5572",
"Source": "CVE"
},
{
"RefID": "CVE-2015-5573",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2015-5573",
"Source": "CVE"
},
{
"RefID": "CVE-2015-5574",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2015-5574",
"Source": "CVE"
},
{
"RefID": "CVE-2015-5575",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2015-5575",
"Source": "CVE"
},
{
"RefID": "CVE-2015-5576",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2015-5576",
"Source": "CVE"
},
{
"RefID": "CVE-2015-5577",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2015-5577",
"Source": "CVE"
},
{
"RefID": "CVE-2015-5578",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2015-5578",
"Source": "CVE"
},
{
"RefID": "CVE-2015-5579",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2015-5579",
"Source": "CVE"
},
{
"RefID": "CVE-2015-5580",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2015-5580",
"Source": "CVE"
},
{
"RefID": "CVE-2015-5581",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2015-5581",
"Source": "CVE"
},
{
"RefID": "CVE-2015-5582",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2015-5582",
"Source": "CVE"
},
{
"RefID": "CVE-2015-5584",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2015-5584",
"Source": "CVE"
},
{
"RefID": "CVE-2015-5587",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2015-5587",
"Source": "CVE"
},
{
"RefID": "CVE-2015-5588",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2015-5588",
"Source": "CVE"
},
{
"RefID": "CVE-2015-6676",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2015-6676",
"Source": "CVE"
},
{
"RefID": "CVE-2015-6677",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2015-6677",
"Source": "CVE"
},
{
"RefID": "CVE-2015-6678",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2015-6678",
"Source": "CVE"
},
{
"RefID": "CVE-2015-6679",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2015-6679",
"Source": "CVE"
},
{
"RefID": "CVE-2015-6682",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2015-6682",
"Source": "CVE"
}
],
"Description": "This update upgrades adobe-flash-player to version 11-alt53. \nSecurity Fix(es):\n\n * BDU:2015-11487: Уязвимость программной платформы Flash Player и Adobe Integrated Runtime, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании\n\n * BDU:2015-11488: Уязвимость программных платформ Flash Player и Adobe Integrated Runtime, позволяющая нарушителю вызвать отказ в обслуживании\n\n * BDU:2015-11489: Уязвимость программных платформ Flash Player и Adobe Integrated Runtime, позволяющая нарушителю выполнить произвольный код\n\n * BDU:2015-11490: Уязвимость программных платформ Flash Player и Adobe Integrated Runtime, позволяющая нарушителю выполнить произвольный код\n\n * BDU:2015-11491: Уязвимость программных платформ Flash Player и Adobe Integrated Runtime, позволяющая нарушителю выполнить произвольный код\n\n * BDU:2015-11492: Уязвимость программных платформ Flash Player и Adobe Integrated Runtime, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании\n\n * BDU:2015-11493: Уязвимость программных платформ Flash Player и Adobe Integrated Runtime, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании\n\n * BDU:2015-11494: Уязвимость программных платформ Flash Player и Adobe Integrated Runtime, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании\n\n * BDU:2015-11495: Уязвимость программных платформ Flash Player и Adobe Integrated Runtime, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании\n\n * BDU:2015-11496: Уязвимость программных платформ Flash Player и Adobe Integrated Runtime, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании\n\n * BDU:2015-11497: Уязвимость программных платформ Flash Player и Adobe Integrated Runtime, позволяющая нарушителю выполнить произвольный код\n\n * BDU:2015-11498: Уязвимость программных платформ Flash Player и Adobe Integrated Runtime, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании\n\n * BDU:2015-11499: Уязвимость программных платформ Flash Player и Adobe Integrated Runtime, позволяющая нарушителю выполнить произвольный код\n\n * BDU:2015-11500: Уязвимость программных платформ Flash Player и Adobe Integrated Runtime, позволяющая нарушителю выполнить произвольный код\n\n * BDU:2015-11501: Уязвимость программных платформ Flash Player и Adobe Integrated Runtime, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании\n\n * BDU:2015-11502: Уязвимость программных платформ Flash Player и Adobe Integrated Runtime, позволяющая нарушителю выполнить произвольный код\n\n * BDU:2015-11503: Уязвимость программных платформ Flash Player и Adobe Integrated Runtime, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании\n\n * BDU:2015-11504: Уязвимость программных платформ Flash Player и Adobe Integrated Runtime, позволяющая нарушителю выполнить произвольный код\n\n * BDU:2015-11505: Уязвимость программных платформ Flash Player и Adobe Integrated Runtime, позволяющая нарушителю выполнить произвольный код\n\n * BDU:2015-11527: Уязвимость программных платформ Flash Player и Adobe Integrated Runtime, позволяющая нарушителю получить доступ к защищаемой информации\n\n * BDU:2015-11528: Уязвимость программных платформ Flash Player и Adobe Integrated Runtime, позволяющая нарушителю обойти существующие правила разграничения доступа и получить доступ к защищаемой информации\n\n * BDU:2015-11529: Уязвимость программных платформ Flash Player и Adobe Integrated Runtime, позволяющая нарушителю обойти механизм защиты ASLR\n\n * BDU:2015-11531: Уязвимость программных платформ Flash Player и Adobe Integrated Runtime, позволяющая нарушителю обойти существующие правила разграничения доступа и получить доступ к защищаемой информации\n\n * CVE-2015-5567: Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK \u0026 Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5579.\n\n * CVE-2015-5568: Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK \u0026 Compiler before 19.0.0.190 allow attackers to cause a denial of service (vector-length corruption) or possibly have unspecified other impact via unknown vectors.\n\n * CVE-2015-5570: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK \u0026 Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5574, CVE-2015-5581, CVE-2015-5584, and CVE-2015-6682.\n\n * CVE-2015-5571: Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK \u0026 Compiler before 19.0.0.190 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API. NOTE: this issue exists because of an incomplete fix for CVE-2014-4671 and CVE-2014-5333.\n\n * CVE-2015-5572: Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK \u0026 Compiler before 19.0.0.190 allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors.\n\n * CVE-2015-5573: Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK \u0026 Compiler before 19.0.0.190 allow attackers to execute arbitrary code by leveraging an unspecified \"type confusion.\"\n\n * CVE-2015-5574: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK \u0026 Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5570, CVE-2015-5581, CVE-2015-5584, and CVE-2015-6682.\n\n * CVE-2015-5575: Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK \u0026 Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5577, CVE-2015-5578, CVE-2015-5580, CVE-2015-5582, CVE-2015-5588, and CVE-2015-6677.\n\n * CVE-2015-5576: Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK \u0026 Compiler before 19.0.0.190 do not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors.\n\n * CVE-2015-5577: Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK \u0026 Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5575, CVE-2015-5578, CVE-2015-5580, CVE-2015-5582, CVE-2015-5588, and CVE-2015-6677.\n\n * CVE-2015-5578: Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK \u0026 Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5575, CVE-2015-5577, CVE-2015-5580, CVE-2015-5582, CVE-2015-5588, and CVE-2015-6677.\n\n * CVE-2015-5579: Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK \u0026 Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5567.\n\n * CVE-2015-5580: Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK \u0026 Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5575, CVE-2015-5577, CVE-2015-5578, CVE-2015-5582, CVE-2015-5588, and CVE-2015-6677.\n\n * CVE-2015-5581: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK \u0026 Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5570, CVE-2015-5574, CVE-2015-5584, and CVE-2015-6682.\n\n * CVE-2015-5582: Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK \u0026 Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5575, CVE-2015-5577, CVE-2015-5578, CVE-2015-5580, CVE-2015-5588, and CVE-2015-6677.\n\n * CVE-2015-5584: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK \u0026 Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5570, CVE-2015-5574, CVE-2015-5581, and CVE-2015-6682.\n\n * CVE-2015-5587: Stack-based buffer overflow in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK \u0026 Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors.\n\n * CVE-2015-5588: Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK \u0026 Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5575, CVE-2015-5577, CVE-2015-5578, CVE-2015-5580, CVE-2015-5582, and CVE-2015-6677.\n\n * CVE-2015-6676: Buffer overflow in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK \u0026 Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-6678.\n\n * CVE-2015-6677: Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK \u0026 Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5575, CVE-2015-5577, CVE-2015-5578, CVE-2015-5580, CVE-2015-5582, and CVE-2015-5588.\n\n * CVE-2015-6678: Buffer overflow in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK \u0026 Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-6676.\n\n * CVE-2015-6679: Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK \u0026 Compiler before 19.0.0.190 allow attackers to bypass the Same Origin Policy and obtain sensitive information via unspecified vectors.\n\n * CVE-2015-6682: Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK \u0026 Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5570, CVE-2015-5574, CVE-2015-5581, and CVE-2015-5584.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Critical",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2015-09-25"
},
"Updated": {
"Date": "2015-09-25"
},
"BDUs": [
{
"ID": "BDU:2015-11487",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-119",
"Href": "https://bdu.fstec.ru/vul/2015-11487",
"Impact": "Critical",
"Public": "20150922"
},
{
"ID": "BDU:2015-11488",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-20",
"Href": "https://bdu.fstec.ru/vul/2015-11488",
"Impact": "Critical",
"Public": "20150922"
},
{
"ID": "BDU:2015-11489",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-416",
"Href": "https://bdu.fstec.ru/vul/2015-11489",
"Impact": "Critical",
"Public": "20150922"
},
{
"ID": "BDU:2015-11490",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-843",
"Href": "https://bdu.fstec.ru/vul/2015-11490",
"Impact": "Critical",
"Public": "20150922"
},
{
"ID": "BDU:2015-11491",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-416",
"Href": "https://bdu.fstec.ru/vul/2015-11491",
"Impact": "Critical",
"Public": "20150922"
},
{
"ID": "BDU:2015-11492",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-119",
"Href": "https://bdu.fstec.ru/vul/2015-11492",
"Impact": "Critical",
"Public": "20150922"
},
{
"ID": "BDU:2015-11493",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-119",
"Href": "https://bdu.fstec.ru/vul/2015-11493",
"Impact": "Critical",
"Public": "20150922"
},
{
"ID": "BDU:2015-11494",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-119",
"Href": "https://bdu.fstec.ru/vul/2015-11494",
"Impact": "Critical",
"Public": "20150922"
},
{
"ID": "BDU:2015-11495",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-119",
"Href": "https://bdu.fstec.ru/vul/2015-11495",
"Impact": "Critical",
"Public": "20150922"
},
{
"ID": "BDU:2015-11496",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-119",
"Href": "https://bdu.fstec.ru/vul/2015-11496",
"Impact": "Critical",
"Public": "20150922"
},
{
"ID": "BDU:2015-11497",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-416",
"Href": "https://bdu.fstec.ru/vul/2015-11497",
"Impact": "Critical",
"Public": "20150922"
},
{
"ID": "BDU:2015-11498",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-119",
"Href": "https://bdu.fstec.ru/vul/2015-11498",
"Impact": "Critical",
"Public": "20150922"
},
{
"ID": "BDU:2015-11499",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-416",
"Href": "https://bdu.fstec.ru/vul/2015-11499",
"Impact": "Critical",
"Public": "20150922"
},
{
"ID": "BDU:2015-11500",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-119",
"Href": "https://bdu.fstec.ru/vul/2015-11500",
"Impact": "Critical",
"Public": "20150922"
},
{
"ID": "BDU:2015-11501",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-119",
"Href": "https://bdu.fstec.ru/vul/2015-11501",
"Impact": "Critical",
"Public": "20150922"
},
{
"ID": "BDU:2015-11502",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-119",
"Href": "https://bdu.fstec.ru/vul/2015-11502",
"Impact": "Critical",
"Public": "20150922"
},
{
"ID": "BDU:2015-11503",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-119",
"Href": "https://bdu.fstec.ru/vul/2015-11503",
"Impact": "Critical",
"Public": "20150922"
},
{
"ID": "BDU:2015-11504",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-119",
"Href": "https://bdu.fstec.ru/vul/2015-11504",
"Impact": "Critical",
"Public": "20150922"
},
{
"ID": "BDU:2015-11505",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-416",
"Href": "https://bdu.fstec.ru/vul/2015-11505",
"Impact": "Critical",
"Public": "20150922"
},
{
"ID": "BDU:2015-11527",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"CWE": "CWE-200",
"Href": "https://bdu.fstec.ru/vul/2015-11527",
"Impact": "Low",
"Public": "20150922"
},
{
"ID": "BDU:2015-11528",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"CWE": "CWE-200",
"Href": "https://bdu.fstec.ru/vul/2015-11528",
"Impact": "Low",
"Public": "20150922"
},
{
"ID": "BDU:2015-11529",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"CWE": "CWE-200",
"Href": "https://bdu.fstec.ru/vul/2015-11529",
"Impact": "Low",
"Public": "20150922"
},
{
"ID": "BDU:2015-11531",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"CWE": "CWE-200",
"Href": "https://bdu.fstec.ru/vul/2015-11531",
"Impact": "Low",
"Public": "20150922"
}
],
"CVEs": [
{
"ID": "CVE-2015-5567",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-119",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2015-5567",
"Impact": "Critical",
"Public": "20150922"
},
{
"ID": "CVE-2015-5568",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-20",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2015-5568",
"Impact": "Critical",
"Public": "20150922"
},
{
"ID": "CVE-2015-5570",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "NVD-CWE-Other",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2015-5570",
"Impact": "Critical",
"Public": "20150922"
},
{
"ID": "CVE-2015-5571",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"CWE": "CWE-352",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2015-5571",
"Impact": "Low",
"Public": "20150922"
},
{
"ID": "CVE-2015-5572",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"CWE": "CWE-200",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2015-5572",
"Impact": "Low",
"Public": "20150922"
},
{
"ID": "CVE-2015-5573",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "NVD-CWE-Other",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2015-5573",
"Impact": "Critical",
"Public": "20150922"
},
{
"ID": "CVE-2015-5574",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "NVD-CWE-Other",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2015-5574",
"Impact": "Critical",
"Public": "20150922"
},
{
"ID": "CVE-2015-5575",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-119",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2015-5575",
"Impact": "Critical",
"Public": "20150922"
},
{
"ID": "CVE-2015-5576",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"CWE": "CWE-200",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2015-5576",
"Impact": "Low",
"Public": "20150922"
},
{
"ID": "CVE-2015-5577",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-119",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2015-5577",
"Impact": "Critical",
"Public": "20150922"
},
{
"ID": "CVE-2015-5578",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-119",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2015-5578",
"Impact": "Critical",
"Public": "20150922"
},
{
"ID": "CVE-2015-5579",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-119",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2015-5579",
"Impact": "Critical",
"Public": "20150922"
},
{
"ID": "CVE-2015-5580",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-119",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2015-5580",
"Impact": "Critical",
"Public": "20150922"
},
{
"ID": "CVE-2015-5581",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "NVD-CWE-Other",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2015-5581",
"Impact": "Critical",
"Public": "20150922"
},
{
"ID": "CVE-2015-5582",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-119",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2015-5582",
"Impact": "Critical",
"Public": "20150922"
},
{
"ID": "CVE-2015-5584",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "NVD-CWE-Other",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2015-5584",
"Impact": "Critical",
"Public": "20150922"
},
{
"ID": "CVE-2015-5587",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-119",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2015-5587",
"Impact": "Critical",
"Public": "20150922"
},
{
"ID": "CVE-2015-5588",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-119",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2015-5588",
"Impact": "Critical",
"Public": "20150922"
},
{
"ID": "CVE-2015-6676",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-119",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2015-6676",
"Impact": "Critical",
"Public": "20150922"
},
{
"ID": "CVE-2015-6677",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-119",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2015-6677",
"Impact": "Critical",
"Public": "20150922"
},
{
"ID": "CVE-2015-6678",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-119",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2015-6678",
"Impact": "Critical",
"Public": "20150922"
},
{
"ID": "CVE-2015-6679",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"CWE": "CWE-200",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2015-6679",
"Impact": "Low",
"Public": "20150922"
},
{
"ID": "CVE-2015-6682",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "NVD-CWE-Other",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2015-6682",
"Impact": "Critical",
"Public": "20150922"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:10",
"cpe:/o:alt:spserver:10"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:4001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20151803001",
"Comment": "i586-mozilla-plugin-adobe-flash is earlier than 3:11.2.202.521-alt53"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20151803002",
"Comment": "mozilla-plugin-adobe-flash is earlier than 3:11.2.202.521-alt53"
}
]
}
]
}
}
]
}