Adobe Security Bulletin APSB15-25 for Adobe Flash Player describes a flaw that can possibly lead to bypass of the same origin policy and disclosure of sensitive information Flash Player is used to play a specially crafted SWF file. It also describes hardening fix for the Flash broker API. Quoting from the APSB15-25: These updates resolve a vulnerability that could be exploited to bypass the same-origin-policy and lead to information disclosure (CVE-2015-7628). These updates include a defense-in-depth feature in the Flash broker API (CVE-2015-5569). External References: https://helpx.adobe.com/security/products/flash-player/apsb15-25.html
This issue has been addressed in the following products: Supplementary for Red Hat Enterprise Linux 6 Via RHSA-2015:1893 https://rhn.redhat.com/errata/RHSA-2015-1893.html
This issue has been addressed in the following products: Supplementary for Red Hat Enterprise Linux 5 Via RHSA-2015:2024 https://rhn.redhat.com/errata/RHSA-2015-2024.html