Gentoo Archives: gentoo-announce

From: Alex Legler <a3li@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 201001-02 ] Adobe Flash Player: Multiple vulnerabilities
Date: Sun, 03 Jan 2010 18:08:10
Message-Id: 20100103182413.50cf38e2@mail.a3li.li
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201001-02
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Adobe Flash Player: Multiple vulnerabilities
9 Date: January 03, 2010
10 Bugs: #296407
11 ID: 201001-02
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities in Adobe Flash Player might allow remote
19 attackers to execute arbitrary code or cause a Denial of Service.
20
21 Background
22 ==========
23
24 The Adobe Flash Player is a renderer for the SWF file format, which is
25 commonly used to provide interactive websites.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 www-plugins/adobe-flash < 10.0.42.34 >= 10.0.42.34
34
35 Description
36 ===========
37
38 Multiple vulnerabilities have been discovered in Adobe Flash Player:
39
40 * An anonymous researcher working with the Zero Day Initiative
41 reported that Adobe Flash Player does not properly process JPEG files
42 (CVE-2009-3794).
43
44 * Jim Cheng of EffectiveUI reported an unspecified data injection
45 vulnerability (CVE-2009-3796).
46
47 * Bing Liu of Fortinet's FortiGuard Labs reported multiple
48 unspecified memory corruption vulnerabilities (CVE-2009-3797,
49 CVE-2009-3798).
50
51 * Damian Put reported an integer overflow in the
52 Verifier::parseExceptionHandlers() function (CVE-2009-3799).
53
54 * Will Dormann of CERT reported multiple unspecified Denial of
55 Service vulnerabilities (CVE-2009-3800).
56
57 Impact
58 ======
59
60 A remote attacker could entice a user to open a specially crafted SWF
61 file, possibly resulting in the remote execution of arbitrary code with
62 the privileges of the user running the application, or a Denial of
63 Service via unknown vectors.
64
65 Workaround
66 ==========
67
68 There is no known workaround at this time.
69
70 Resolution
71 ==========
72
73 All Adobe Flash Player users should upgrade to the latest version:
74
75 # emerge --sync
76 # emerge --ask --oneshot --verbose
77 ">=www-plugins/adobe-flash-10.0.42.34"
78
79 References
80 ==========
81
82 [ 1 ] CVE-2009-3794
83 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3794
84 [ 2 ] CVE-2009-3796
85 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3796
86 [ 3 ] CVE-2009-3797
87 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3797
88 [ 4 ] CVE-2009-3798
89 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3798
90 [ 5 ] CVE-2009-3799
91 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3799
92 [ 6 ] CVE-2009-3800
93 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3800
94
95 Availability
96 ============
97
98 This GLSA and any updates to it are available for viewing at
99 the Gentoo Security Website:
100
101 http://security.gentoo.org/glsa/glsa-201001-02.xml
102
103 Concerns?
104 =========
105
106 Security is a primary focus of Gentoo Linux and ensuring the
107 confidentiality and security of our users machines is of utmost
108 importance to us. Any security concerns should be addressed to
109 security@g.o or alternatively, you may file a bug at
110 https://bugs.gentoo.org.
111
112 License
113 =======
114
115 Copyright 2010 Gentoo Foundation, Inc; referenced text
116 belongs to its owner(s).
117
118 The contents of this document are licensed under the
119 Creative Commons - Attribution / Share Alike license.
120
121 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature