Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: GLSA: netscape-flash (200303-9)
Date: Sun, 09 Mar 2003 12:36:37
Message-Id: 20030309015629.CFAC25763@mail2.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - ---------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200303-9
6 - - ---------------------------------------------------------------------
7
8 PACKAGE : netscape-flash
9 SUMMARY : buffer overflow
10 DATE : 2003-03-09 01:56 UTC
11 EXPLOIT : remote
12 VERSIONS AFFECTED : <6.0.79
13 FIXED VERSION : =>6.0.79
14 CVE :
15
16 - - ---------------------------------------------------------------------
17
18 - From advisory:
19 "The cumulative security patch is available today and addresses the
20 potential for exploits surrounding buffer overflows (read/write) and
21 sandbox integrity within the player, which might allow malicious users
22 to gain access to a user's computer. The possibility of running native
23 code on a users machine is a theoretical exploit, and extremely
24 difficult to execute in practice. There are no known examples of
25 running such native code from Macromedia Flash movies; however, even
26 though this issue is difficult and theoretical in nature only, we
27 are encouraging users to upgrade."
28
29 Read the full advisory at:
30 http://www.macromedia.com/v1/handlers/index.cfm?ID=23821
31
32 SOLUTION
33
34 It is recommended that all Gentoo Linux users who are running
35 net-www/netscape-flash upgrade to netscape-flash-6.0.79 as follows:
36
37 emerge sync
38 emerge netscape-flash
39 emerge clean
40
41 - - ---------------------------------------------------------------------
42 aliz@g.o - GnuPG key is available at http://cvs.gentoo.org/~aliz
43 - - ---------------------------------------------------------------------
44 -----BEGIN PGP SIGNATURE-----
45 Version: GnuPG v1.2.1 (GNU/Linux)
46
47 iD8DBQE+ap9HfT7nyhUpoZMRAlRuAJ4oOZYqilO1mRTGJW70KA1JI20CuQCggBp3
48 UGP5R8pxURyGTPEVsbstJMI=
49 =dyfL
50 -----END PGP SIGNATURE-----