Gentoo Archives: gentoo-announce

From: Mikle Kolyada <zlogene@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 201504-07 ] Adobe Flash Player: Multiple vulnerabilities
Date: Fri, 17 Apr 2015 15:34:28
Message-Id: 55312718.9040206@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201504-07
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Adobe Flash Player: Multiple vulnerabilities
9 Date: April 17, 2015
10 Bugs: #546706
11 ID: 201504-07
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been found in Adobe Flash Player, the
19 worst of which allows remote attackers to execute arbitrary code.
20
21 Background
22 ==========
23
24 The Adobe Flash Player is a renderer for the SWF file format, which is
25 commonly used to provide interactive websites.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 www-plugins/adobe-flash < 11.2.202.457 >= 11.2.202.457
34
35 Description
36 ===========
37
38 Multiple vulnerabilities have been discovered in Adobe Flash Player.
39 Please review the CVE identifiers referenced below for details.
40
41 Impact
42 ======
43
44 A remote attacker could possibly execute arbitrary code with the
45 privileges of the process or cause a Denial of Service condition.
46
47 Workaround
48 ==========
49
50 There is no known workaround at this time.
51
52 Resolution
53 ==========
54
55 All Adobe Flash Player users should upgrade to the latest version:
56
57 # emerge --sync
58 # emerge --ask --oneshot -v ">=www-plugins/adobe-flash-11.2.202.457"
59
60 References
61 ==========
62
63 [ 1 ] CVE-2015-0346
64 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0346
65 [ 2 ] CVE-2015-0347
66 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0347
67 [ 3 ] CVE-2015-0348
68 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0348
69 [ 4 ] CVE-2015-0349
70 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0349
71 [ 5 ] CVE-2015-0350
72 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0350
73 [ 6 ] CVE-2015-0351
74 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0351
75 [ 7 ] CVE-2015-0352
76 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0352
77 [ 8 ] CVE-2015-0353
78 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0353
79 [ 9 ] CVE-2015-0354
80 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0354
81 [ 10 ] CVE-2015-0355
82 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0355
83 [ 11 ] CVE-2015-0356
84 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0356
85 [ 12 ] CVE-2015-0357
86 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0357
87 [ 13 ] CVE-2015-0358
88 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0358
89 [ 14 ] CVE-2015-0359
90 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0359
91 [ 15 ] CVE-2015-0360
92 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0360
93 [ 16 ] CVE-2015-3038
94 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-3038
95 [ 17 ] CVE-2015-3039
96 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-3039
97 [ 18 ] CVE-2015-3040
98 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-3040
99 [ 19 ] CVE-2015-3041
100 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-3041
101 [ 20 ] CVE-2015-3042
102 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-3042
103 [ 21 ] CVE-2015-3043
104 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-3043
105 [ 22 ] CVE-2015-3044
106 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-3044
107
108 Availability
109 ============
110
111 This GLSA and any updates to it are available for viewing at
112 the Gentoo Security Website:
113
114 https://security.gentoo.org/glsa/201504-07
115
116 Concerns?
117 =========
118
119 Security is a primary focus of Gentoo Linux and ensuring the
120 confidentiality and security of our users' machines is of utmost
121 importance to us. Any security concerns should be addressed to
122 security@g.o or alternatively, you may file a bug at
123 https://bugs.gentoo.org.
124
125 License
126 =======
127
128 Copyright 2015 Gentoo Foundation, Inc; referenced text
129 belongs to its owner(s).
130
131 The contents of this document are licensed under the
132 Creative Commons - Attribution / Share Alike license.
133
134 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature