1 |
-----BEGIN PGP SIGNED MESSAGE----- |
2 |
Hash: SHA1 |
3 |
|
4 |
- - --------------------------------------------------------------------- |
5 |
GENTOO LINUX SECURITY ANNOUNCEMENT 200303-9 |
6 |
- - --------------------------------------------------------------------- |
7 |
|
8 |
PACKAGE : netscape-flash |
9 |
SUMMARY : buffer overflow |
10 |
DATE : 2003-03-09 01:56 UTC |
11 |
EXPLOIT : remote |
12 |
VERSIONS AFFECTED : <6.0.79 |
13 |
FIXED VERSION : =>6.0.79 |
14 |
CVE : |
15 |
|
16 |
- - --------------------------------------------------------------------- |
17 |
|
18 |
- From advisory: |
19 |
"The cumulative security patch is available today and addresses the |
20 |
potential for exploits surrounding buffer overflows (read/write) and |
21 |
sandbox integrity within the player, which might allow malicious users |
22 |
to gain access to a user's computer. The possibility of running native |
23 |
code on a users machine is a theoretical exploit, and extremely |
24 |
difficult to execute in practice. There are no known examples of |
25 |
running such native code from Macromedia Flash movies; however, even |
26 |
though this issue is difficult and theoretical in nature only, we |
27 |
are encouraging users to upgrade." |
28 |
|
29 |
Read the full advisory at: |
30 |
http://www.macromedia.com/v1/handlers/index.cfm?ID=23821 |
31 |
|
32 |
SOLUTION |
33 |
|
34 |
It is recommended that all Gentoo Linux users who are running |
35 |
net-www/netscape-flash upgrade to netscape-flash-6.0.79 as follows: |
36 |
|
37 |
emerge sync |
38 |
emerge netscape-flash |
39 |
emerge clean |
40 |
|
41 |
- - --------------------------------------------------------------------- |
42 |
aliz@g.o - GnuPG key is available at http://cvs.gentoo.org/~aliz |
43 |
- - --------------------------------------------------------------------- |
44 |
-----BEGIN PGP SIGNATURE----- |
45 |
Version: GnuPG v1.2.1 (GNU/Linux) |
46 |
|
47 |
iD8DBQE+ap9HfT7nyhUpoZMRAlRuAJ4oOZYqilO1mRTGJW70KA1JI20CuQCggBp3 |
48 |
UGP5R8pxURyGTPEVsbstJMI= |
49 |
=dyfL |
50 |
-----END PGP SIGNATURE----- |