Gentoo Archives: gentoo-announce

From: Thomas Deutschmann <whissi@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 201701-17 ] Adobe Flash Player: Multiple vulnerabilities
Date: Tue, 10 Jan 2017 13:57:26
Message-Id: 7f32c9b8-af64-1a0f-7099-f7be88cee831@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201701-17
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Adobe Flash Player: Multiple vulnerabilities
9 Date: January 10, 2017
10 Bugs: #602546
11 ID: 201701-17
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been found in Adobe Flash Player, the
19 worst of which allows remote attackers to execute arbitrary code.
20
21 Background
22 ==========
23
24 The Adobe Flash Player is a renderer for the SWF file format, which is
25 commonly used to provide interactive websites.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 www-plugins/adobe-flash < 24.0.0.186 >= 24.0.0.186
34
35 Description
36 ===========
37
38 Multiple vulnerabilities have been discovered in Adobe Flash Player.
39 Please review the CVE identifiers referenced below for details.
40
41 Impact
42 ======
43
44 A remote attacker could possibly execute arbitrary code with the
45 privileges of the process or bypass security restrictions.
46
47 Workaround
48 ==========
49
50 There is no known workaround at this time.
51
52 Resolution
53 ==========
54
55 All Adobe Flash Player users should upgrade to the latest version:
56
57 # emerge --sync
58 # emerge --ask --oneshot -v ">=www-plugins/adobe-flash-24.0.0.186"
59
60 References
61 ==========
62
63 [ 1 ] APSB16-39
64 https://helpx.adobe.com/security/products/flash-player/apsb16-39.html
65 [ 2 ] CVE-2016-7867
66 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7867
67 [ 3 ] CVE-2016-7868
68 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7868
69 [ 4 ] CVE-2016-7869
70 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7869
71 [ 5 ] CVE-2016-7870
72 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7870
73 [ 6 ] CVE-2016-7871
74 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7871
75 [ 7 ] CVE-2016-7872
76 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7872
77 [ 8 ] CVE-2016-7873
78 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7873
79 [ 9 ] CVE-2016-7874
80 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7874
81 [ 10 ] CVE-2016-7875
82 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7875
83 [ 11 ] CVE-2016-7876
84 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7876
85 [ 12 ] CVE-2016-7877
86 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7877
87 [ 13 ] CVE-2016-7878
88 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7878
89 [ 14 ] CVE-2016-7879
90 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7879
91 [ 15 ] CVE-2016-7880
92 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7880
93 [ 16 ] CVE-2016-7881
94 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7881
95 [ 17 ] CVE-2016-7890
96 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7890
97 [ 18 ] CVE-2016-7892
98 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-7892
99
100 Availability
101 ============
102
103 This GLSA and any updates to it are available for viewing at
104 the Gentoo Security Website:
105
106 https://security.gentoo.org/glsa/201701-17
107
108 Concerns?
109 =========
110
111 Security is a primary focus of Gentoo Linux and ensuring the
112 confidentiality and security of our users' machines is of utmost
113 importance to us. Any security concerns should be addressed to
114 security@g.o or alternatively, you may file a bug at
115 https://bugs.gentoo.org.
116
117 License
118 =======
119
120 Copyright 2017 Gentoo Foundation, Inc; referenced text
121 belongs to its owner(s).
122
123 The contents of this document are licensed under the
124 Creative Commons - Attribution / Share Alike license.
125
126 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature