Gentoo Archives: gentoo-announce

From: Kristian Fiskerstrand <k_f@g.o>
To: gentoo-announce@g.o
Subject: [gentoo-announce] [ GLSA 201411-06 ] Adobe Flash Player: Multiple vulnerabilities
Date: Fri, 21 Nov 2014 12:35:43
Message-Id: 546F2B02.6000309@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201411-06
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Adobe Flash Player: Multiple vulnerabilities
9 Date: November 21, 2014
10 Bugs: #525430, #529088
11 ID: 201411-06
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been found in Adobe Flash Player, the
19 worst of which allows remote attackers to execute arbitrary code.
20
21 Background
22 ==========
23
24 The Adobe Flash Player is a renderer for the SWF file format, which is
25 commonly used to provide interactive websites.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 www-plugins/adobe-flash < 11.2.202.418 >= 11.2.202.418
34
35 Description
36 ===========
37
38 Multiple vulnerabilities have been discovered in Adobe Flash Player.
39 Please review the CVE identifiers referenced below for details.
40
41 Impact
42 ======
43
44 A remote attacker could possibly execute arbitrary code with the
45 privileges of the process or bypass security restrictions.
46
47 Workaround
48 ==========
49
50 There is no known workaround at this time.
51
52 Resolution
53 ==========
54
55 All Adobe Flash Player users should upgrade to the latest version:
56
57 # emerge --sync
58 # emerge --ask --oneshot -v ">=www-plugins/adobe-flash-11.2.202.418"
59
60 References
61 ==========
62
63 [ 1 ] CVE-2014-0558
64 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0558
65 [ 2 ] CVE-2014-0564
66 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0564
67 [ 3 ] CVE-2014-0569
68 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0569
69 [ 4 ] CVE-2014-0573
70 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0573
71 [ 5 ] CVE-2014-0574
72 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0574
73 [ 6 ] CVE-2014-0576
74 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0576
75 [ 7 ] CVE-2014-0577
76 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0577
77 [ 8 ] CVE-2014-0581
78 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0581
79 [ 9 ] CVE-2014-0582
80 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0582
81 [ 10 ] CVE-2014-0583
82 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0583
83 [ 11 ] CVE-2014-0584
84 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0584
85 [ 12 ] CVE-2014-0585
86 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0585
87 [ 13 ] CVE-2014-0586
88 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0586
89 [ 14 ] CVE-2014-0588
90 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0588
91 [ 15 ] CVE-2014-0589
92 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0589
93 [ 16 ] CVE-2014-0590
94 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0590
95 [ 17 ] CVE-2014-8437
96 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-8437
97 [ 18 ] CVE-2014-8438
98 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-8438
99 [ 19 ] CVE-2014-8440
100 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-8440
101 [ 20 ] CVE-2014-8441
102 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-8441
103 [ 21 ] CVE-2014-8442
104 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-8442
105
106 Availability
107 ============
108
109 This GLSA and any updates to it are available for viewing at
110 the Gentoo Security Website:
111
112 http://security.gentoo.org/glsa/glsa-201411-06.xml
113
114 Concerns?
115 =========
116
117 Security is a primary focus of Gentoo Linux and ensuring the
118 confidentiality and security of our users' machines is of utmost
119 importance to us. Any security concerns should be addressed to
120 security@g.o or alternatively, you may file a bug at
121 https://bugs.gentoo.org.
122
123 License
124 =======
125
126 Copyright 2014 Gentoo Foundation, Inc; referenced text
127 belongs to its owner(s).
128
129 The contents of this document are licensed under the
130 Creative Commons - Attribution / Share Alike license.
131
132 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature