<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>112251</bug_id>
          
          <creation_ts>2005-11-12 03:16 0000</creation_ts>
          <short_desc>net-www/netscape-flash: arbitrary code execution</short_desc>
          <delta_ts>2005-11-25 04:21:07 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://secunia.com/advisories/17430/</bug_file_loc>
          <status_whiteboard>A2 [glsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>major</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>taviso@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>flash3001@yahoo.com</cc>
    
    <cc>tetromino@gmail.com</cc>

      

      
          <long_desc isprivate="0">
            <who>taviso@gentoo.org</who>
            <bug_when>2005-11-12 03:16:04 0000</bug_when>
            <thetext>The netscape-flash package installs an old vulnerable `gflashplayer` when the 
gtk USE flag is set, this version is vulnerable to a security flaw and should be 
removed from the package.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-11-13 10:04:51 0000</bug_when>
            <thetext>No maintainer...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vapier@gentoo.org</who>
            <bug_when>2005-11-14 16:57:26 0000</bug_when>
            <thetext>so there is no new version of gflashplayer ?  our only choice is to not install
it at all ?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kevquinn@gentoo.org</who>
            <bug_when>2005-11-15 00:17:39 0000</bug_when>
            <thetext>The Secunia advisory says that v8 and v7.0.60.0/7.0.61.0 are not vulnerable.
The current ebuild installs 7.0.25 so presumably that&apos;s vulnerable as well as
gflashplayer.  There&apos;s no v8 available for Linux, and while there is a 7.0.61.0
currently at

http://fpdownload.macromedia.com/get/flashplayer/current/install_flash_player_7_linux.tar.gz

it is not available through the official mirror sites
http://macromedia.mplug.org/ where the latest version is 7.0.25.0 (presumably
vulnerable).

This macromedia.com URL obviously isn&apos;t stable from one point revision to the
next, and
http://www.macromedia.com/software/flashplayer/productinfo/faq/#item-3-2
explicitly prohibits redistribution.

We could create net-www/netscape-flash-7.ebuild, and do a -rN bump every time
Macromedia do a point revision so users see the revision change.  Might need
RESTRICT=fetch.  Alternatively perhaps poking macromedia.mplug.org to update
would be simpler (warren@togami.com) - 7.0.61.0 was released 4th Nov.

The standalone player in v6 doesn&apos;t use libflashplayer.so so presumably is
vulnerable, and as there&apos;s no newer version I guess we should ditch it.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vapier@gentoo.org</who>
            <bug_when>2005-11-15 06:11:43 0000</bug_when>
            <thetext>dropped an e-mail to warren@togami.com</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>taviso@gentoo.org</who>
            <bug_when>2005-11-15 08:56:12 0000</bug_when>
            <thetext>Kevin, the secunia advisory says &quot;versions prior to 7.0.25.0 on the Unix 
platform.&quot;, so the plugin is fine, only the gflashplayer is vulnerable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kevquinn@gentoo.org</who>
            <bug_when>2005-11-16 13:44:57 0000</bug_when>
            <thetext>Hmm; didn&apos;t see that bit, I paid more attention to the &apos;solution&apos; part that
indicates updating to 7.0.61.0 as the recommended fix.

Macromedia&apos;s notice at
http://www.macromedia.com/devnet/security/security_zone/mpsb05-07.html says
&quot;Flash Player 7.0.53.0 and earlier&quot; are vulnerable; whether that includes the
Unix version or not is unclear but there&apos;s no real reason to suspect the Unix
version is any different to the Windows version in this respect.

The SEC Consult and the Eeye reports are different overflows, similar enough to
be the same issue but in different functions.  Macromedia&apos;s release indicates
there were multiple instances of unchecked array bounds, &quot;There was a problem
with bounds validation for indexes of certain arrays in Flash Player 7 and
earlier&quot;.  SEC Consult say their issue is resolved in 7.0.25.0, eEye don&apos;t
identify specific point revisions, however Macromedia say 7.0.61.0 or 7.0.60.0
are the versions in which the problems are fixed, so I&apos;d tend to go with that.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>taviso@gentoo.org</who>
            <bug_when>2005-11-18 01:51:49 0000</bug_when>
            <thetext>karma@designfolks.com.au provided a testcase http://www.designfolks.com.au/df.
swf

It does crash gflashplayer, but the plugin seems to survive.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>taviso@gentoo.org</who>
            <bug_when>2005-11-18 02:15:22 0000</bug_when>
            <thetext>Oops, my mistake, the plugin is affected as well.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>taviso@gentoo.org</who>
            <bug_when>2005-11-18 03:17:10 0000</bug_when>
            <thetext>shellsage points out macromedia has released a new version of the plugin here 
http://www.macromedia.com/devnet/security/security_zone/mpsb05-07.html, i&apos;ve 
installed 7.0.61.0 and confirm the poc no longer works.

No gflashplayer, but we need to push the plugin out asap.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>shellsage@gentoo.org</who>
            <bug_when>2005-11-18 03:38:51 0000</bug_when>
            <thetext>Created an attachment (id=73126)
Ebuild for =net-www/netscape-flash-7.0.61

Sending ebuild per taviso&apos;s request.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>shellsage@gentoo.org</who>
            <bug_when>2005-11-18 03:40:37 0000</bug_when>
            <thetext>A note about the ebuild I just posted: I removed support for gflashplayer and
the gtk use flag. Versions &lt;= 7.0.61 of the player are vulnerable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-11-18 04:27:45 0000</bug_when>
            <thetext>No maintainer, so security should bump it</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-11-21 01:03:57 0000</bug_when>
            <thetext>Tavis/solar/vapier: please doublecheck the ebuild and security-bump that
package. The sooner it&apos;s out, the better.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>taviso@gentoo.org</who>
            <bug_when>2005-11-23 02:04:13 0000</bug_when>
            <thetext>bumpified, requires stabilisation.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-11-23 02:18:39 0000</bug_when>
            <thetext>Arches please test and mark stable. </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>wolf31o2@gentoo.org</who>
            <bug_when>2005-11-23 08:13:44 0000</bug_when>
            <thetext>Using this plugin, if I right click on a movie in Firefox, it crashes Firefox. 
Firefox is 1.0.7-r3...

The current stable plugin does not have this issue.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dang@gentoo.org</who>
            <bug_when>2005-11-23 08:16:20 0000</bug_when>
            <thetext>Works fine here.  amd64 done.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-11-24 02:38:28 0000</bug_when>
            <thetext>Chris: can&apos;t reproduce your issue on x86 with Firefox 1.0.7. Right-clicking on
Flash things works OK here. x86 ATs, please confirm.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>halcy0n@gentoo.org</who>
            <bug_when>2005-11-24 17:31:18 0000</bug_when>
            <thetext>No problems in firefox or mozilla for me.  Looks good on x86.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-11-25 04:21:07 0000</bug_when>
            <thetext>GLSA 200511-21</thetext>
          </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="0"
              isprivate="0"
          >
            <attachid>73126</attachid>
            <date>2005-11-18 03:38 0000</date>
            <desc>Ebuild for =net-www/netscape-flash-7.0.61</desc>
            <filename>netscape-flash-7.0.61.ebuild</filename>
            <type>application/octet-stream</type>
            <data encoding="base64">IyBDb3B5cmlnaHQgMTk5OS0yMDA1IEdlbnRvbyBGb3VuZGF0aW9uCiMgRGlzdHJpYnV0ZWQgdW5k
ZXIgdGhlIHRlcm1zIG9mIHRoZSBHTlUgR2VuZXJhbCBQdWJsaWMgTGljZW5zZSB2MgojICRIZWFk
ZXI6IC92YXIvY3Zzcm9vdC9nZW50b28teDg2L25ldC13d3cvbmV0c2NhcGUtZmxhc2gvbmV0c2Nh
cGUtZmxhc2gtNy4wLjI1LmVidWlsZCx2IDEuOSAyMDA1LzA4LzExIDIwOjI1OjQyIGZsYW1lZXll
cyBFeHAgJAoKaW5oZXJpdCBuc3BsdWdpbnMKClM9JHtXT1JLRElSfS9pbnN0YWxsX2ZsYXNoX3Bs
YXllcl83X2xpbnV4CkRFU0NSSVBUSU9OPSJNYWNyb21lZGlhIFNob2Nrd2F2ZSBGbGFzaCBQbGF5
ZXIiClNSQ19VUkk9Im1pcnJvcjovL21hY3JvbWVkaWEvZmxhc2gtcGx1Z2luLSR7UFZ9LnRhci5n
eiIKSE9NRVBBR0U9Imh0dHA6Ly93d3cubWFjcm9tZWRpYS5jb20vIgoKU0xPVD0iMCIKS0VZV09S
RFM9Ing4NiBhbWQ2NCAtcHBjIC1zcGFyYyIKTElDRU5TRT0iTWFjcm9tZWRpYSIKCkRFUEVORD0i
IW5ldC13d3cvZ3BsZmxhc2gKCWFtZDY0PyAoYXBwLWVtdWxhdGlvbi9lbXVsLWxpbnV4LXg4Ni1i
YXNlbGlicwoJCWFwcC1lbXVsYXRpb24vZW11bC1saW51eC14ODYteGxpYnMgKSIKUkVTVFJJQ1Q9
Im5vc3RyaXAiCgpwa2dfc2V0dXAoKSB7CgkjIFRoaXMgaXMgYSBiaW5hcnkgeDg2IHBhY2thZ2Ug
PT4gQUJJPXg4NgoJIyBQbGVhc2Uga2VlcCB0aGlzIGluIGZ1dHVyZSB2ZXJzaW9ucwoJIyBEYW5u
eSB2YW4gRHlrIDxrdWdlbGZhbmdAZ2VudG9vLm9yZz4gMjAwNS8wMy8yNgoJaGFzX211bHRpbGli
X3Byb2ZpbGUgJiYgQUJJPSJ4ODYiCn0KCnNyY19pbnN0YWxsKCkgewoJZXhlaW50byAvb3B0L25l
dHNjYXBlL3BsdWdpbnMKCWRvZXhlIGxpYmZsYXNocGxheWVyLnNvCgoJaW5zaW50byAvb3B0L25l
dHNjYXBlL3BsdWdpbnMKCWRvaW5zIGZsYXNocGxheWVyLnhwdAoKCWluc3RfcGx1Z2luIC9vcHQv
bmV0c2NhcGUvcGx1Z2lucy9saWJmbGFzaHBsYXllci5zbwoJaW5zdF9wbHVnaW4gL29wdC9uZXRz
Y2FwZS9wbHVnaW5zL2ZsYXNocGxheWVyLnhwdAoKCWRvZG9jIFJlYWRtZS50eHQKCWRvaHRtbCBS
ZWFkbWUuaHRtCn0K
</data>        

          </attachment>
    </bug>

</bugzilla>