Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 446984 (CVE-2012-5676)

Summary: <www-plugins/adobe-flash-11.2.202.258: Multiple Vulnerabilities (CVE-2012-{5676,5677,5678})
Product: Gentoo Security Reporter: Agostino Sarubbo <ago>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal CC: desktop-misc, lack
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://www.adobe.com/support/security/bulletins/apsb12-27.html
Whiteboard: B2 [glsa]
Package list:
Runtime testing required: ---

Description Agostino Sarubbo gentoo-dev 2012-12-12 11:22:28 UTC
From $URL :

Adobe has released security updates for Adobe Flash Player 11.5.502.110 and earlier versions for 
Windows and Macintosh, Adobe Flash Player 11.2.202.251 and earlier versions for Linux, Adobe Flash 
Player 11.1.115.27 and earlier versions for Android 4.x, and Adobe Flash Player 11.1.111.24 and 
earlier versions for Android 3.x and 2.x. These updates address vulnerabilities that could cause a 
crash and potentially allow an attacker to take control of the affected system. 

Adobe recommends users update their product installations to the latest versions:

Users of Adobe Flash Player 11.2.202.251 and earlier versions for Linux should update to Adobe 
Flash Player 11.2.202.258.
Comment 1 Jeroen Roovers (RETIRED) gentoo-dev 2012-12-12 15:45:47 UTC
Arch teams, please test and mark stable:
=www-plugins/adobe-flash-11.2.202.258
Stable KEYWORDS : amd64 x86
Comment 2 Sergey Popov gentoo-dev 2012-12-12 16:02:42 UTC
amd64 stable
Comment 3 GLSAMaker/CVETool Bot gentoo-dev 2012-12-13 01:27:30 UTC
CVE-2012-5678 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5678):
  Adobe Flash Player before 10.3.183.48 and 11.x before 11.5.502.135 on
  Windows, before 10.3.183.48 and 11.x before 11.5.502.136 on Mac OS X, before
  10.3.183.48 and 11.x before 11.2.202.258 on Linux, before 11.1.111.29 on
  Android 2.x and 3.x, and before 11.1.115.34 on Android 4.x; Adobe AIR before
  3.5.0.880 on Windows and before 3.5.0.890 on Mac OS X; and Adobe AIR SDK
  before 3.5.0.880 on Windows and before 3.5.0.890 on Mac OS X allow attackers
  to execute arbitrary code or cause a denial of service (memory corruption)
  via unspecified vectors.

CVE-2012-5677 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5677):
  Integer overflow in Adobe Flash Player before 10.3.183.48 and 11.x before
  11.5.502.135 on Windows, before 10.3.183.48 and 11.x before 11.5.502.136 on
  Mac OS X, before 10.3.183.48 and 11.x before 11.2.202.258 on Linux, before
  11.1.111.29 on Android 2.x and 3.x, and before 11.1.115.34 on Android 4.x;
  Adobe AIR before 3.5.0.880 on Windows and before 3.5.0.890 on Mac OS X; and
  Adobe AIR SDK before 3.5.0.880 on Windows and before 3.5.0.890 on Mac OS X
  allows attackers to execute arbitrary code via unspecified vectors.

CVE-2012-5676 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5676):
  Buffer overflow in Adobe Flash Player before 10.3.183.48 and 11.x before
  11.5.502.135 on Windows, before 10.3.183.48 and 11.x before 11.5.502.136 on
  Mac OS X, before 10.3.183.48 and 11.x before 11.2.202.258 on Linux, before
  11.1.111.29 on Android 2.x and 3.x, and before 11.1.115.34 on Android 4.x;
  Adobe AIR before 3.5.0.880 on Windows and before 3.5.0.890 on Mac OS X; and
  Adobe AIR SDK before 3.5.0.880 on Windows and before 3.5.0.890 on Mac OS X
  allows attackers to execute arbitrary code via unspecified vectors.
Comment 4 Agostino Sarubbo gentoo-dev 2012-12-13 10:48:52 UTC
x86 stable
Comment 5 Sean Amoss (RETIRED) gentoo-dev Security 2012-12-13 12:49:58 UTC
Added to existing GLSA draft.
Comment 6 GLSAMaker/CVETool Bot gentoo-dev 2013-09-14 02:54:40 UTC
This issue was resolved and addressed in
 GLSA 201309-06 at http://security.gentoo.org/glsa/glsa-201309-06.xml
by GLSA coordinator Sean Amoss (ackle).