Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 16851 - flash 6.0.69 has a security hole. that's why 6.0.79 has been released.
Summary: flash 6.0.69 has a security hole. that's why 6.0.79 has been released.
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: x86 Linux
: High critical (vote)
Assignee: Gentoo Security
URL: http://www.heise.de/newsticker/data/p...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2003-03-04 15:13 UTC by Andreas Kotowicz
Modified: 2003-03-08 21:00 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
The ebuild (netscape-flash-6.0.79.ebuild,1.54 KB, text/plain)
2003-03-06 05:35 UTC, Patrick Kursawe (RETIRED)
Details
Second try (netscape-flash-6.0.79.ebuild,1.44 KB, text/plain)
2003-03-06 06:13 UTC, Patrick Kursawe (RETIRED)
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Kotowicz 2003-03-04 15:13:01 UTC
I found this on some german internet page (see link above).  the new player is
already available for download at
http://download.macromedia.com/pub/shockwave/flash/english/linux/6.0r79/install_flash_player_6_linux.tar.gz

Reproducible: Always
Steps to Reproduce:
1.
2.
3.
Comment 1 Oliver Schoett 2003-03-04 15:56:00 UTC
This bug should be flagged SECURITY and have Severity critical (I am not allowed to do this).

The bug can be exploited by any website to get the full rights of the visiting user on the visiting computer.

Macromedia Security Bulletin in English:
http://www.macromedia.com/v1/handlers/index.cfm?ID=23821
Comment 2 Patrick Kursawe (RETIRED) gentoo-dev 2003-03-06 05:35:37 UTC
Created attachment 9015 [details]
The ebuild

Yes, I know this is sick...
Comment 3 Patrick Kursawe (RETIRED) gentoo-dev 2003-03-06 05:36:14 UTC
That is bad news, especially since the filename is the same as for the buggy version. How to get this into portage?

My following suggestion:
Don't set SRC_URI to avoid portage complaining about file digests. Do the
MD5 check and downloading manually.

Ebuild attached, works fine for me.
Comment 4 Patrick Kursawe (RETIRED) gentoo-dev 2003-03-06 06:13:17 UTC
Created attachment 9017 [details]
Second try

Some cosmetics.
Comment 5 Daniel Ahlberg (RETIRED) gentoo-dev 2003-03-08 21:00:30 UTC
glsa sent