Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 393619 - www-plugins/adobe-flash Unspecified Code Execution Vulnerability (CVE-2011-{4693,4694})
Summary: www-plugins/adobe-flash Unspecified Code Execution Vulnerability (CVE-2011-{4...
Status: RESOLVED NEEDINFO
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://secunia.com/advisories/47161/
Whiteboard: B2 [upstream?]
Keywords:
Depends on:
Blocks:
 
Reported: 2011-12-08 14:19 UTC by Agostino Sarubbo
Modified: 2013-09-03 18:12 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2011-12-08 14:19:20 UTC
From secunia security advisory at $URL:


Description:
The vulnerability is caused due to an unspecified error. No further information is currently available.

Successful exploitation allows execution of arbitrary code.

The vulnerability is reported in version 11.1.102.55. Other versions may also be affected.


Solution:
There is no patch atm.
Comment 1 GLSAMaker/CVETool Bot gentoo-dev 2011-12-12 23:50:56 UTC
CVE-2011-4694 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4694):
  Unspecified vulnerability in Adobe Flash Player 11.1.102.55 on Windows and
  Mac OS X allows remote attackers to execute arbitrary code via a crafted SWF
  file, as demonstrated by the second of two vulnerabilities exploited by the
  Intevydis vd_adobe_fp module in VulnDisco Step Ahead (SA).  NOTE: as of
  20111207, this disclosure has no actionable information. However, because
  the module author is a reliable researcher, the issue is being assigned a
  CVE identifier for tracking purposes.

CVE-2011-4693 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4693):
  Unspecified vulnerability in Adobe Flash Player 11.1.102.55 on Windows and
  Mac OS X allows remote attackers to execute arbitrary code via a crafted SWF
  file, as demonstrated by the first of two vulnerabilities exploited by the
  Intevydis vd_adobe_fp module in VulnDisco Step Ahead (SA).  NOTE: as of
  20111207, this disclosure has no actionable information. However, because
  the module author is a reliable researcher, the issue is being assigned a
  CVE identifier for tracking purposes.
Comment 2 Chris Reffett (RETIRED) gentoo-dev Security 2013-09-03 18:12:47 UTC
It's unclear whether this has been fixed. Red Hat closed this as CANTFIX due to a lack of information on what is affected. I'm inclined to agree; closing NEEDINFO.