Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 563172 (CVE-2015-7645) - <www-plugins/adobe-flash-11.2.202.540: Multiple vulnerabilities (APSB15-27) (CVE-2015-{7645,7646,7647,7648})
Summary: <www-plugins/adobe-flash-11.2.202.540: Multiple vulnerabilities (APSB15-27) (...
Status: RESOLVED FIXED
Alias: CVE-2015-7645
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://helpx.adobe.com/security/prod...
Whiteboard: A2 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2015-10-16 00:11 UTC by Linear Systems Tech Svcs.
Modified: 2015-11-17 11:47 UTC (History)
4 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Linear Systems Tech Svcs. 2015-10-16 00:11:36 UTC
Adobe has released a security advisory for all versions of Adobe Flash Player up through the newly released 11.2.202.535.  Adobe has given this vulnerability a Critical rating for all platforms.

Learn more: https://helpx.adobe.com/security/products/flash-player/apsa15-05.html

Affected: Adobe Flash Player for Linux     versions 11.2.202.535 and earlier     Linux

Solution and priority:
At this time, Adobe is expecting a patch for this vulnerability by October 23rd, 2015.

Reproducible: Always
Comment 1 Daniel Kenzelmann 2015-10-16 19:17:51 UTC
Hotfix version for this vulnerability is 11.2.202.540 which is currently distributed.

See:
https://helpx.adobe.com/security/products/flash-player/apsb15-27.html

Change title to:

<www-plugins/adobe-flash-11.2.202.540 : Vulnerability in adobe flash player (APSB15-27) (CVE-2015-7645)

Please update and stabilize,
Comment 2 GLSAMaker/CVETool Bot gentoo-dev 2015-10-19 14:32:30 UTC
CVE-2015-7645 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7645):
  Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on
  Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote
  attackers to execute arbitrary code via a crafted SWF file, as exploited in
  the wild in October 2015.
Comment 3 Jeroen Roovers (RETIRED) gentoo-dev 2015-10-20 03:18:34 UTC
Arch teams, please test and mark stable:
=www-plugins/adobe-flash-11.2.202.540
Targeted stable KEYWORDS : amd64 x86
Comment 4 Agostino Sarubbo gentoo-dev 2015-10-20 09:38:56 UTC
amd64 stable
Comment 5 Agostino Sarubbo gentoo-dev 2015-10-20 09:39:21 UTC
x86 stable.

Maintainer(s), please cleanup.
Security, please add it to the existing request, or file a new one.
Comment 6 Sergey Popov gentoo-dev 2015-10-20 12:48:46 UTC
Thanks for you work

Cleanup is done by maintainer, GLSA request filed
Comment 7 GLSAMaker/CVETool Bot gentoo-dev 2015-11-17 11:47:29 UTC
This issue was resolved and addressed in
 GLSA 201511-02 at https://security.gentoo.org/glsa/201511-02
by GLSA coordinator Sergey Popov (pinkbyte).