Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 343091

Summary: <app-text/acroread-9.4.1: Remote Code Execution Vulnerability (CVE-2010-3654)
Product: Gentoo Security Reporter: Tim Sammut (RETIRED) <underling>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: major CC: printing
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://www.adobe.com/support/security/advisories/apsa10-05.html
Whiteboard: A2 [glsa]
Package list:
Runtime testing required: ---

Description Tim Sammut (RETIRED) gentoo-dev 2010-10-28 15:07:31 UTC
From $URL: 

A critical  vulnerability exists in Adobe Flash Player 10.1.85.3 and earlier versions for Windows, Macintosh, Linux and Solaris operating systems; Adobe Flash Player 10.1.95.2 and earlier versions for Android; and the authplay.dll component that ships with Adobe Reader 9.4 and earlier 9.x versions for Windows, Macintosh and UNIX operating systems, and Adobe Acrobat 9.4 and earlier 9.x versions for Windows and Macintosh operating systems.

This vulnerability (CVE-2010-3654) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild against Adobe Reader and Acrobat 9.x. Adobe is not currently aware of attacks targeting Adobe Flash Player.

We are in the process of finalizing a fix for the issue and expect to provide an update for Flash Player 10.x for Windows, Macintosh, Linux, and Android by November 9, 2010. We expect to make available an update for Adobe Reader and Acrobat 9.4 and earlier 9.x versions during the week of November 15, 2010.


There is a different bug for www-plugins/adobe-flash, bug 343089.
Comment 1 Stefan Behte (RETIRED) gentoo-dev Security 2010-11-17 12:20:58 UTC
http://www.adobe.com/support/security/bulletins/apsb10-28.html

Adobe Reader 9.4.1 is available now, please provide an updated ebuild.
Comment 2 Tim Sammut (RETIRED) gentoo-dev 2010-11-17 14:29:55 UTC
(In reply to comment #1)
> http://www.adobe.com/support/security/bulletins/apsb10-28.html
> 
> Adobe Reader 9.4.1 is available now, please provide an updated ebuild.
> 

Unfortunately, the binaries for Linux will not be available until Nov. 30.

"Adobe recommends users of Adobe Reader 9.4 and earlier versions for UNIX update to Adobe Reader 9.4.1, expected to be available on November 30, 2010."
Comment 3 Tim Sammut (RETIRED) gentoo-dev 2010-12-02 01:04:46 UTC
Adobe have release Reader 9.4.1 for linux.

ftp://ftp.adobe.com/pub/adobe/reader/unix/9.x/9.4.1/
Comment 4 Timo Gurr (RETIRED) gentoo-dev 2010-12-07 22:31:17 UTC
acroread-9.4.1 is in CVS now.
Comment 5 Tim Sammut (RETIRED) gentoo-dev 2010-12-07 22:39:10 UTC
Arches, please test and mark stable:
=app-text/acroread-9.4.1
Target keywords : "amd64 x86"
Comment 6 Paweł Hajdan, Jr. (RETIRED) gentoo-dev 2010-12-08 12:56:17 UTC
x86 stable
Comment 7 Agostino Sarubbo gentoo-dev 2010-12-08 20:07:01 UTC
amd64 ok
Comment 8 Markos Chandras (RETIRED) gentoo-dev 2010-12-09 11:53:03 UTC
amd64 done. Thanks Agostino
Comment 9 Tim Sammut (RETIRED) gentoo-dev 2010-12-09 15:08:38 UTC
Thanks, folks. GLSA with bug 336508.
Comment 10 Tim Sammut (RETIRED) gentoo-dev 2011-01-21 17:19:08 UTC
This is GLSA 201101-08; thank you.