Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 473038 (CVE-2013-3343)

Summary: <www-plugins/adobe-flash-{,} - Unspecified vulnerability (CVE-2013-3343)
Product: Gentoo Security Reporter: Max Steel <M.Steel>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Severity: normal CC: desktop-misc, jer
Priority: Normal Keywords: STABLEREQ
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard: B2 [glsa]
Package list:
Runtime testing required: ---

Description Max Steel 2013-06-11 21:56:47 UTC
adobe-flash released by upstream.

Reproducible: Always
Comment 1 Jeroen Roovers (RETIRED) gentoo-dev 2013-06-12 00:32:03 UTC
Arch teams, please test and mark stable:
Stable KEYWORDS : amd64 x86
Comment 2 Agostino Sarubbo gentoo-dev 2013-06-12 10:39:07 UTC
amd64 stable
Comment 3 Agostino Sarubbo gentoo-dev 2013-06-12 10:39:17 UTC
x86 stable
Comment 4 Piotr Szymaniak 2013-06-12 20:33:40 UTC
I know this isn't the best bug for it, but this seems important for stable packages (x86 here):

>>> Downloading ''
--2013-06-12 22:29:01--
Łączenie się z||:80... połączono.
Żądanie HTTP wysłano, oczekiwanie na odpowiedź... 404 Not Found
2013-06-12 22:29:01 BŁĄD 404: Not Found.

!!! Couldn't download 'adobe-flash-'. Aborting.
 * Fetch failed for 'www-plugins/adobe-flash-', Log file:
 *  '/var/log/portage/www-plugins:adobe-flash-'
Comment 5 Jeroen Roovers (RETIRED) gentoo-dev 2013-06-12 21:11:39 UTC
(In reply to Piotr Szymaniak from comment #4)
> I know this isn't the best bug for it, but this seems important for stable
> packages (x86 here):

Then file a new bug report. Thanks.
Comment 6 GLSAMaker/CVETool Bot gentoo-dev 2013-08-27 03:53:39 UTC
CVE-2013-3343 (
  Adobe Flash Player before and 11.x before 11.7.700.224 on
  Windows, before and 11.x before 11.7.700.225 on Mac OS X, before and 11.x before on Linux, before on
  Android 2.x and 3.x, and before on Android 4.x; Adobe AIR before on Windows and Android and before on Mac OS X; and
  Adobe AIR SDK & Compiler before on Windows and before
  on Mac OS X allow attackers to execute arbitrary code or cause a denial of
  service (memory corruption) via unspecified vectors.
Comment 7 GLSAMaker/CVETool Bot gentoo-dev 2013-09-14 02:54:55 UTC
This issue was resolved and addressed in
 GLSA 201309-06 at
by GLSA coordinator Sean Amoss (ackle).