Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 519790 (CVE-2014-0540)

Summary: <www-plugins/adobe-flash-11.2.202.400 - multiple code execution or security bypass flaws (APSB14-18) (CVE-{2014-0538,0540,0541,0542,0543,0544,0545})
Product: Gentoo Security Reporter: Agostino Sarubbo <ago>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: major CC: desktop-misc, jer
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://helpx.adobe.com/security/products/flash-player/apsb14-18.html
Whiteboard: A2 [glsa]
Package list:
Runtime testing required: ---

Description Agostino Sarubbo gentoo-dev 2014-08-13 07:54:38 UTC
From ${URL} :

Adobe has released Flash Player 11.2.202.400 for Linux to correct the following flaws:

* These updates resolve memory leakage vulnerabilities that could be used to bypass memory address 
randomization (CVE-2014-0540, CVE-2014-0542, CVE-2014-0543, CVE-2014-0544, CVE-2014-0545).

* These updates resolve a security bypass vulnerability (CVE-2014-0541).

* These updates resolve a use-after-free vulnerability that could lead to code execution 
(CVE-2014-0538).


External References:

http://helpx.adobe.com/security/products/flash-player/apsb14-18.html


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Jeroen Roovers (RETIRED) gentoo-dev 2014-08-13 11:24:38 UTC
Arch teams, please test and mark stable:
=www-plugins/adobe-flash-11.2.202.400
Targeted stable KEYWORDS : amd64 x86
Comment 2 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2014-08-13 13:31:21 UTC
amd64/x86 stable
Comment 3 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2014-08-13 16:10:18 UTC
Cleanup done by Jer.
Comment 4 GLSAMaker/CVETool Bot gentoo-dev 2014-08-13 16:18:58 UTC
CVE-2014-0538 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0538):
  Use-after-free vulnerability in Adobe Flash Player before 13.0.0.241 and
  14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux,
  Adobe AIR before 14.0.0.178 on Windows and OS X and before 14.0.0.179 on
  Android, Adobe AIR SDK before 14.0.0.178, and Adobe AIR SDK & Compiler
  before 14.0.0.178 allows attackers to execute arbitrary code via unspecified
  vectors.
Comment 5 GLSAMaker/CVETool Bot gentoo-dev 2014-08-13 16:20:09 UTC
CVE-2014-0545 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0545):
  Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows
  and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on
  Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before
  14.0.0.178, and Adobe AIR SDK & Compiler before 14.0.0.178 do not properly
  restrict discovery of memory addresses, which allows attackers to bypass the
  ASLR protection mechanism via unspecified vectors, a different vulnerability
  than CVE-2014-0540, CVE-2014-0542, CVE-2014-0543, and CVE-2014-0544.

CVE-2014-0544 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0544):
  Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows
  and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on
  Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before
  14.0.0.178, and Adobe AIR SDK & Compiler before 14.0.0.178 do not properly
  restrict discovery of memory addresses, which allows attackers to bypass the
  ASLR protection mechanism via unspecified vectors, a different vulnerability
  than CVE-2014-0540, CVE-2014-0542, CVE-2014-0543, and CVE-2014-0545.

CVE-2014-0543 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0543):
  Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows
  and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on
  Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before
  14.0.0.178, and Adobe AIR SDK & Compiler before 14.0.0.178 do not properly
  restrict discovery of memory addresses, which allows attackers to bypass the
  ASLR protection mechanism via unspecified vectors, a different vulnerability
  than CVE-2014-0540, CVE-2014-0542, CVE-2014-0544, and CVE-2014-0545.

CVE-2014-0542 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0542):
  Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows
  and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on
  Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before
  14.0.0.178, and Adobe AIR SDK & Compiler before 14.0.0.178 do not properly
  restrict discovery of memory addresses, which allows attackers to bypass the
  ASLR protection mechanism via unspecified vectors, a different vulnerability
  than CVE-2014-0540, CVE-2014-0543, CVE-2014-0544, and CVE-2014-0545.

CVE-2014-0541 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0541):
  Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows
  and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on
  Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before
  14.0.0.178, and Adobe AIR SDK & Compiler before 14.0.0.178 allow attackers
  to bypass intended access restrictions via unspecified vectors.

CVE-2014-0540 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0540):
  Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows
  and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on
  Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before
  14.0.0.178, and Adobe AIR SDK & Compiler before 14.0.0.178 do not properly
  restrict discovery of memory addresses, which allows attackers to bypass the
  ASLR protection mechanism via unspecified vectors, a different vulnerability
  than CVE-2014-0542, CVE-2014-0543, CVE-2014-0544, and CVE-2014-0545.
Comment 6 GLSAMaker/CVETool Bot gentoo-dev 2014-08-14 13:47:28 UTC
This issue was resolved and addressed in
 GLSA 201408-05 at http://security.gentoo.org/glsa/glsa-201408-05.xml
by GLSA coordinator Mikle Kolyada (Zlogene).