Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 343089 (CVE-2010-3654) - <www-plugins/adobe-flash-10.1.102.64: Many Vulnerabilities, including Remote Code Execution (CVE-2010-{3636,3637,3638,3639,3640,3641,3642,3643,3644,3645,3646,3647,3648,3649,3650,3652,3654,3976})
Summary: <www-plugins/adobe-flash-10.1.102.64: Many Vulnerabilities, including Remote ...
Status: RESOLVED FIXED
Alias: CVE-2010-3654
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High major (vote)
Assignee: Gentoo Security
URL: http://www.adobe.com/support/security...
Whiteboard: A2 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2010-10-28 15:05 UTC by Tim Sammut (RETIRED)
Modified: 2011-06-13 17:45 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Tim Sammut (RETIRED) gentoo-dev 2010-10-28 15:05:17 UTC
From $URL: 

A critical  vulnerability exists in Adobe Flash Player 10.1.85.3 and earlier versions for Windows, Macintosh, Linux and Solaris operating systems; Adobe Flash Player 10.1.95.2 and earlier versions for Android; and the authplay.dll component that ships with Adobe Reader 9.4 and earlier 9.x versions for Windows, Macintosh and UNIX operating systems, and Adobe Acrobat 9.4 and earlier 9.x versions for Windows and Macintosh operating systems.

This vulnerability (CVE-2010-3654) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild against Adobe Reader and Acrobat 9.x. Adobe is not currently aware of attacks targeting Adobe Flash Player.

We are in the process of finalizing a fix for the issue and expect to provide an update for Flash Player 10.x for Windows, Macintosh, Linux, and Android by November 9, 2010. We expect to make available an update for Adobe Reader and Acrobat 9.4 and earlier 9.x versions during the week of November 15, 2010.
Comment 1 Tim Sammut (RETIRED) gentoo-dev 2010-11-05 03:03:28 UTC
Adobe has released flash player 10.1.102.64.

http://www.adobe.com/support/security/bulletins/apsb10-26.html

This update fixes the following issues, as listed at the above URL:

Critical  vulnerabilities have been identified in Adobe Flash Player 10.1.85.3 and earlier versions for Windows, Macintosh, Linux, and Solaris, and Adobe Flash Player 10.1.95.1 for Android. These vulnerabilities, including CVE-2010-3654 referenced in Security Advisory APSA10-05, could cause the application to crash and could potentially allow an attacker to take control of the affected system.

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-3654).

This update resolves an input validation issue vulnerability that could lead to a bypass of cross-domain policy file restrictions with certain server encodings (CVE-2010-3636).

This update resolves a memory corruption vulnerability that could lead to code execution (ActiveX only) (CVE-2010-3637).

This update resolves an information disclosure vulnerability (Macintosh platform, Safari browser only) (CVE-2010-3638).

This update resolves a Denial of Service vulnerability. Arbitrary code execution has not been demonstrated, but may be possible (CVE-2010-3639).

This update resolves multiple memory corruption vulnerabilities that could lead to code execution:

    * (CVE-2010-3640)
    * (CVE-2010-3641)
    * (CVE-2010-3642)
    * (CVE-2010-3643)
    * (CVE-2010-3644)
    * (CVE-2010-3645)
    * (CVE-2010-3646)
    * (CVE-2010-3647)
    * (CVE-2010-3648)
    * (CVE-2010-3649)
    * (CVE-2010-3650)
    * (CVE-2010-3652)

This update resolves a library-loading vulnerability that could lead to code execution (CVE-2010-3976).
Comment 2 Jim Ramsay (lack) (RETIRED) gentoo-dev 2010-11-05 17:35:24 UTC
Okay, www-plugins/adobe-flash-10.1.102.64 is in the tree.

As usual with this binary-only package, feel free to ask arch teams to stabilize as soon as you like.
Comment 3 Tim Sammut (RETIRED) gentoo-dev 2010-11-05 18:00:50 UTC
Thanks for doing this so quickly, Jim.

Arches, please test and mark stable:
=www-plugins/adobe-flash-10.1.102.64
Comment 4 Markos Chandras (RETIRED) gentoo-dev 2010-11-05 18:27:37 UTC
amd64 done
Comment 5 David Abbott (RETIRED) gentoo-dev 2010-11-05 19:25:27 UTC
Tested on x86 all good here.
Comment 6 Christian Faulhammer (RETIRED) gentoo-dev 2010-11-05 22:59:08 UTC
stable x86, thanks David
Comment 7 Tim Sammut (RETIRED) gentoo-dev 2010-11-06 01:27:16 UTC
Thanks, folks.

GLSA with bugs 332205, 322855 and 337204.
Comment 8 Tim Sammut (RETIRED) gentoo-dev 2011-01-21 17:21:02 UTC
This is GLSA 201101-09; thank you.
Comment 9 GLSAMaker/CVETool Bot gentoo-dev 2011-06-13 17:45:50 UTC
CVE-2010-3976 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3976):
  Untrusted search path vulnerability in Adobe Flash Player before 9.0.289.0
  and 10.x before 10.1.102.64 on Windows allows local users, and possibly
  remote attackers, to execute arbitrary code and conduct DLL hijacking
  attacks via a Trojan horse dwmapi.dll that is located in the same folder as
  a file that is processed by Flash Player.

CVE-2010-3654 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3654):
  Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows,
  Mac OS X, Linux, and Solaris and 10.1.95.1 on Android, and authplay.dll (aka
  AuthPlayLib.bundle or libauthplay.so.0.0.0) in Adobe Reader and Acrobat 9.x
  through 9.4, allows remote attackers to execute arbitrary code or cause a
  denial of service (memory corruption and application crash) via crafted SWF
  content, as exploited in the wild in October 2010.

CVE-2010-3652 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3652):
  Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x
  before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1
  on Android, allows attackers to execute arbitrary code or cause a denial of
  service (memory corruption) via unknown vectors, a different vulnerability
  than CVE-2010-3640, CVE-2010-3641, CVE-2010-3642, CVE-2010-3643,
  CVE-2010-3644, CVE-2010-3645, CVE-2010-3646, CVE-2010-3647, CVE-2010-3648,
  CVE-2010-3649, and CVE-2010-3650.

CVE-2010-3650 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3650):
  Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x
  before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1
  on Android, allows attackers to execute arbitrary code or cause a denial of
  service (memory corruption) via unknown vectors, a different vulnerability
  than CVE-2010-3640, CVE-2010-3641, CVE-2010-3642, CVE-2010-3643,
  CVE-2010-3644, CVE-2010-3645, CVE-2010-3646, CVE-2010-3647, CVE-2010-3648,
  CVE-2010-3649, and CVE-2010-3652.

CVE-2010-3649 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3649):
  Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x
  before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1
  on Android, allows attackers to execute arbitrary code or cause a denial of
  service (memory corruption) via unknown vectors, a different vulnerability
  than CVE-2010-3640, CVE-2010-3641, CVE-2010-3642, CVE-2010-3643,
  CVE-2010-3644, CVE-2010-3645, CVE-2010-3646, CVE-2010-3647, CVE-2010-3648,
  CVE-2010-3650, and CVE-2010-3652.

CVE-2010-3648 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3648):
  Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x
  before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1
  on Android, allows attackers to execute arbitrary code or cause a denial of
  service (memory corruption) via unknown vectors, a different vulnerability
  than CVE-2010-3640, CVE-2010-3641, CVE-2010-3642, CVE-2010-3643,
  CVE-2010-3644, CVE-2010-3645, CVE-2010-3646, CVE-2010-3647, CVE-2010-3649,
  CVE-2010-3650, and CVE-2010-3652.

CVE-2010-3647 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3647):
  Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x
  before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1
  on Android, allows attackers to execute arbitrary code or cause a denial of
  service (memory corruption) via unknown vectors, a different vulnerability
  than CVE-2010-3640, CVE-2010-3641, CVE-2010-3642, CVE-2010-3643,
  CVE-2010-3644, CVE-2010-3645, CVE-2010-3646, CVE-2010-3648, CVE-2010-3649,
  CVE-2010-3650, and CVE-2010-3652.

CVE-2010-3646 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3646):
  Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x
  before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1
  on Android, allows attackers to execute arbitrary code or cause a denial of
  service (memory corruption) via unknown vectors, a different vulnerability
  than CVE-2010-3640, CVE-2010-3641, CVE-2010-3642, CVE-2010-3643,
  CVE-2010-3644, CVE-2010-3645, CVE-2010-3647, CVE-2010-3648, CVE-2010-3649,
  CVE-2010-3650, and CVE-2010-3652.

CVE-2010-3645 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3645):
  Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x
  before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1
  on Android, allows attackers to execute arbitrary code or cause a denial of
  service (memory corruption) via unknown vectors, a different vulnerability
  than CVE-2010-3640, CVE-2010-3641, CVE-2010-3642, CVE-2010-3643,
  CVE-2010-3644, CVE-2010-3646, CVE-2010-3647, CVE-2010-3648, CVE-2010-3649,
  CVE-2010-3650, and CVE-2010-3652.

CVE-2010-3644 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3644):
  Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x
  before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1
  on Android, allows attackers to execute arbitrary code or cause a denial of
  service (memory corruption) via unknown vectors, a different vulnerability
  than CVE-2010-3640, CVE-2010-3641, CVE-2010-3642, CVE-2010-3643,
  CVE-2010-3645, CVE-2010-3646, CVE-2010-3647, CVE-2010-3648, CVE-2010-3649,
  CVE-2010-3650, and CVE-2010-3652.

CVE-2010-3643 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3643):
  Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x
  before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1
  on Android, allows attackers to execute arbitrary code or cause a denial of
  service (memory corruption) via unknown vectors, a different vulnerability
  than CVE-2010-3640, CVE-2010-3641, CVE-2010-3642, CVE-2010-3644,
  CVE-2010-3645, CVE-2010-3646, CVE-2010-3647, CVE-2010-3648, CVE-2010-3649,
  CVE-2010-3650, and CVE-2010-3652.

CVE-2010-3642 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3642):
  Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x
  before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1
  on Android, allows attackers to execute arbitrary code or cause a denial of
  service (memory corruption) via unknown vectors, a different vulnerability
  than CVE-2010-3640, CVE-2010-3641, CVE-2010-3643, CVE-2010-3644,
  CVE-2010-3645, CVE-2010-3646, CVE-2010-3647, CVE-2010-3648, CVE-2010-3649,
  CVE-2010-3650, and CVE-2010-3652.

CVE-2010-3641 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3641):
  Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x
  before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1
  on Android, allows attackers to execute arbitrary code or cause a denial of
  service (memory corruption) via unknown vectors, a different vulnerability
  than CVE-2010-3640, CVE-2010-3642, CVE-2010-3643, CVE-2010-3644,
  CVE-2010-3645, CVE-2010-3646, CVE-2010-3647, CVE-2010-3648, CVE-2010-3649,
  CVE-2010-3650, and CVE-2010-3652.

CVE-2010-3640 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3640):
  Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x
  before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1
  on Android, allows attackers to execute arbitrary code or cause a denial of
  service (memory corruption) via unknown vectors, a different vulnerability
  than CVE-2010-3641, CVE-2010-3642, CVE-2010-3643, CVE-2010-3644,
  CVE-2010-3645, CVE-2010-3646, CVE-2010-3647, CVE-2010-3648, CVE-2010-3649,
  CVE-2010-3650, and CVE-2010-3652.

CVE-2010-3639 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3639):
  Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x
  before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1
  on Android, allows attackers to cause a denial of service or possibly
  execute arbitrary code via unknown vectors.

CVE-2010-3638 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3638):
  Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x
  before 10.1.102.64 on Mac OS X, when Safari is used, allows attackers to
  obtain sensitive information via unknown vectors.

CVE-2010-3637 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3637):
  An unspecified ActiveX control in Adobe Flash Player before 9.0.289.0 and
  10.x before 10.1.102.64 (Flash10h.ocx) on Windows allows remote attackers to
  execute arbitrary code or cause a denial of service (memory corruption) via
  a crafted FLV video.

CVE-2010-3636 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3636):
  Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows,
  Mac OS X, Linux, and Solaris, and 10.1.95.1 on Android, does not properly
  handle unspecified encodings during the parsing of a cross-domain policy
  file, which allows remote web servers to bypass intended access restrictions
  via unknown vectors.