Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 442084 (CVE-2012-5274) - <www-plugins/adobe-flash-{10.3.183.43,11.2.202.251}: multiple vulnerabilities (CVE-2012-{5274,5275,5276,5277,5278,5279,5280})
Summary: <www-plugins/adobe-flash-{10.3.183.43,11.2.202.251}: multiple vulnerabilities...
Status: RESOLVED FIXED
Alias: CVE-2012-5274
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://www.adobe.com/support/securit...
Whiteboard: B2 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2012-11-06 19:20 UTC by Agostino Sarubbo
Modified: 2013-09-14 02:54 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2012-11-06 19:20:27 UTC
From https://www.adobe.com/support/security/bulletins/apsb12-24.html :

Adobe has released security updates for Adobe Flash Player 11.4.402.287 and earlier versions for 
Windows and Macintosh, Adobe Flash Player 11.2.202.243 and earlier versions for Linux, Adobe Flash 
Player 11.1.115.20 and earlier versions for Android 4.x, and Adobe Flash Player 11.1.111.19 and 
earlier versions for Android 3.x and 2.x. These updates address vulnerabilities that could cause a 
crash and potentially allow an attacker to take control of the affected system.

Adobe recommends users update their product installations to the latest versions:

Users of Adobe Flash Player 11.4.402.287 and earlier versions for Windows and Macintosh should 
update to Adobe Flash Player 11.5.502.110.
Users of Adobe Flash Player 11.2.202.243 and earlier versions for Linux should update to Adobe 
Flash Player 11.2.202.251.
Comment 1 Jeroen Roovers gentoo-dev 2012-11-06 21:38:54 UTC
Arch teams, please test and mark stable:
=www-plugins/adobe-flash-11.2.202.251
Stable KEYWORDS : amd64 x86
Comment 2 Agostino Sarubbo gentoo-dev 2012-11-07 10:37:17 UTC
amd64 stable
Comment 3 Agostino Sarubbo gentoo-dev 2012-11-07 10:39:54 UTC
x86 stable
Comment 4 GLSAMaker/CVETool Bot gentoo-dev 2012-11-07 23:19:33 UTC
CVE-2012-5280 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5280):
  Buffer overflow in Adobe Flash Player before 10.3.183.43 and 11.x before
  11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before
  11.2.202.251 on Linux, before 11.1.111.24 on Android 2.x and 3.x, and before
  11.1.115.27 on Android 4.x; Adobe AIR before 3.5.0.600; and Adobe AIR SDK
  before 3.5.0.600 allows attackers to execute arbitrary code via unspecified
  vectors, a different vulnerability than CVE-2012-5274, CVE-2012-5275,
  CVE-2012-5276, and CVE-2012-5277.

CVE-2012-5279 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5279):
  Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on
  Windows and Mac OS X, before 10.3.183.43 and 11.x before 11.2.202.251 on
  Linux, before 11.1.111.24 on Android 2.x and 3.x, and before 11.1.115.27 on
  Android 4.x; Adobe AIR before 3.5.0.600; and Adobe AIR SDK before 3.5.0.600
  allow attackers to execute arbitrary code or cause a denial of service
  (memory corruption) via unspecified vectors.

CVE-2012-5278 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5278):
  Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on
  Windows and Mac OS X, before 10.3.183.43 and 11.x before 11.2.202.251 on
  Linux, before 11.1.111.24 on Android 2.x and 3.x, and before 11.1.115.27 on
  Android 4.x; Adobe AIR before 3.5.0.600; and Adobe AIR SDK before 3.5.0.600
  allow attackers to bypass intended access restrictions and execute arbitrary
  code via unspecified vectors.

CVE-2012-5277 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5277):
  Buffer overflow in Adobe Flash Player before 10.3.183.43 and 11.x before
  11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before
  11.2.202.251 on Linux, before 11.1.111.24 on Android 2.x and 3.x, and before
  11.1.115.27 on Android 4.x; Adobe AIR before 3.5.0.600; and Adobe AIR SDK
  before 3.5.0.600 allows attackers to execute arbitrary code via unspecified
  vectors, a different vulnerability than CVE-2012-5274, CVE-2012-5275,
  CVE-2012-5276, and CVE-2012-5280.

CVE-2012-5276 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5276):
  Buffer overflow in Adobe Flash Player before 10.3.183.43 and 11.x before
  11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before
  11.2.202.251 on Linux, before 11.1.111.24 on Android 2.x and 3.x, and before
  11.1.115.27 on Android 4.x; Adobe AIR before 3.5.0.600; and Adobe AIR SDK
  before 3.5.0.600 allows attackers to execute arbitrary code via unspecified
  vectors, a different vulnerability than CVE-2012-5274, CVE-2012-5275,
  CVE-2012-5277, and CVE-2012-5280.

CVE-2012-5275 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5275):
  Buffer overflow in Adobe Flash Player before 10.3.183.43 and 11.x before
  11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before
  11.2.202.251 on Linux, before 11.1.111.24 on Android 2.x and 3.x, and before
  11.1.115.27 on Android 4.x; Adobe AIR before 3.5.0.600; and Adobe AIR SDK
  before 3.5.0.600 allows attackers to execute arbitrary code via unspecified
  vectors, a different vulnerability than CVE-2012-5274, CVE-2012-5276,
  CVE-2012-5277, and CVE-2012-5280.

CVE-2012-5274 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5274):
  Buffer overflow in Adobe Flash Player before 10.3.183.43 and 11.x before
  11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before
  11.2.202.251 on Linux, before 11.1.111.24 on Android 2.x and 3.x, and before
  11.1.115.27 on Android 4.x; Adobe AIR before 3.5.0.600; and Adobe AIR SDK
  before 3.5.0.600 allows attackers to execute arbitrary code via unspecified
  vectors, a different vulnerability than CVE-2012-5275, CVE-2012-5276,
  CVE-2012-5277, and CVE-2012-5280.
Comment 5 Sean Amoss gentoo-dev Security 2012-11-07 23:27:55 UTC
Added to existing GLSA draft.
Comment 6 GLSAMaker/CVETool Bot gentoo-dev 2013-09-14 02:54:38 UTC
This issue was resolved and addressed in
 GLSA 201309-06 at http://security.gentoo.org/glsa/glsa-201309-06.xml
by GLSA coordinator Sean Amoss (ackle).