Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 469870 (CVE-2013-2728) - <www-plugins/adobe-flash-11.2.202.285 : multiple vulnerabilities (CVE-2013-{2728,3324,3325,3326,3327,3328,3329,3330,3331,3332,3333,3334,3335})
Summary: <www-plugins/adobe-flash-11.2.202.285 : multiple vulnerabilities (CVE-2013-{2...
Status: RESOLVED FIXED
Alias: CVE-2013-2728
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: http://www.adobe.com/support/security...
Whiteboard: B2 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-05-14 19:46 UTC by Agostino Sarubbo
Modified: 2013-09-14 02:54 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2013-05-14 19:46:27 UTC
From ${URL} :

Adobe security bulletin APSB13-14 describes multiple security flaws that could cause Adobe Flash 
Player to crash and potentially allow an attacker to take control of the affected system:

These updates resolve memory corruption vulnerabilities that could lead to code execution 
(CVE-2013-2728, CVE-2013-3324, CVE-2013-3325, CVE-2013-3326, CVE-2013-3327, CVE-2013-3328, 
CVE-2013-3329, CVE-2013-3330, CVE-2013-3331, CVE-2013-3332, CVE-2013-3333, CVE-2013-3334, 
CVE-2013-3335).


External References:

http://www.adobe.com/support/security/bulletins/apsb13-14.html


@maintainer(s): after the bump, in case we need to stabilize the package, please say explicitly if it is ready for the stabilization or not.
Comment 1 Jeroen Roovers gentoo-dev 2013-05-14 23:46:00 UTC
Arch teams, please test and mark stable:
=www-plugins/adobe-flash-11.2.202.285
Stable KEYWORDS : amd64 x86
Comment 2 Sergey Popov gentoo-dev Security 2013-05-15 09:10:25 UTC
amd64 stable
Comment 3 Agostino Sarubbo gentoo-dev 2013-05-19 15:08:24 UTC
x86 stable
Comment 4 GLSAMaker/CVETool Bot gentoo-dev 2013-08-27 16:28:06 UTC
CVE-2013-3335 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-3335):
  Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on
  Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on
  Linux, before 11.1.111.54 on Android 2.x and 3.x, and before 11.1.115.58 on
  Android 4.x; Adobe AIR before 3.7.0.1860; and Adobe AIR SDK & Compiler
  before 3.7.0.1860 allow attackers to execute arbitrary code or cause a
  denial of service (memory corruption) via unspecified vectors, a different
  vulnerability than CVE-2013-2728, CVE-2013-3324, CVE-2013-3325,
  CVE-2013-3326, CVE-2013-3327, CVE-2013-3328, CVE-2013-3329, CVE-2013-3330,
  CVE-2013-3331, CVE-2013-3332, CVE-2013-3333, and CVE-2013-3334.

CVE-2013-3334 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-3334):
  Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on
  Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on
  Linux, before 11.1.111.54 on Android 2.x and 3.x, and before 11.1.115.58 on
  Android 4.x; Adobe AIR before 3.7.0.1860; and Adobe AIR SDK & Compiler
  before 3.7.0.1860 allow attackers to execute arbitrary code or cause a
  denial of service (memory corruption) via unspecified vectors, a different
  vulnerability than CVE-2013-2728, CVE-2013-3324, CVE-2013-3325,
  CVE-2013-3326, CVE-2013-3327, CVE-2013-3328, CVE-2013-3329, CVE-2013-3330,
  CVE-2013-3331, CVE-2013-3332, CVE-2013-3333, and CVE-2013-3335.

CVE-2013-3333 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-3333):
  Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on
  Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on
  Linux, before 11.1.111.54 on Android 2.x and 3.x, and before 11.1.115.58 on
  Android 4.x; Adobe AIR before 3.7.0.1860; and Adobe AIR SDK & Compiler
  before 3.7.0.1860 allow attackers to execute arbitrary code or cause a
  denial of service (memory corruption) via unspecified vectors, a different
  vulnerability than CVE-2013-2728, CVE-2013-3324, CVE-2013-3325,
  CVE-2013-3326, CVE-2013-3327, CVE-2013-3328, CVE-2013-3329, CVE-2013-3330,
  CVE-2013-3331, CVE-2013-3332, CVE-2013-3334, and CVE-2013-3335.

CVE-2013-3332 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-3332):
  Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on
  Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on
  Linux, before 11.1.111.54 on Android 2.x and 3.x, and before 11.1.115.58 on
  Android 4.x; Adobe AIR before 3.7.0.1860; and Adobe AIR SDK & Compiler
  before 3.7.0.1860 allow attackers to execute arbitrary code or cause a
  denial of service (memory corruption) via unspecified vectors, a different
  vulnerability than CVE-2013-2728, CVE-2013-3324, CVE-2013-3325,
  CVE-2013-3326, CVE-2013-3327, CVE-2013-3328, CVE-2013-3329, CVE-2013-3330,
  CVE-2013-3331, CVE-2013-3333, CVE-2013-3334, and CVE-2013-3335.

CVE-2013-3331 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-3331):
  Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on
  Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on
  Linux, before 11.1.111.54 on Android 2.x and 3.x, and before 11.1.115.58 on
  Android 4.x; Adobe AIR before 3.7.0.1860; and Adobe AIR SDK & Compiler
  before 3.7.0.1860 allow attackers to execute arbitrary code or cause a
  denial of service (memory corruption) via unspecified vectors, a different
  vulnerability than CVE-2013-2728, CVE-2013-3324, CVE-2013-3325,
  CVE-2013-3326, CVE-2013-3327, CVE-2013-3328, CVE-2013-3329, CVE-2013-3330,
  CVE-2013-3332, CVE-2013-3333, CVE-2013-3334, and CVE-2013-3335.

CVE-2013-3330 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-3330):
  Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on
  Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on
  Linux, before 11.1.111.54 on Android 2.x and 3.x, and before 11.1.115.58 on
  Android 4.x; Adobe AIR before 3.7.0.1860; and Adobe AIR SDK & Compiler
  before 3.7.0.1860 allow attackers to execute arbitrary code or cause a
  denial of service (memory corruption) via unspecified vectors, a different
  vulnerability than CVE-2013-2728, CVE-2013-3324, CVE-2013-3325,
  CVE-2013-3326, CVE-2013-3327, CVE-2013-3328, CVE-2013-3329, CVE-2013-3331,
  CVE-2013-3332, CVE-2013-3333, CVE-2013-3334, and CVE-2013-3335.

CVE-2013-3329 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-3329):
  Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on
  Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on
  Linux, before 11.1.111.54 on Android 2.x and 3.x, and before 11.1.115.58 on
  Android 4.x; Adobe AIR before 3.7.0.1860; and Adobe AIR SDK & Compiler
  before 3.7.0.1860 allow attackers to execute arbitrary code or cause a
  denial of service (memory corruption) via unspecified vectors, a different
  vulnerability than CVE-2013-2728, CVE-2013-3324, CVE-2013-3325,
  CVE-2013-3326, CVE-2013-3327, CVE-2013-3328, CVE-2013-3330, CVE-2013-3331,
  CVE-2013-3332, CVE-2013-3333, CVE-2013-3334, and CVE-2013-3335.

CVE-2013-3328 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-3328):
  Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on
  Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on
  Linux, before 11.1.111.54 on Android 2.x and 3.x, and before 11.1.115.58 on
  Android 4.x; Adobe AIR before 3.7.0.1860; and Adobe AIR SDK & Compiler
  before 3.7.0.1860 allow attackers to execute arbitrary code or cause a
  denial of service (memory corruption) via unspecified vectors, a different
  vulnerability than CVE-2013-2728, CVE-2013-3324, CVE-2013-3325,
  CVE-2013-3326, CVE-2013-3327, CVE-2013-3329, CVE-2013-3330, CVE-2013-3331,
  CVE-2013-3332, CVE-2013-3333, CVE-2013-3334, and CVE-2013-3335.

CVE-2013-3327 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-3327):
  Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on
  Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on
  Linux, before 11.1.111.54 on Android 2.x and 3.x, and before 11.1.115.58 on
  Android 4.x; Adobe AIR before 3.7.0.1860; and Adobe AIR SDK & Compiler
  before 3.7.0.1860 allow attackers to execute arbitrary code or cause a
  denial of service (memory corruption) via unspecified vectors, a different
  vulnerability than CVE-2013-2728, CVE-2013-3324, CVE-2013-3325,
  CVE-2013-3326, CVE-2013-3328, CVE-2013-3329, CVE-2013-3330, CVE-2013-3331,
  CVE-2013-3332, CVE-2013-3333, CVE-2013-3334, and CVE-2013-3335.

CVE-2013-3326 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-3326):
  Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on
  Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on
  Linux, before 11.1.111.54 on Android 2.x and 3.x, and before 11.1.115.58 on
  Android 4.x; Adobe AIR before 3.7.0.1860; and Adobe AIR SDK & Compiler
  before 3.7.0.1860 allow attackers to execute arbitrary code or cause a
  denial of service (memory corruption) via unspecified vectors, a different
  vulnerability than CVE-2013-2728, CVE-2013-3324, CVE-2013-3325,
  CVE-2013-3327, CVE-2013-3328, CVE-2013-3329, CVE-2013-3330, CVE-2013-3331,
  CVE-2013-3332, CVE-2013-3333, CVE-2013-3334, and CVE-2013-3335.

CVE-2013-3325 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-3325):
  Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on
  Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on
  Linux, before 11.1.111.54 on Android 2.x and 3.x, and before 11.1.115.58 on
  Android 4.x; Adobe AIR before 3.7.0.1860; and Adobe AIR SDK & Compiler
  before 3.7.0.1860 allow attackers to execute arbitrary code or cause a
  denial of service (memory corruption) via unspecified vectors, a different
  vulnerability than CVE-2013-2728, CVE-2013-3324, CVE-2013-3326,
  CVE-2013-3327, CVE-2013-3328, CVE-2013-3329, CVE-2013-3330, CVE-2013-3331,
  CVE-2013-3332, CVE-2013-3333, CVE-2013-3334, and CVE-2013-3335.

CVE-2013-3324 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-3324):
  Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on
  Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on
  Linux, before 11.1.111.54 on Android 2.x and 3.x, and before 11.1.115.58 on
  Android 4.x; Adobe AIR before 3.7.0.1860; and Adobe AIR SDK & Compiler
  before 3.7.0.1860 allow attackers to execute arbitrary code or cause a
  denial of service (memory corruption) via unspecified vectors, a different
  vulnerability than CVE-2013-2728, CVE-2013-3325, CVE-2013-3326,
  CVE-2013-3327, CVE-2013-3328, CVE-2013-3329, CVE-2013-3330, CVE-2013-3331,
  CVE-2013-3332, CVE-2013-3333, CVE-2013-3334, and CVE-2013-3335.

CVE-2013-2728 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2728):
  Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on
  Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on
  Linux, before 11.1.111.54 on Android 2.x and 3.x, and before 11.1.115.58 on
  Android 4.x; Adobe AIR before 3.7.0.1860; and Adobe AIR SDK & Compiler
  before 3.7.0.1860 allow attackers to execute arbitrary code or cause a
  denial of service (memory corruption) via unspecified vectors, a different
  vulnerability than CVE-2013-3324, CVE-2013-3325, CVE-2013-3326,
  CVE-2013-3327, CVE-2013-3328, CVE-2013-3329, CVE-2013-3330, CVE-2013-3331,
  CVE-2013-3332, CVE-2013-3333, CVE-2013-3334, and CVE-2013-3335.
Comment 5 GLSAMaker/CVETool Bot gentoo-dev 2013-09-14 02:54:53 UTC
This issue was resolved and addressed in
 GLSA 201309-06 at http://security.gentoo.org/glsa/glsa-201309-06.xml
by GLSA coordinator Sean Amoss (ackle).