Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 582670 (CVE-2016-4117) - <www-plugins/adobe-flash-11.2.202.621 - many vulnerabilities (CVE-2016-{4117,4121,4160,4161,4162,4163})
Summary: <www-plugins/adobe-flash-11.2.202.621 - many vulnerabilities (CVE-2016-{4117,...
Status: RESOLVED FIXED
Alias: CVE-2016-4117
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo Security
URL: https://helpx.adobe.com/security/prod...
Whiteboard: A2 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2016-05-10 18:13 UTC by Jeroen Roovers (RETIRED)
Modified: 2016-06-18 23:51 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jeroen Roovers (RETIRED) gentoo-dev 2016-05-10 18:13:42 UTC
A critical vulnerability (CVE-2016-4117) exists in Adobe Flash Player 21.0.0.226 and earlier versions for Windows, Macintosh, Linux, and Chrome OS. Successful exploitation could cause a crash and potentially allow an attacker to take control of the affected system.

Adobe is aware of a report that an exploit for CVE-2016-4117 exists in the wild.  Adobe will address this vulnerability in our monthly security update, which will be available as early as May 12.
Comment 1 Jeroen Roovers (RETIRED) gentoo-dev 2016-05-12 10:08:18 UTC
The advisory has not been updated yet, but there is a new version out.

Arch teams, please test and mark stable:
=www-plugins/adobe-flash-11.2.202.621
Targeted stable KEYWORDS : amd64 x86
Comment 2 Jeroen Roovers (RETIRED) gentoo-dev 2016-05-12 18:21:50 UTC
https://helpx.adobe.com/security/products/flash-player/apsb16-15.html
Comment 3 Agostino Sarubbo gentoo-dev 2016-05-14 22:22:44 UTC
amd64 stable
Comment 4 Agostino Sarubbo gentoo-dev 2016-05-14 22:24:24 UTC
x86 stable.

Maintainer(s), please cleanup.
Security, please add it to the existing request, or file a new one.
Comment 5 Aaron Bauman (RETIRED) gentoo-dev 2016-06-17 23:27:06 UTC
Added to existing GLSA.
Comment 6 Aaron Bauman (RETIRED) gentoo-dev 2016-06-18 22:39:41 UTC
CVE references are for Microsoft IE and Edge implementations.  Removing.
Comment 7 GLSAMaker/CVETool Bot gentoo-dev 2016-06-18 23:07:36 UTC
CVE-2016-4117 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-4117):
  Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute
  arbitrary code via unspecified vectors, as exploited in the wild in May
  2016.
Comment 8 GLSAMaker/CVETool Bot gentoo-dev 2016-06-18 23:19:38 UTC
CVE-2016-4121 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-4121):
  Use-after-free vulnerability in Adobe Flash Player before 18.0.0.352 and
  19.x through 21.x before 21.0.0.242 on Windows and OS X and before
  11.2.202.621 on Linux allows attackers to execute arbitrary code via
  unspecified vectors, a different vulnerability than CVE-2016-1097,
  CVE-2016-1106, CVE-2016-1107, CVE-2016-1108, CVE-2016-1109, CVE-2016-1110,
  CVE-2016-4108, and CVE-2016-4110.
Comment 9 GLSAMaker/CVETool Bot gentoo-dev 2016-06-18 23:20:42 UTC
CVE-2016-4163 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-4163):
  Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242
  on Windows and OS X and before 11.2.202.621 on Linux allows attackers to
  execute arbitrary code or cause a denial of service (memory corruption) via
  unspecified vectors, a different vulnerability than CVE-2016-1096,
  CVE-2016-1098, CVE-2016-1099, CVE-2016-1100, CVE-2016-1102, CVE-2016-1104,
  CVE-2016-4109, CVE-2016-4111, CVE-2016-4112, CVE-2016-4113, CVE-2016-4114,
  CVE-2016-4115, CVE-2016-4120, CVE-2016-4160, CVE-2016-4161, and
  CVE-2016-4162.

CVE-2016-4162 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-4162):
  Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242
  on Windows and OS X and before 11.2.202.621 on Linux allows attackers to
  execute arbitrary code or cause a denial of service (memory corruption) via
  unspecified vectors, a different vulnerability than CVE-2016-1096,
  CVE-2016-1098, CVE-2016-1099, CVE-2016-1100, CVE-2016-1102, CVE-2016-1104,
  CVE-2016-4109, CVE-2016-4111, CVE-2016-4112, CVE-2016-4113, CVE-2016-4114,
  CVE-2016-4115, CVE-2016-4120, CVE-2016-4160, CVE-2016-4161, and
  CVE-2016-4163.

CVE-2016-4161 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-4161):
  Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242
  on Windows and OS X and before 11.2.202.621 on Linux allows attackers to
  execute arbitrary code or cause a denial of service (memory corruption) via
  unspecified vectors, a different vulnerability than CVE-2016-1096,
  CVE-2016-1098, CVE-2016-1099, CVE-2016-1100, CVE-2016-1102, CVE-2016-1104,
  CVE-2016-4109, CVE-2016-4111, CVE-2016-4112, CVE-2016-4113, CVE-2016-4114,
  CVE-2016-4115, CVE-2016-4120, CVE-2016-4160, CVE-2016-4162, and
  CVE-2016-4163.

CVE-2016-4160 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-4160):
  Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242
  on Windows and OS X and before 11.2.202.621 on Linux allows attackers to
  execute arbitrary code or cause a denial of service (memory corruption) via
  unspecified vectors, a different vulnerability than CVE-2016-1096,
  CVE-2016-1098, CVE-2016-1099, CVE-2016-1100, CVE-2016-1102, CVE-2016-1104,
  CVE-2016-4109, CVE-2016-4111, CVE-2016-4112, CVE-2016-4113, CVE-2016-4114,
  CVE-2016-4115, CVE-2016-4120, CVE-2016-4161, CVE-2016-4162, and
  CVE-2016-4163.
Comment 10 GLSAMaker/CVETool Bot gentoo-dev 2016-06-18 23:51:05 UTC
This issue was resolved and addressed in
 GLSA 201606-08 at https://security.gentoo.org/glsa/201606-08
by GLSA coordinator Kristian Fiskerstrand (K_F).