Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 473038 (CVE-2013-3343) - <www-plugins/adobe-flash-{10.3.183.90,11.2.202.291} - Unspecified vulnerability (CVE-2013-3343)
Summary: <www-plugins/adobe-flash-{10.3.183.90,11.2.202.291} - Unspecified vulnerabili...
Status: RESOLVED FIXED
Alias: CVE-2013-3343
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: http://www.adobe.com/support/security...
Whiteboard: B2 [glsa]
Keywords: STABLEREQ
Depends on:
Blocks:
 
Reported: 2013-06-11 21:56 UTC by Max Steel
Modified: 2013-09-14 02:54 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Max Steel 2013-06-11 21:56:47 UTC
adobe-flash 11.2.202.291 released by upstream.

Reproducible: Always
Comment 1 Jeroen Roovers (RETIRED) gentoo-dev 2013-06-12 00:32:03 UTC
Arch teams, please test and mark stable:
=www-plugins/adobe-flash-11.2.202.291
Stable KEYWORDS : amd64 x86
Comment 2 Agostino Sarubbo gentoo-dev 2013-06-12 10:39:07 UTC
amd64 stable
Comment 3 Agostino Sarubbo gentoo-dev 2013-06-12 10:39:17 UTC
x86 stable
Comment 4 Piotr Szymaniak 2013-06-12 20:33:40 UTC
I know this isn't the best bug for it, but this seems important for stable packages (x86 here):

>>> Downloading 'http://fpdownload.macromedia.com/get/flashplayer/pdc/11.2.202.291/install_flash_player_11.2.202.291_linux.i386.tar.gz'
--2013-06-12 22:29:01--  http://fpdownload.macromedia.com/get/flashplayer/pdc/11.2.202.291/install_flash_player_11.2.202.291_linux.i386.tar.gz
Translacja fpdownload.macromedia.com... 84.53.166.70
Łączenie się z fpdownload.macromedia.com|84.53.166.70|:80... połączono.
Żądanie HTTP wysłano, oczekiwanie na odpowiedź... 404 Not Found
2013-06-12 22:29:01 BŁĄD 404: Not Found.

!!! Couldn't download 'adobe-flash-11.2.202.291.i386.tar.gz'. Aborting.
 * Fetch failed for 'www-plugins/adobe-flash-11.2.202.291-r1', Log file:
 *  '/var/log/portage/www-plugins:adobe-flash-11.2.202.291-r1:20130612-202901.log'
Comment 5 Jeroen Roovers (RETIRED) gentoo-dev 2013-06-12 21:11:39 UTC
(In reply to Piotr Szymaniak from comment #4)
> I know this isn't the best bug for it, but this seems important for stable
> packages (x86 here):

Then file a new bug report. Thanks.
Comment 6 GLSAMaker/CVETool Bot gentoo-dev 2013-08-27 03:53:39 UTC
CVE-2013-3343 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-3343):
  Adobe Flash Player before 10.3.183.90 and 11.x before 11.7.700.224 on
  Windows, before 10.3.183.90 and 11.x before 11.7.700.225 on Mac OS X, before
  10.3.183.90 and 11.x before 11.2.202.291 on Linux, before 11.1.111.59 on
  Android 2.x and 3.x, and before 11.1.115.63 on Android 4.x; Adobe AIR before
  3.7.0.2090 on Windows and Android and before 3.7.0.2100 on Mac OS X; and
  Adobe AIR SDK & Compiler before 3.7.0.2090 on Windows and before 3.7.0.2100
  on Mac OS X allow attackers to execute arbitrary code or cause a denial of
  service (memory corruption) via unspecified vectors.
Comment 7 GLSAMaker/CVETool Bot gentoo-dev 2013-09-14 02:54:55 UTC
This issue was resolved and addressed in
 GLSA 201309-06 at http://security.gentoo.org/glsa/glsa-201309-06.xml
by GLSA coordinator Sean Amoss (ackle).