Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 602546 (APSB16-39, CVE-2016-7867, CVE-2016-7868, CVE-2016-7869, CVE-2016-7870, CVE-2016-7871, CVE-2016-7872, CVE-2016-7873, CVE-2016-7874, CVE-2016-7875, CVE-2016-7876, CVE-2016-7877, CVE-2016-7878, CVE-2016-7879, CVE-2016-7880, CVE-2016-7881, CVE-2016-7890, CVE-2016-7892) - <www-plugins/adobe-flash-24.0.0.186: Multiple vulnerabilities (APSB16-39)
Summary: <www-plugins/adobe-flash-24.0.0.186: Multiple vulnerabilities (APSB16-39)
Status: RESOLVED FIXED
Alias: APSB16-39, CVE-2016-7867, CVE-2016-7868, CVE-2016-7869, CVE-2016-7870, CVE-2016-7871, CVE-2016-7872, CVE-2016-7873, CVE-2016-7874, CVE-2016-7875, CVE-2016-7876, CVE-2016-7877, CVE-2016-7878, CVE-2016-7879, CVE-2016-7880, CVE-2016-7881, CVE-2016-7890, CVE-2016-7892
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal major
Assignee: Gentoo Security
URL: https://helpx.adobe.com/security/prod...
Whiteboard: A2 [glsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2016-12-13 14:35 UTC by Thomas Deutschmann (RETIRED)
Modified: 2017-01-10 13:56 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Deutschmann (RETIRED) gentoo-dev 2016-12-13 14:35:57 UTC
Adobe Security Bulletin not yet available however release notes (https://helpx.adobe.com/flash-player/release-note/fp_24_air_24_release_notes.html) were updated:

> December 13, 2016
> 
> In today's scheduled release, we've updated Flash Player and AIR
> with important bug fixes, security updates, and new features.


Upstream has already released v24.0.0.186. No information regarding v11.x yet.


Bulletin-URL (not yet published): https://helpx.adobe.com/security/products/flash-player/apsb16-39.html
Comment 1 Thomas Deutschmann (RETIRED) gentoo-dev 2016-12-13 16:08:54 UTC
Bulletin is now available.

Looks like Adobe wants that v11.2.202.644 users (which are affected) should upgrade to v24.0.0.186 as well.
Comment 3 Thomas Deutschmann (RETIRED) gentoo-dev 2017-01-08 17:46:49 UTC
(In reply to Matt from comment #2)
> There even seems to be 24.0.0.189 out according to:

This is Adobe's beta release for the next upcoming version. It was only re-based against 24.0.0.186.



Fixed version in tree since 2016-12-13 via https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=af80dd617dbd4bbc682fcf43ac7df38f0eeaeae1 and stable since 2016-12-15 via https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=04faccfbbc130e63720bb31dbd8524f0f63324b9

New GLSA request filed.
Comment 4 GLSAMaker/CVETool Bot gentoo-dev 2017-01-10 13:56:06 UTC
This issue was resolved and addressed in
 GLSA 201701-17 at https://security.gentoo.org/glsa/201701-17
by GLSA coordinator Thomas Deutschmann (whissi).