| Summary: | flash-player-plugin security update 30.0.0.134 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | Nicolas Salguero <nicolas.salguero> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | critical | ||
| Priority: | Normal | CC: | davidwhodgins, herman.viaene, marja11, mhrambo3501, smelror, sysadmin-bugs |
| Version: | 6 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA6-32-OK MGA6-64-OK | ||
| Source RPM: | flash-player-plugin | CVE: | CVE-2018-5007, CVE-2018-5008 |
| Status comment: | |||
|
Description
Nicolas Salguero
2018-07-11 14:20:48 CEST
Nicolas Salguero
2018-07-11 14:21:50 CEST
CVE:
(none) =>
CVE-2018-5007, CVE-2018-5008 Assigning to the registered maintainer. CC:
(none) =>
marja11, mrambo, smelror Updated files uploaded for Cauldron and Mageia 6. Advisory: ======================== Updated flash-player-plugin package fixes security vulnerabilities: * A type confusion vulnerability that could lead to arbitrary code execution (CVE-2018-5007). * An out of bounds read that could lead to information disclosure (CVE-2018-5008). References: https://helpx.adobe.com/security/products/flash-player/apsb18-24.html https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5007 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5008 ======================== Updated packages in nonfree/updates_testing: ======================== flash-player-plugin-30.0.0.134-1.mga6 from flash-player-plugin-30.0.0.134-1.mga6.src.rpm Version:
Cauldron =>
6 Hi, It seems you submitted to core/updates_testing in place of nonfree/updates_testing for Mga6. Best regards, Nico. This should be removed from Mageia 6 core updates testing and resubmitted to nonfree updates testing. Keywords:
(none) =>
feedback MGA6-32 MATE on IBM Thinkpad R50e No installation issues All sites I regularly use don't use flash anymore. But youtube and Mr. Bean provided me with a flash movie. Works OK. Whiteboard:
(none) =>
MGA6-32-OK Tested at http://www.dhs.state.il.us/accessibility/tests/flash/video.html on m6 x86_64. Advisory committed to svn. Validating the update. Whiteboard:
MGA6-32-OK =>
MGA6-32-OK MGA6-64-OK An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2018-0315.html Resolution:
(none) =>
FIXED |