Bug 11943 - Security update request for flash-player-plugin, to 11.2.202.332
Summary: Security update request for flash-player-plugin, to 11.2.202.332
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 3
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: mga3-64-ok mga3-32-ok advisory
Keywords: Security, validated_update
Depends on:
Blocks:
 
Reported: 2013-12-10 19:45 CET by Anssi Hannula
Modified: 2013-12-12 23:26 CET (History)
3 users (show)

See Also:
Source RPM:
CVE: CVE-2013-5331 CVE-2013-5332
Status comment:


Attachments

Description Anssi Hannula 2013-12-10 19:45:36 CET
Advisory:
============
Adobe Flash Player 11.2.202.332 contains fixes to critical security
vulnerabilities found in earlier versions. These vulnerabilities could cause a
crash and potentially allow an attacker to take control of the affected system.

This update resolves a type confusion vulnerability that could lead to code execution (CVE-2013-5331).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2013-5332).

References:
http://helpx.adobe.com/security/products/flash-player/apsb13-28.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5331
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5332
============

Updated Flash Player 11.2.202.332 packages are in mga3 nonfree/updates_testing.

Source packages:
flash-player-plugin-11.2.202.332-1.mga3.nonfree

Binary packages:
flash-player-plugin-11.2.202.332-1.mga3.nonfree
flash-player-plugin-kde-11.2.202.332-1.mga3.nonfree
Comment 1 Bill Wilkinson 2013-12-11 03:32:38 CET
No PoC on securityfocus.

Updates install, able to change settings in flash player and play videos from YouTube.  All OK.

My 32 bit system is on an older AMD processor, and can't use the newer flash player plugins, so I'll leave that for someone else to test.

CC: (none) => wrw105
Whiteboard: (none) => mga2-64-ok

claire robinson 2013-12-11 12:22:52 CET

Severity: normal => critical

Bill Wilkinson 2013-12-11 12:31:41 CET

Whiteboard: mga2-64-ok => mga3-64-ok

Comment 2 claire robinson 2013-12-11 12:50:38 CET
Testing complete mga3 32

Whiteboard: mga3-64-ok => mga3-64-ok mga3-32-ok

Comment 3 claire robinson 2013-12-11 12:56:28 CET
Advisory uploaded. Validating.

Could sysadmin please push from 3 nonfree/updates_testing to updates

Thanks!

Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs

claire robinson 2013-12-11 12:56:37 CET

Whiteboard: mga3-64-ok mga3-32-ok => mga3-64-ok mga3-32-ok advisory

Comment 4 Thomas Backlund 2013-12-12 23:26:44 CET
Update pushed:
http://advisories.mageia.org/MGASA-2013-0370.html

Status: ASSIGNED => RESOLVED
CC: (none) => tmb
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.