Bug 12997 - Security update request for flash-player-plugin, to 11.2.202.346
Summary: Security update request for flash-player-plugin, to 11.2.202.346
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 4
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA3TOO has_procedure advisory mga3-3...
Keywords: Security, validated_update
Depends on:
Blocks:
 
Reported: 2014-03-11 23:32 CET by Anssi Hannula
Modified: 2014-03-12 17:33 CET (History)
4 users (show)

See Also:
Source RPM: flash-player-plugin
CVE: CVE-2014-0503, CVE-2014-0504
Status comment:


Attachments

Description Anssi Hannula 2014-03-11 23:32:54 CET
Suggested advisory:
============
Adobe Flash Player 11.2.202.346 contains fixes to important vulnerabilities found in earlier versions that could allow a remote attacker to bypass security restrictions or to access sensitive information.

This update resolves a vulnerability that could be used to bypass the same origin policy (CVE-2014-0503).

This update resolves a vulnerability that could be used to read the contents of the clipboard (CVE-2014-0504).

References:
http://helpx.adobe.com/security/products/flash-player/apsb14-08.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0503
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0504
============

Uploaded to mga3+mga4 nonfree/updates_testing:

Source packages:
flash-player-plugin-11.2.202.346-1.mga3.nonfree
flash-player-plugin-11.2.202.346-1.mga4.nonfree

Binary packages:
flash-player-plugin-11.2.202.346-1.mga3.nonfree
flash-player-plugin-kde-11.2.202.346-1.mga3.nonfree
flash-player-plugin-11.2.202.346-1.mga4.nonfree
flash-player-plugin-kde-11.2.202.346-1.mga4.nonfree

P.S. This is the first time I remember Adobe issuing a Flash update classified as only Important instead of Critical... (this is because the security issues do not allow a remote takeover as usual).
Comment 1 Bill Wilkinson 2014-03-12 12:36:57 CET
No PoC. Tested general use mga4-64.

Played Youtube videos, and a flash game. changed settings in KDE panel, all OK.

Will test mga3-64 momentarily.  Someone else will have to pick up mga3 and 4 32. I have an older AMD processor and newer flash updates don't work on my 32-bit system.

CC: (none) => wrw105
Whiteboard: (none) => MGA3TOO mga4-64-ok

Comment 2 claire robinson 2014-03-12 12:47:40 CET
I'll do both 32bit now.
Comment 3 Bill Wilkinson 2014-03-12 13:00:35 CET
Tested mga3-64 as above, all OK.

Whiteboard: MGA3TOO mga4-64-ok => MGA3TOO mga4-64-ok mga3-64-ok

Comment 4 claire robinson 2014-03-12 13:10:13 CET
Testing complete mga3 32 & mga4 32
Comment 5 claire robinson 2014-03-12 13:17:14 CET
Advisory uploaded. Validating.

Could sysadmin please push to 3 & 4 nonfree updates

Thanks

Keywords: (none) => validated_update
Whiteboard: MGA3TOO mga4-64-ok mga3-64-ok => MGA3TOO has_procedure advisory mga3-32-ok mga4-32-ok mga4-64-ok mga3-64-ok
CC: (none) => sysadmin-bugs

Stuart Morgan 2014-03-12 17:29:37 CET

CC: (none) => smorgan

Comment 6 Thomas Backlund 2014-03-12 17:33:39 CET
Update pushed:
http://advisories.mageia.org/MGASA-2014-0128.html

Status: ASSIGNED => RESOLVED
CC: (none) => tmb
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.