Bug 16392 - Security update request for flash-player-plugin, to 11.2.202.491
Summary: Security update request for flash-player-plugin, to 11.2.202.491
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 5
Hardware: All Linux
Priority: High major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA4TOO MGA4-32-OK MGA4-64-OK mga5-32...
Keywords: Security, validated_update
Depends on:
Blocks:
 
Reported: 2015-07-16 15:31 CEST by Anssi Hannula
Modified: 2015-07-16 23:22 CEST (History)
5 users (show)

See Also:
Source RPM: flash-player-plugin
CVE: CVE-2015-5122, CVE-2015-5123
Status comment:


Attachments

Description Anssi Hannula 2015-07-16 15:31:41 CEST
Advisory:
============
Adobe Flash Player 11.2.202.491 contains fixes to critical security vulnerabilities found in earlier versions that could potentially allow an attacker to take control of the affected system.

Adobe is aware of reports that exploits targeting these vulnerabilities have been published publicly.

This update resolves a use-after-free vulnerability that could lead to code execution (CVE-2015-5122).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2015-5123).

References:
https://helpx.adobe.com/security/products/flash-player/apsb15-18.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5122
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5123
============

Updated Flash Player 11.2.202.491 packages are in mga5+mga4 nonfree/updates_testing.

Source packages:
flash-player-plugin-11.2.202.491-1.mga4.nonfree
flash-player-plugin-11.2.202.491-1.mga5.nonfree

Binary packages:
flash-player-plugin
flash-player-plugin-kde
Anssi Hannula 2015-07-16 15:31:56 CEST

Whiteboard: (none) => MGA4TOO

Comment 1 David Walser 2015-07-16 15:57:39 CEST
It works (Mageia 4 i586).  Firefox is still blocking it, but I guess they'll fix that soon.

Whiteboard: MGA4TOO => MGA4TOO MGA4-32-OK

Comment 2 Anssi Hannula 2015-07-16 16:39:25 CEST
Hmh, weird, .491 is not listed at https://addons.mozilla.org/en-US/firefox/blocked/
Comment 3 Bill Wilkinson 2015-07-16 18:00:15 CEST
No issue with firefox blocking the new release on mga5-64. youTube and game both work, as does changing saving local content setting.

CC: (none) => wrw105
Whiteboard: MGA4TOO MGA4-32-OK => MGA4TOO MGA4-32-OK mga5-64-ok

Comment 4 Otto Leipälä 2015-07-16 19:03:23 CEST
(In reply to Anssi Hannula from comment #2)
> Hmh, weird, .491 is not listed at
> https://addons.mozilla.org/en-US/firefox/blocked/

Would that be it's fixed already so why to block it if bug is fixed in that version when only older ones are affected ????.

CC: (none) => ozkyster

Comment 5 Otto Leipälä 2015-07-16 19:07:44 CEST
(In reply to Otto Leipälä from comment #4)
> (In reply to Anssi Hannula from comment #2)
> > Hmh, weird, .491 is not listed at
> > https://addons.mozilla.org/en-US/firefox/blocked/
> 
> Would that be it's fixed already so why to block it if bug is fixed in that
> version when only older ones are affected ????.

In my system flash is not blocked at all now as i removed profile so it's not blocked at all anymore.
Comment 6 David Walser 2015-07-16 21:42:21 CEST
I restarted Firefox and now it's not blocked.  Before, I did make sure that the plugin wasn't running before I updated it and tested it, so when I clicked to temporarily allow it, it was using the updated Flash, but for some reason Firefox didn't know to stop blocking it.  Restarting fixes it.
Comment 7 William Kenney 2015-07-16 22:42:03 CEST
In VirtualBox, M5, KDE, 32-bit

Package(s) under test:
flash-player-plugin flash-player-plugin-kde

default install of package

[root@localhost wilcal]# urpmi flash-player-plugin
Package flash-player-plugin-11.2.202.481-1.mga5.nonfree.i586 is already installed
[root@localhost wilcal]# urpmi flash-player-plugin-kde
Package flash-player-plugin-kde-11.2.202.481-1.mga5.nonfree.i586 is already installed

Blocked Flash sites

install flash-player-plugin flash-player-plugin-kde from updates_testing

[root@localhost wilcal]# urpmi flash-player-plugin
Package flash-player-plugin-11.2.202.491-1.mga5.nonfree.i586 is already installed
[root@localhost wilcal]# urpmi flash-player-plugin-kde
Package flash-player-plugin-kde-11.2.202.491-1.mga5.nonfree.i586 is already installed

Flash sites work

Test platform:
Intel Core i7-2600K Sandy Bridge 3.4GHz
GIGABYTE GA-Z68X-UD3-B3 LGA 1155 MoBo
GIGABYTE GV-N440D3-1GI Nvidia GeForce GT 440 (Fermi) 1GB
RTL8111/8168B PCI Express 1Gbit Ethernet
DRAM 16GB (4 x 4GB)
Mageia 4 64-bit, Nvidia driver
virtualbox-4.3.26-1.mga4.x86_64
virtualbox-guest-additions-4.3.26-1.mga4.x86_64

CC: (none) => wilcal.int

William Kenney 2015-07-16 22:42:19 CEST

Whiteboard: MGA4TOO MGA4-32-OK mga5-64-ok => MGA4TOO MGA4-32-OK mga5-32-ok mga5-64-ok

Comment 8 William Kenney 2015-07-16 23:03:31 CEST
In VirtualBox, M4, KDE, 64-bit

Package(s) under test:
flash-player-plugin flash-player-plugin-kde

default install of flash-player-plugin flash-player-plugin-kde

[root@localhost wilcal]# urpmi flash-player-plugin
Package flash-player-plugin-11.2.202.481-1.mga4.nonfree.x86_64 is already installed
[root@localhost wilcal]# urpmi flash-player-plugin-kde
Package flash-player-plugin-kde-11.2.202.481-1.mga4.nonfree.x86_64 is already installed

Blocked Flash sites

install flash-player-plugin flash-player-plugin-kde from updates_testing

[root@localhost wilcal]# urpmi flash-player-plugin
Package flash-player-plugin-11.2.202.491-1.mga4.nonfree.x86_64 is already installed
[root@localhost wilcal]# urpmi flash-player-plugin-kde
Package flash-player-plugin-kde-11.2.202.491-1.mga4.nonfree.x86_64 is already installed

Flash sites work

Test platform:
Intel Core i7-2600K Sandy Bridge 3.4GHz
GIGABYTE GA-Z68X-UD3-B3 LGA 1155 MoBo
GIGABYTE GV-N440D3-1GI Nvidia GeForce GT 440 (Fermi) 1GB
RTL8111/8168B PCI Express 1Gbit Ethernet
DRAM 16GB (4 x 4GB)
Mageia 4 64-bit, Nvidia driver
virtualbox-4.3.26-1.mga4.x86_64
virtualbox-guest-additions-4.3.26-1.mga4.x86_64
William Kenney 2015-07-16 23:03:50 CEST

Whiteboard: MGA4TOO MGA4-32-OK mga5-32-ok mga5-64-ok => MGA4TOO MGA4-32-OK MGA4-64-OK mga5-32-ok mga5-64-ok

Comment 9 William Kenney 2015-07-16 23:04:40 CEST
This update works fine.
Testing complete for mga4 & mga5, 32-bit & 64-bit
Validating the update.
Could someone from the sysadmin team push to updates.
Thanks

CC: (none) => sysadmin-bugs
Keywords: (none) => validated_update

Comment 10 Thomas Backlund 2015-07-16 23:17:45 CEST
advisory added

CC: (none) => tmb
Whiteboard: MGA4TOO MGA4-32-OK MGA4-64-OK mga5-32-ok mga5-64-ok => MGA4TOO MGA4-32-OK MGA4-64-OK mga5-32-ok mga5-64-ok advisory

Comment 11 Mageia Robot 2015-07-16 23:21:08 CEST
An update for this issue has been pushed to Mageia Updates repository.

http://advisories.mageia.org/MGASA-2015-0275.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED

Comment 12 William Kenney 2015-07-16 23:22:14 CEST
It's over for this week. See ya next week.

Note You need to log in before you can comment on or make changes to this bug.