Bug 22367 - flash-player-plugin security update 28.0.0.137
Summary: flash-player-plugin security update 28.0.0.137
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 6
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: https://helpx.adobe.com/security/prod...
Whiteboard: mga6-64-ok
Keywords: Security, advisory, validated_update
Depends on:
Blocks:
 
Reported: 2018-01-10 09:55 CET by Nicolas Salguero
Modified: 2018-01-12 20:50 CET (History)
4 users (show)

See Also:
Source RPM: flash-player-plugin
CVE: CVE-2018-4871
Status comment:


Attachments

Description Nicolas Salguero 2018-01-10 09:55:38 CET
Hi,

Version 28.0.0.137 fixes:

An Out-of-bounds Read issue was discovered in Adobe Flash Player before 28.0.0.137. This vulnerability occurs because of computation that reads data that is past the end of the target buffer. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the vulnerability. A successful attack can lead to sensitive data exposure. (CVE-2018-4871)

Reference:
https://helpx.adobe.com/security/products/flash-player/apsb18-01.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-4871

Best regards,

Nico.
Nicolas Salguero 2018-01-10 09:56:18 CET

Whiteboard: (none) => MGA6TOO
CVE: (none) => CVE-2018-4871
Source RPM: (none) => flash-player-plugin

Marja Van Waes 2018-01-10 10:46:02 CET

Assignee: bugsquad => anssi.hannula
CC: (none) => marja11

Comment 1 Anssi Hannula 2018-01-10 15:12:59 CET
Advisory:
============
Adobe Flash Player 28.0.0.137 addresses an important out-of-bounds read vulnerability that could lead to information exposure (CVE-2018-4871).

References:
https://helpx.adobe.com/security/products/flash-player/apsb18-01.html
============

Updated Flash Player packages have been submitted to mga6 nonfree/updates_testing and to cauldron nonfree/release.

Source packages:
flash-player-plugin-28.0.0.137-1.mga6.nonfree

Binary packages:
flash-player-plugin

Status: NEW => ASSIGNED
CC: (none) => anssi.hannula
URL: (none) => https://helpx.adobe.com/security/products/flash-player/apsb18-01.html
Keywords: (none) => Security
Assignee: anssi.hannula => qa-bugs

Thomas Backlund 2018-01-10 15:44:20 CET

Version: Cauldron => 6
Whiteboard: MGA6TOO => (none)
CC: (none) => tmb

Comment 2 claire robinson 2018-01-11 19:02:56 CET
Tested OK mga6 64

Confirmed version being installed. Checked at adobe flash test page and played some flash games.

Whiteboard: (none) => mga6-64-ok

Lewis Smith 2018-01-12 09:37:55 CET

Keywords: (none) => advisory, validated_update
CC: (none) => sysadmin-bugs

Comment 3 Mageia Robot 2018-01-12 20:50:26 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2018-0072.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.