Bug 23006 - Security update request for flash-player-plugin, to 29.0.0.171
Summary: Security update request for flash-player-plugin, to 29.0.0.171
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 6
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: https://helpx.adobe.com/security/prod...
Whiteboard: MGA6-64-OK MGA6-32-OK
Keywords: Security, advisory, validated_update
Depends on:
Blocks:
 
Reported: 2018-05-08 17:38 CEST by Anssi Hannula
Modified: 2018-05-12 10:41 CEST (History)
3 users (show)

See Also:
Source RPM: flash-player-plugin
CVE: CVE-2018-4944
Status comment:


Attachments

Description Anssi Hannula 2018-05-08 17:38:50 CEST
Advisory:
============
Adobe Flash Player 29.0.0.171 addresses a critical type confusion vulnerability that could lead to arbitrary code execution (CVE-2018-4944).

References:
https://helpx.adobe.com/security/products/flash-player/apsb18-16.html
============

Updated Flash Player packages have been submitted to mga6 nonfree/updates_testing.

Source packages:
flash-player-plugin-29.0.0.171-1.mga6.nonfree

Binary packages:
flash-player-plugin
Comment 1 Thomas Andrews 2018-05-11 15:22:34 CEST
Tested both arches in Plasma 5.12.2 installs on an HP 6550b laptop (i3, 8GB, Intel graphics, Intel wifi).

Packages installed cleanly. One install had had the flashplayer and freshplayer removed, and this package installed both as it should.

Tested on a radar sit known to still use Flash for loops, and it worked as it should.

Going ahead with OKs on this, as the flashplayer currently in the repos refuses to install due to Adobe's practices

Whiteboard: (none) => MGA6-64-OK MGA6-32-OK
CC: (none) => andrewsfarm

Comment 2 Thomas Backlund 2018-05-12 10:39:18 CEST
Advisory added, validating

Keywords: (none) => advisory, validated_update
CC: (none) => tmb, sysadmin-bugs

Comment 3 Mageia Robot 2018-05-12 10:41:53 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2018-0233.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.