Bug 26184 - flash-player-plugin security update 32.0.0.330
Summary: flash-player-plugin security update 32.0.0.330
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7-64-OK MGA7-32-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2020-02-11 15:34 CET by Nicolas Salguero
Modified: 2020-02-13 11:50 CET (History)
3 users (show)

See Also:
Source RPM: flash-player-plugin
CVE: CVE-2020-3757
Status comment:


Attachments

Description Nicolas Salguero 2020-02-11 15:34:12 CET
Hi,

Version 32.0.0.330 fixes CVE-2020-3757.

References:
https://helpx.adobe.com/security/products/flash-player/apsb20-06.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-3757

Best regards,

Nico.
Nicolas Salguero 2020-02-11 15:35:19 CET

Whiteboard: (none) => MGA7TOO
Source RPM: (none) => flash-player-plugin
CVE: (none) => CVE-2020-3757

Comment 1 Nicolas Salguero 2020-02-11 15:40:16 CET
Suggested advisory:
========================

Updated flash-player-plugin package fixes a security vulnerability:

Type confusion that leads to arbitrary code execution in the context of the current user. (CVE-2020-3757)

References:
https://helpx.adobe.com/security/products/flash-player/apsb20-06.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-3757
========================

Updated packages in nonfree/updates_testing:
========================
flash-player-plugin-32.0.0.330-1.mga7.nonfree

from SRPMS:
flash-player-plugin-32.0.0.330-1.mga7.nonfree.src.rpm

Whiteboard: MGA7TOO => (none)
Status: NEW => ASSIGNED
Assignee: bugsquad => qa-bugs
Version: Cauldron => 7

Comment 2 Thomas Andrews 2020-02-11 21:18:54 CET
64-bit Plasma system. No installation issues.

Went to a US radar site known to use flash for some of its loops. Turned off flash, tried a loop, didn't work. Turned it back on, and it worked.

OK for 64-bit.

CC: (none) => andrewsfarm
Whiteboard: (none) => MGA7-64-OK

Comment 3 Thomas Andrews 2020-02-11 21:31:10 CET
Real 32-bit hardware, Xfce system. Again, no installation issues.

Performed the same test as in Comment 2, with the same result. 

OK for 32-bit. Validating. Advisory in Comment 1.

CC: (none) => sysadmin-bugs
Whiteboard: MGA7-64-OK => MGA7-64-OK MGA7-32-OK
Keywords: (none) => validated_update

Thomas Backlund 2020-02-13 11:17:19 CET

Keywords: (none) => advisory
CC: (none) => tmb

Comment 4 Mageia Robot 2020-02-13 11:50:23 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2020-0085.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.