Bug 26779 - flash-player-plugin security update 32.0.0.387
Summary: flash-player-plugin security update 32.0.0.387
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2020-06-12 16:23 CEST by Nicolas Salguero
Modified: 2020-06-15 09:56 CEST (History)
4 users (show)

See Also:
Source RPM: flash-player-plugin
CVE: CVE-2020-9633
Status comment:


Attachments

Description Nicolas Salguero 2020-06-12 16:23:04 CEST
Hi,

Version 32.0.0.387 fixes CVE-2020-9633.

References:
https://helpx.adobe.com/security/products/flash-player/apsb20-30.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9633

Best regards,

Nico.
Comment 1 Nicolas Salguero 2020-06-12 16:32:28 CEST
Suggested advisory:
========================

The updated packages fix a security vulnerability:

Use after free that leads to arbitrary code execution in the context of the current user. (CVE-2020-9633)

References:
https://helpx.adobe.com/security/products/flash-player/apsb20-30.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9633
========================

Updated packages in core/updates_testing:
========================
flash-player-plugin-32.0.0.387-1.mga7.nonfree

from SRPMS:
flash-player-plugin-32.0.0.387-1.mga7.nonfree.src.rpm

CVE: (none) => CVE-2020-9633
Source RPM: (none) => flash-player-plugin
Status: NEW => ASSIGNED
Assignee: bugsquad => qa-bugs
Version: Cauldron => 7

Comment 2 Morgan Leijström 2020-06-13 17:19:51 CEST
OK mga7-64, intel i7, plasma, nvidia-latest, firefox

Updated this and a bunch of other things, rebooted, went to https://get.adobe.com/se/flashplayer/about/ and it say flash is working and is version 32.0.0.387.

Whiteboard: (none) => MGA7-64-OK
CC: (none) => fri

Comment 3 Thomas Andrews 2020-06-14 00:59:31 CEST
Validating. Advisory in Comment 1.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Nicolas Lécureuil 2020-06-15 08:52:41 CEST

CC: (none) => mageia
Keywords: (none) => advisory

Comment 4 Mageia Robot 2020-06-15 09:56:05 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2020-0264.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.