Bug 5752 - Update request for flash-player-plugin, to 11.2.202.235
Summary: Update request for flash-player-plugin, to 11.2.202.235
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: RPM Packages (show other bugs)
Version: 1
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact:
URL:
Whiteboard:
Keywords: Security, validated_update
Depends on:
Blocks:
 
Reported: 2012-05-04 22:43 CEST by Anssi Hannula
Modified: 2012-05-07 15:04 CEST (History)
4 users (show)

See Also:
Source RPM: flash-player-plugin
CVE:
Status comment:


Attachments

Description Anssi Hannula 2012-05-04 22:43:13 CEST
Flash Player 11.2.202.235 has been pushed to mga1 nonfree/updates_testing.

Advisory:
============
Adobe Flash Player 11.2.202.235 contains a fix to a critical security
vulnerability found in earlier versions. This vulnerability could cause a
crash and potentially allow an attacker to take control of the affected system.

This update resolves an object confusion vulnerability that could lead to code execution (CVE-2012-0779). The vulnerability is being exploited in the wild in active targeted attacks, though the currently reported exploits do not target Linux systems.

References:
http://www.adobe.com/support/security/bulletins/apsb12-09.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0779
============

Updated Flash Player 11.2.202.235 packages are in mga1 nonfree/updates_testing
as flash-player-plugin (i586 and x86_64) and flash-player-plugin-kde (i586 and
x86_64).

==========
Suggested testing procedure:
==========
Package installs and Flash works.
Comment 1 Dave Hodgins 2012-05-05 01:40:22 CEST
Testing complete on i586 for the srpm
flash-player-plugin-11.2.202.235-1.mga1.nonfree.src.rpm

Testing using http://www.adobe.com/software/flash/about,
http://video.citytv.com/video/detail/1602807255001.000000/worlds-apart/
and the kde tools menu entry.

CC: (none) => davidwhodgins

Comment 2 claire robinson 2012-05-05 10:02:12 CEST
Testing complete x86_64

Please see comment 0 for advisory and srpm.

Could sysadmin please push from nonfree/updates_testing to nonfree/updates

Thanks!

Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs
Version: Cauldron => 1

Comment 3 Olivier Delaune 2012-05-06 20:46:33 CEST
Testing complete on x86_64. I read video on youtube without any trouble.

CC: (none) => olivier.delaune

Comment 4 Thomas Backlund 2012-05-07 15:04:05 CEST
Update pushed

Status: ASSIGNED => RESOLVED
CC: (none) => tmb
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.