Bug 6385 - Update request for flash-player-plugin, to 11.2.202.236, mga1
Summary: Update request for flash-player-plugin, to 11.2.202.236, mga1
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 1
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact:
URL:
Whiteboard: mga1-64-OK, mga1-32-OK
Keywords: Security, validated_update
Depends on: 6384
Blocks:
  Show dependency treegraph
 
Reported: 2012-06-09 13:33 CEST by Anssi Hannula
Modified: 2012-06-10 21:05 CEST (History)
3 users (show)

See Also:
Source RPM: flash-player-plugin
CVE:
Status comment:


Attachments

Description Anssi Hannula 2012-06-09 13:33:51 CEST
Flash Player 11.2.202.236 has been pushed to mga1 nonfree/updates_testing.

Advisory:
============
Adobe Flash Player 11.2.202.236 contains fixes to critical security vulnerabilites found in earlier versions. These vulnerabilities could cause a crash and potentially allow an attacker to take control of the affected system.

This update resolves various memory corruption (CVE-2012-2034, CVE-2012-2037), stack overflow (CVE-2012-2035), integer overflow (CVE-2012-2036), and null dereference vulnerabilities (CVE-2012-2039) that could lead to code execution.

This update resolves a security bypass vulnerability that could lead to information disclosure (CVE-2012-2038).

Additionally, a packaging issue is fixed which prevented XCB version of libcairo from being used (Mageia bug #5824).

References:
http://www.adobe.com/support/security/bulletins/apsb12-14.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2034
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2035
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2036
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2037
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2038
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2039
https://bugs.mageia.org/show_bug.cgi?id=5824
============

Updated Flash Player 11.2.202.236 packages are in mga1 nonfree/updates_testing
as flash-player-plugin (i586 and x86_64) and flash-player-plugin-kde (i586 and
x86_64).

==========
Suggested testing procedure:
==========
Package installs and Flash works.
Manuel Hiebel 2012-06-10 13:13:24 CEST

Blocks: (none) => 6384

Comment 1 Manuel Hiebel 2012-06-10 13:13:53 CEST
Ok on mga1 x86_64

Component: RPM Packages => Security
Blocks: 6384 => (none)
Whiteboard: (none) => mga1-64-OK,

claire robinson 2012-06-10 14:49:58 CEST

Depends on: (none) => 6384

Comment 2 Anssi Hannula 2012-06-10 17:06:02 CEST
I tested on mga1 i586 myself, seems to work.
Comment 3 Dave Hodgins 2012-06-10 18:10:34 CEST
Validating the update.

Could someone from the sysadmin team push the srpm
flash-player-plugin-11.2.202.236-1.mga1.nonfree.src.rpm
from Nonfree Updates Testing to Nonfree Updates.

Note that this update should be pushed at the same time as, or after
the Mageia 2 update, in bug 6384.

Advisory: Adobe Flash Player 11.2.202.236 contains fixes to critical
security vulnerabilites found in earlier versions. These vulnerabilities
could cause a crash and potentially allow an attacker to take control of
the affected system.

This update resolves various memory corruption (CVE-2012-2034, CVE-2012-2037),
stack overflow (CVE-2012-2035), integer overflow (CVE-2012-2036), and null
dereference vulnerabilities (CVE-2012-2039) that could lead to code execution.

This update resolves a security bypass vulnerability that could lead to
information disclosure (CVE-2012-2038).

Additionally, a packaging issue is fixed which prevented XCB version of
libcairo from being used (Mageia bug #5824).

References:
http://www.adobe.com/support/security/bulletins/apsb12-14.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2034
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2035
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2036
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2037
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2038
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2039
https://bugs.mageia.org/show_bug.cgi?id=5824

https://bugs.mageia.org/show_bug.cgi?id=6385

CC: (none) => davidwhodgins, sysadmin-bugs
Keywords: (none) => validated_update
Whiteboard: mga1-64-OK, => mga1-64-OK, mga1-32-OK

Comment 4 Thomas Backlund 2012-06-10 21:05:33 CEST
Update submitted:
https://wiki.mageia.org/en/Support/Advisories/MGASA-2012-0114

CC: (none) => tmb
Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.