Bug 476172 (CVE-2008-5499)

Summary: CVE-2008-5499 flash-plugin: Linux-specific code execution flaw via crafted SWF file
Product: [Other] Security Response Reporter: Tomas Hoger <thoger>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: urgent Docs Contact:
Priority: urgent    
Version: unspecifiedCC: jlieskov, kreilly, mjc, security-response-team, wtogami
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2008-12-19 19:31:40 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 476173, 476174, 476175    
Bug Blocks:    

Description Tomas Hoger 2008-12-12 08:20:35 UTC
A security flaw was discovered in the Adobe Flash Player for Linux 10.0.12.36 and 9.0.151.0 that could allow attacker to run arbitrary code on the user's system when crafted SWF file was opened by a victim.

Comment 2 Mark J. Cox 2008-12-18 08:19:25 UTC
Public, removing embargo:
http://www.adobe.com/support/security/bulletins/apsb08-24.html

Comment 4 Red Hat Product Security 2008-12-19 19:31:40 UTC
This issue was addressed in:

Red Hat Enterprise Linux Extras:
  http://rhn.redhat.com/errata/RHSA-2008-1047.html

Comment 5 Tomas Hoger 2009-01-03 11:10:53 UTC
Further technical details about this flaw in the Bas Alberts' blog post:
http://basonbugs.blogspot.com/2008/12/you-can-only-sit-down-if-you-are-human.html