Bug 513362 (APSA09-03, CVE-2009-1862)
Summary: | CVE-2009-1862 acroread, flash-plugin: Remote code execution vulnerability via malicious SWF (Shockwave Flash) content | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Jan Lieskovsky <jlieskov> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | urgent | Docs Contact: | |
Priority: | urgent | ||
Version: | unspecified | CC: | kreilly, mjc, wtogami |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://www.adobe.com/support/security/advisories/apsa09-03.html | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2009-07-31 14:57:51 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 513373, 513374, 513375 | ||
Bug Blocks: |
Description
Jan Lieskovsky
2009-07-23 10:31:44 UTC
MITRE's CVE-2009-1862 record: Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87, allows remote attackers to execute arbitrary code via (1) a crafted Flash application in a .pdf file or (2) a crafted .swf file, related to authplay.dll, as exploited in the wild in July 2009. References: ----------- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1862 http://blogs.adobe.com/psirt/2009/07/potential_adobe_reader_and_fla.html http://bugs.adobe.com/jira/browse/FP-1265 http://isc.sans.org/diary.html?storyid=6847 http://news.cnet.com/8301-27080_3-10293389-245.html http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-072209-2512-99 http://www.symantec.com/connect/blogs/next-generation-flash-vulnerability http://www.kb.cert.org/vuls/id/259425 http://www.securityfocus.com/bid/35759 Note: An exact duplicate CVE identifier of CVE-2009-2580 has been also assigned to this vulnerability. Fixed now in Adobe Flash Player 9.0.246.0 and 10.0.32.18: http://www.adobe.com/support/security/bulletins/apsb09-10.html This issue has been addressed in following products: Extras for RHEL 3 Extras for RHEL 4 Via RHSA-2009:1189 https://rhn.redhat.com/errata/RHSA-2009-1189.html This issue has been addressed in following products: Extras for Red Hat Enterprise Linux 5 Via RHSA-2009:1188 https://rhn.redhat.com/errata/RHSA-2009-1188.html |