Bug 602627 (CVE-2010-2172)

Summary: CVE-2010-2172 flash-plugin: CVE-2010-0187 "possible player crash" affects also v9.x versions of Adobe Flash Player
Product: [Other] Security Response Reporter: Jan Lieskovsky <jlieskov>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: jrb, security-response-team, stransky, vdanen
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
URL: http://www.adobe.com/support/security/bulletins/apsb10-06.html
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2012-09-25 16:13:59 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 602641, 602642    
Bug Blocks:    

Description Jan Lieskovsky 2010-06-10 11:00:56 UTC
Originally, the following CVE-2010-0187 security flaw has been reported
against Adobe Flash Player v10.x and earlier versions:

  [1] http://www.adobe.com/support/security/bulletins/apsb10-06.html

CVE-2010-0187 got following description from MITRE:

"Adobe Flash Player before 10.0.45.2 and Adobe AIR before 1.5.3.9130 allow
remote attackers to cause a denial of service (application crash) via a
modified SWF file."

Public reproducers for the CVE-2010-0187 are available here:
  [2] http://www.exploit-db.com/exploits/11182/
  [3] http://sebug.net/exploit/18967/

Further testing showed, this deficiency affects also v9.x based versions
of Adobe Flash Player. This new discovered flaw got CVE id of CVE-2010-2172.

Comment 1 Jan Lieskovsky 2010-06-10 11:14:31 UTC
This issue affects the versions of the flash-plugin package, as shipped
with Red Hat Enterprise Linux 3 and 4.

This issue has been addressed in following products:

  Extras for Red Hat Enterprise Linux 5

Via RHSA-2010:0102 https://rhn.redhat.com/errata/RHSA-2010-0102.html

Comment 3 Vincent Danen 2010-06-11 18:25:52 UTC
This was publicly noted in APSB10-14:

http://www.adobe.com/support/security/bulletins/apsb10-14.html

Specifically:

This update resolves a denial of service issue on some UNIX platforms (Flash Player 9 only) (CVE-2010-2172).

Comment 4 errata-xmlrpc 2010-06-14 22:28:15 UTC
This issue has been addressed in following products:

  Extras for RHEL 3
  Extras for RHEL 4

Via RHSA-2010:0470 https://rhn.redhat.com/errata/RHSA-2010-0470.html