Bug 695546 (CVE-2011-0611)

Summary: CVE-2011-0611 flash-plugin: crash and potential arbitrary code execution (APSB11-07)
Product: [Other] Security Response Reporter: Vincent Danen <vdanen>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: urgent Docs Contact:
Priority: urgent    
Version: unspecifiedCC: ed.costello, emhuang, mmelanso, mtilburg, stransky
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2012-09-25 16:06:55 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 696433, 696434    
Bug Blocks:    

Description Vincent Danen 2011-04-11 23:10:25 UTC
Adobe has released APSA11-02 [1] to warn of a new critical vulnerability in
Adobe Flash Player 10.x.  The vulnerability is described as:

This vulnerability (CVE-2011-0611) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being exploited in the wild in targeted attacks via a Flash (.swf) file embedded in a Microsoft Word (.doc) file delivered as an email attachment, targeting the Windows platform. At this time, Adobe is not aware of any attacks via PDF targeting Adobe Reader and Acrobat. Adobe Reader X Protected Mode mitigations would prevent an exploit of this kind from executing.

This flaw does not affect Adobe Reader 9.x for UNIX.

[1] http://www.adobe.com/support/security/advisories/apsa11-02.html

Comment 2 Vincent Danen 2011-04-15 23:10:59 UTC
Updated packages are now available via APSB11-07:

http://www.adobe.com/support/security/bulletins/apsb11-07.html

Comment 3 errata-xmlrpc 2011-04-18 15:38:56 UTC
This issue has been addressed in following products:

  Supplementary for Red Hat Enterprise Linux 5
  Supplementary for Red Hat Enterprise Linux 6

Via RHSA-2011:0451 https://rhn.redhat.com/errata/RHSA-2011-0451.html