Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 563819 - (CVE-2010-0186) CVE-2010-0186 flash-plugin: unauthorized cross-domain requests (APSB10-06)
CVE-2010-0186 flash-plugin: unauthorized cross-domain requests (APSB10-06)
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
high Severity high
: ---
: ---
Assigned To: Red Hat Product Security
http://www.adobe.com/support/security...
impact=important,source=adobe,reporte...
: Security
Depends On: 563863 564230 564231 566092 566093
Blocks:
  Show dependency treegraph
 
Reported: 2010-02-11 04:25 EST by Jan Lieskovsky
Modified: 2010-03-29 04:59 EDT (History)
6 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2010-03-29 04:59:32 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2010:0102 normal SHIPPED_LIVE Important: flash-plugin security update 2010-02-12 09:24:26 EST
Red Hat Product Errata RHSA-2010:0103 normal SHIPPED_LIVE Important: flash-plugin security update 2010-02-12 09:24:44 EST
Red Hat Product Errata RHSA-2010:0114 normal SHIPPED_LIVE Critical: acroread security and bug fix update 2010-02-18 10:48:52 EST

  None (edit)
Description Jan Lieskovsky 2010-02-11 04:25:00 EST
On Thursday, 2010-02-11, Adobe is planning to release updated
tarballs for Adobe Flash Player of version v10.0.42.34,
adressing two security issues:

1, An unspecified critical vulnerability was found in Adobe Flash
Player (and related products), which could allow an attacker to
subvert the domain sandbox and make unauthorized cross-domain
requests. (CVE-2010-0186).

Credit: Michael Yong Park
Vulnerable versions of Adobe Flash Player: v10.0.42.34 and earlier
Not vulnerable versions of Adobe Flash Player: 10.0.45.2

2, An unspecified vulnerability was found in Adobe Flash Player
(and related products), which could allow an attacker to 
cause denial of service by unspecified vectors. (CVE-2010-0187)

References:
  http://www.adobe.com/support/security/bulletins/apsb10-06.html
Comment 3 Tomas Hoger 2010-02-12 02:58:01 EST
Public now via Adobe Security Bulletin APSB10-06:
  http://www.adobe.com/support/security/bulletins/apsb10-06.html
Comment 4 Tomas Hoger 2010-02-12 03:00:51 EST
Adobe Reader 9.x versions embed Flash Player.  Adobe is planning to update Adobe Reader on Feb16:
  http://www.adobe.com/support/security/bulletins/apsb10-07.html
Comment 6 Tomas Hoger 2010-02-12 04:52:16 EST
CVE-2010-0187 was split to separate bug #564287.
Comment 7 errata-xmlrpc 2010-02-12 09:24:29 EST
This issue has been addressed in following products:

  Extras for Red Hat Enterprise Linux 5

Via RHSA-2010:0102 https://rhn.redhat.com/errata/RHSA-2010-0102.html
Comment 8 errata-xmlrpc 2010-02-12 09:24:46 EST
This issue has been addressed in following products:

  Extras for RHEL 3
  Extras for RHEL 4

Via RHSA-2010:0103 https://rhn.redhat.com/errata/RHSA-2010-0103.html
Comment 10 errata-xmlrpc 2010-02-18 10:48:57 EST
This issue has been addressed in following products:

  Extras for RHEL 4
  Extras for Red Hat Enterprise Linux 5

Via RHSA-2010:0114 https://rhn.redhat.com/errata/RHSA-2010-0114.html

Note You need to log in before you can comment on or make changes to this bug.