Bug 62052 - Does the netscape libflashplugin.so use an insecure zlib ??
Does the netscape libflashplugin.so use an insecure zlib ??
Status: CLOSED ERRATA
Product: Red Hat Linux
Classification: Retired
Component: netscape (Show other bugs)
7.3
i386 Linux
high Severity medium
: ---
: ---
Assigned To: Bill Nottingham
David Lawrence
: Security
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2002-03-26 19:45 EST by Alan Cox
Modified: 2014-03-16 22:26 EDT (History)
2 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2003-06-20 14:32:54 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Alan Cox 2002-03-26 19:45:43 EST
strings /usr/lib/netscape/plugins/libflashplayer.so | grep zlib

Doing a primitive check with objdump it appears to be an old version of zlib and
probably one with the holes.

Does anyone know if the netscape folks updated it to the new zlib ?
Comment 1 Bill Nottingham 2002-03-27 14:52:17 EST
Since netscape hasn't updated anything yet, no, they haven't.
Putting in 'needinfo' as the closest thing we have to 'needsomeoneelse'ssoftware'.
Comment 2 Alan Cox 2002-03-27 14:58:04 EST
Should we pull the netscape 4 package from 7.3 final ? Without a fix its plain
dangerous to go around shipping exploitable web browsers

Comment 3 Alan Cox 2002-12-18 11:48:52 EST
Killed for 8.0 thankfully
Comment 4 Kjartan Maraas 2003-04-02 18:04:51 EST
Should this be closed then?
Comment 5 Mark J. Cox (Product Security) 2003-04-23 08:54:29 EDT
Leaving open since the flashplayer shipped with 7.2 and 7.3 is still vulnerable
to this issue.  No exploits for the zlib issue in flashplayer have been spotted.
Comment 6 Bill Nottingham 2003-06-20 14:32:54 EDT
An errata has been issued which should help the problem described in this bug report. 
This report is therefore being closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files, please follow the link below. You may reopen 
this bug report if the solution does not work for you.

http://rhn.redhat.com/errata/RHSA-2003-026.html

Note You need to log in before you can comment on or make changes to this bug.