Bug 695546 (CVE-2011-0611) - CVE-2011-0611 flash-plugin: crash and potential arbitrary code execution (APSB11-07)
Summary: CVE-2011-0611 flash-plugin: crash and potential arbitrary code execution (APS...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2011-0611
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
urgent
urgent
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 696433 696434
Blocks:
TreeView+ depends on / blocked
 
Reported: 2011-04-11 23:10 UTC by Vincent Danen
Modified: 2019-09-29 12:44 UTC (History)
5 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2012-09-25 16:06:55 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2011:0451 0 normal SHIPPED_LIVE Critical: flash-plugin security update 2011-04-18 15:38:52 UTC

Description Vincent Danen 2011-04-11 23:10:25 UTC
Adobe has released APSA11-02 [1] to warn of a new critical vulnerability in
Adobe Flash Player 10.x.  The vulnerability is described as:

This vulnerability (CVE-2011-0611) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being exploited in the wild in targeted attacks via a Flash (.swf) file embedded in a Microsoft Word (.doc) file delivered as an email attachment, targeting the Windows platform. At this time, Adobe is not aware of any attacks via PDF targeting Adobe Reader and Acrobat. Adobe Reader X Protected Mode mitigations would prevent an exploit of this kind from executing.

This flaw does not affect Adobe Reader 9.x for UNIX.

[1] http://www.adobe.com/support/security/advisories/apsa11-02.html

Comment 2 Vincent Danen 2011-04-15 23:10:59 UTC
Updated packages are now available via APSB11-07:

http://www.adobe.com/support/security/bulletins/apsb11-07.html

Comment 3 errata-xmlrpc 2011-04-18 15:38:56 UTC
This issue has been addressed in following products:

  Supplementary for Red Hat Enterprise Linux 5
  Supplementary for Red Hat Enterprise Linux 6

Via RHSA-2011:0451 https://rhn.redhat.com/errata/RHSA-2011-0451.html


Note You need to log in before you can comment on or make changes to this bug.