Bug 514874 (CVE-2009-1863, CVE-2009-1864, CVE-2009-1865, CVE-2009-1866, CVE-2009-1868, CVE-2009-1869) - flash-plugin: multiple code execution flaws (APSB09-10)
Summary: flash-plugin: multiple code execution flaws (APSB09-10)
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2009-1863, CVE-2009-1864, CVE-2009-1865, CVE-2009-1866, CVE-2009-1868, CVE-2009-1869
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
urgent
urgent
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 513373 513374 513375
Blocks:
TreeView+ depends on / blocked
 
Reported: 2009-07-31 07:38 UTC by Tomas Hoger
Modified: 2022-04-07 12:26 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2009-07-31 14:58:02 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2009:1188 0 normal SHIPPED_LIVE Critical: flash-plugin security update 2009-07-31 14:20:56 UTC
Red Hat Product Errata RHSA-2009:1189 0 normal SHIPPED_LIVE Critical: flash-plugin security update 2009-07-31 14:16:59 UTC

Description Tomas Hoger 2009-07-31 07:38:02 UTC
Adobe has released new versions of Adobe Flash Player - 9.0.246.0 and 10.0.32.18 - fixing multiple security issues allowing code execution when malicious SWF files were played, detailed in the Adobe Security Bulletin APSB09-10:

http://www.adobe.com/support/security/bulletins/apsb09-10.html

Quoting Adobe Security Bulletin:

The update for Adobe Flash Player and Adobe AIR, Adobe Reader and Acrobat resolves a memory corruption vulnerability that could potentially lead to code execution (CVE-2009-1862).  (tracked via separate bug #513362)

The update for Adobe Flash Player and Adobe AIR resolves the privilege escalation vulnerability that could potentially lead to code execution (CVE-2009-1863).

The update for Adobe Flash Player and Adobe AIR resolves the heap overflow vulnerability that could potentially lead to code execution (CVE-2009-1864).

The update for Adobe Flash Player and Adobe AIR resolves the null pointer vulnerability that could potentially lead to code execution (CVE-2009-1865).

The update for Adobe Flash Player and Adobe AIR resolves the stack overflow vulnerability that could potentially lead to code execution (CVE-2009-1866).

The update for Adobe Flash Player and Adobe AIR resolves the URL parsing heap overflow vulnerability that could potentially lead to code execution (CVE-2009-1868).

The update for Adobe Flash Player and Adobe AIR resolves the integer overflow vulnerability that could potentially lead to code execution (CVE-2009-1869).

Comment 2 errata-xmlrpc 2009-07-31 14:17:05 UTC
This issue has been addressed in following products:

  Extras for RHEL 3
  Extras for RHEL 4

Via RHSA-2009:1189 https://rhn.redhat.com/errata/RHSA-2009-1189.html

Comment 3 errata-xmlrpc 2009-07-31 14:21:01 UTC
This issue has been addressed in following products:

  Extras for Red Hat Enterprise Linux 5

Via RHSA-2009:1188 https://rhn.redhat.com/errata/RHSA-2009-1188.html


Note You need to log in before you can comment on or make changes to this bug.