Macromedia Flash Player: Arbitrary code execution
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 200603-20 / Flash |
| Release Date |
March 21, 2006 |
| Latest Revision |
March 21, 2006: 01 |
| Impact |
normal |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| net-www/netscape-flash |
<
7.0.63 |
>=
7.0.63 |
All supported architectures
|
Related bugreports:
#102777
Synopsis
Multiple vulnerabilities have been identified that allows arbitrary code execution on
a user's system via the handling of malicious SWF files.
2.
Impact Information
Background
The Macromedia Flash Player is a renderer for the popular SWF
filetype which is commonly used to provide interactive websites,
digital experiences and mobile content.
Description
The Macromedia Flash Player contains multiple unspecified
vulnerabilities.
Impact
An attacker serving a maliciously crafted SWF file could entice a
user to view the SWF file and execute arbitrary code on the user's
machine.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All Macromedia Flash Player users should upgrade to the latest
version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-www/netscape-flash-7.0.63"
|
4.
References
|