Adobe Flash Player: Multiple vulnerabilities
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 201101-09 / adobe-flash |
| Release Date |
January 21, 2011 |
| Latest Revision |
January 21, 2011: 01 |
| Impact |
normal |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| www-plugins/adobe-flash |
<
10.1.102.64 |
>=
10.1.102.64 |
All supported architectures
|
Related bugreports:
#307749, #322855, #332205, #337204, #343089
Synopsis
Multiple vulnerabilities in Adobe Flash Player might allow remote attackers
to execute arbitrary code or cause a Denial of Service.
2.
Impact Information
Background
The Adobe Flash Player is a renderer for the SWF file format, which is
commonly used to provide interactive websites.
Description
Multiple vulnerabilities were discovered in Adobe Flash Player. For
further information please consult the CVE entries and the Adobe
Security Bulletins referenced below.
Impact
A remote attacker could entice a user to open a specially crafted SWF
file, possibly resulting in the execution of arbitrary code with the
privileges of the user running the application, or a Denial of Service.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All Adobe Flash Player users should upgrade to the latest stable
version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=www-plugins/adobe-flash-10.1.102.64"
|
4.
References
|