Bug 850220 (CVE-2013-5329) - VUL-0: CVE-2013-5329: flash-player: memory corruption vulnerabilities that could lead to code execution
Summary: VUL-0: CVE-2013-5329: flash-player: memory corruption vulnerabilities that co...
Status: RESOLVED FIXED
Alias: CVE-2013-5329
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Major
Target Milestone: ---
Deadline: 2013-11-20
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard: maint:released:sle11-sp2:55100
Keywords:
Depends on:
Blocks:
 
Reported: 2013-11-13 09:40 UTC by Victor Pereira
Modified: 2015-02-19 01:34 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Victor Pereira 2013-11-13 09:40:02 UTC
CVE-2013-5329
Adobe has released Flash Player 11.2.202.327 for Linux to correct the following flaws:

* These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2013-5329, CVE-2013-5330).

References:

http://www.adobe.com/support/security/bulletins/apsb13-26.html
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-5329
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-5330
https://bugzilla.redhat.com/show_bug.cgi?id=1029692
Comment 1 Swamp Workflow Management 2013-11-13 09:51:20 UTC
The SWAMPID for this issue is 55088.
This issue was rated as important.
Please submit fixed packages until 2013-11-20.
When done, please reassign the bug to security-team@suse.de.
Patchinfo will be handled by security team.
Comment 2 Stanislav Brabec 2013-11-13 20:59:03 UTC
Submitted:
openSUSE:Factory:NonFree: created OBS request id 206822 to multimedia:apps
openSUSE:13.1:NonFree: created OBS request id 206823 (It was missing in the maintenance request and an attempt to add it manually fails with HTTP Error 400: Bad Request)
openSUSE: (12.3, 12.2): created OBS maintenance request id 206825
SLE11: created IBS request id 29296
SLE10: created IBS request id 29297 (Note: It seems that version 11.2.202.310 was not yet released for SLE10, so we are skipping one update).

This time I have to update supplementary script update.sh as well - Adobe changed the web page design. When updating, I also changed it to use .tar.gz files as they are released by Adobe.
Comment 3 Bernhard Wiedemann 2013-11-13 21:00:25 UTC
This is an autogenerated message for OBS integration:
This bug (850220) was mentioned in
https://build.opensuse.org/request/show/206823 13.1:NonFree / flash-player
Comment 4 Swamp Workflow Management 2013-11-13 23:00:25 UTC
bugbot adjusting priority
Comment 6 Bernhard Wiedemann 2013-11-14 10:00:32 UTC
This is an autogenerated message for OBS integration:
This bug (850220) was mentioned in
https://build.opensuse.org/request/show/206858 Factory:NonFree / flash-player
Comment 8 Swamp Workflow Management 2013-11-15 19:47:43 UTC
Update released for: flash-player, flash-player-gnome, flash-player-kde4
Products:
SLE-DESKTOP 11-SP3 (i386, x86_64)
Comment 9 Swamp Workflow Management 2013-11-15 19:49:28 UTC
Update released for: flash-player, flash-player-gnome, flash-player-kde4
Products:
SLE-DESKTOP 11-SP2 (i386, x86_64)
Comment 10 Swamp Workflow Management 2013-11-17 14:04:19 UTC
openSUSE-SU-2013:1717-1: An update that fixes two vulnerabilities is now available.

Category: security (important)
Bug References: 850220
CVE References: CVE-2013-5329,CVE-2013-5330
Sources used:
Comment 11 Bernhard Wiedemann 2013-11-18 07:00:21 UTC
This is an autogenerated message for OBS integration:
This bug (850220) was mentioned in
https://build.opensuse.org/request/show/207419 Evergreen:11.2:Test / flash-player
Comment 12 Marcus Meissner 2013-11-19 16:17:58 UTC
released
Comment 13 Bernhard Wiedemann 2013-11-19 18:00:28 UTC
This is an autogenerated message for OBS integration:
This bug (850220) was mentioned in
https://build.opensuse.org/request/show/207615 Evergreen:11.2 / flash-player
Comment 14 Swamp Workflow Management 2013-11-21 11:04:23 UTC
openSUSE-SU-2013:1737-1: An update that fixes two vulnerabilities is now available.

Category: security (important)
Bug References: 850220
CVE References: CVE-2013-5329,CVE-2013-5330
Sources used: