Bug 882187 (CVE-2014-0531) - VUL-0: CVE-2014-0531: flash-player: Multiple vulnerabilities
Summary: VUL-0: CVE-2014-0531: flash-player: Multiple vulnerabilities
Status: RESOLVED FIXED
Alias: CVE-2014-0531
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Major
Target Milestone: ---
Deadline: 2014-06-18
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/99446/
Whiteboard: maint:released:sle11-sp3:57782
Keywords:
Depends on:
Blocks:
 
Reported: 2014-06-11 08:17 UTC by Johannes Segitz
Modified: 2014-06-18 05:55 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2014-06-11 08:17:49 UTC
Adobe has released Flash Player 11.2.202.378 for Linux to correct the following flaws:

These updates resolve cross-site-scripting vulnerabilities (CVE-2014-0531, CVE-2014-0532, CVE-2014-0533).

These updates resolve security bypass vulnerabilities (CVE-2014-0534, CVE-2014-0535).

These updates resolve a memory corruption vulnerability that could result in arbitrary code execution (CVE-2014-0536).

http://helpx.adobe.com/security/products/flash-player/apsb14-16.html

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1107822
https://bugzilla.redhat.com/show_bug.cgi?id=1107823
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-0536
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-0535
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-0534
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-0533
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-0532
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-0531
Comment 1 Swamp Workflow Management 2014-06-11 08:31:23 UTC
An update workflow for this issue was started.
This issue was rated as important.
Please submit fixed packages until 2014-06-18.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/57781
Comment 2 SMASH SMASH 2014-06-11 08:35:15 UTC
Affected packages:

SLE-11-SP3: flash-player
Comment 3 Stanislav Brabec 2014-06-11 19:38:01 UTC
Submitted.

openSUSE 12.3, 13.1: created OBS maintenance request id 236916
openSUSE:Factory:NonFree: created OBS request id 236918
SLE11: created IBS request id 39347
SLE12: created IBS request id 39348

As Adobe again changed the flashplayer_11_sa.i386.tar.gz contents, I improved the stuff a bit. Now it accepts both forms of this file seen in past:
- only "flashplayer" binary packaged
- the whole tree packaged, with top directory named "install_flash_player_linux_sa" and "flashplayer" binary residing there together with other stuff we don't need.
Comment 4 Bernhard Wiedemann 2014-06-11 20:00:11 UTC
This is an autogenerated message for OBS integration:
This bug (882187) was mentioned in
https://build.opensuse.org/request/show/236918 Factory:NonFree / flash-player
Comment 5 Swamp Workflow Management 2014-06-11 22:00:12 UTC
bugbot adjusting priority
Comment 10 Swamp Workflow Management 2014-06-16 10:04:20 UTC
openSUSE-SU-2014:0798-1: An update that fixes 6 vulnerabilities is now available.

Category: security (moderate)
Bug References: 882187
CVE References: CVE-2014-0531,CVE-2014-0532,CVE-2014-0533,CVE-2014-0534,CVE-2014-0535,CVE-2014-0536
Sources used:
Comment 11 Swamp Workflow Management 2014-06-16 11:04:21 UTC
openSUSE-SU-2014:0799-1: An update that fixes 6 vulnerabilities is now available.

Category: security (moderate)
Bug References: 882187
CVE References: CVE-2014-0531,CVE-2014-0532,CVE-2014-0533,CVE-2014-0534,CVE-2014-0535,CVE-2014-0536
Sources used:
Comment 12 Marcus Meissner 2014-06-17 18:11:07 UTC
released
Comment 14 Swamp Workflow Management 2014-06-17 19:46:12 UTC
Update released for: flash-player, flash-player-gnome, flash-player-kde4
Products:
SLE-DESKTOP 11-SP3 (i386, x86_64)
Comment 15 Swamp Workflow Management 2014-06-17 23:04:31 UTC
SUSE-SU-2014:0806-1: An update that fixes 6 vulnerabilities is now available.

Category: security (important)
Bug References: 882187
CVE References: CVE-2014-0531,CVE-2014-0532,CVE-2014-0533,CVE-2014-0534,CVE-2014-0535,CVE-2014-0536
Sources used:
SUSE Linux Enterprise Desktop 11 SP3 (src):    flash-player-11.2.202.378-0.3.1