Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 0 articles for you...
91

Gentoo: GLSA-202003-61 Normal Severity: Adobe Flash Remote Execution

A vulnerability in Adobe Flash Player might allow remote attackers to execute arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202003-61 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Adobe Flash Player: Remote execution of arbitrary code Date: March 26, 2020 Bugs: #709728 ID: 202003-61 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability in Adobe Flash Player might allow remote attackers to execute arbitrary code. Background ========= The Adobe Flash Player is a renderer for the SWF file format, which is commonly used to provide interactive websites. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-plugins/adobe-flash < 32.0.0.330 > = 32.0.0.330 Description ========== A critical type confusion vulnerability was discovered in Adobe Flash Player. Impact ===== A remote attacker could possibly execute arbitrary code with the privileges of the process or cause a Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All Adobe Flash users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v "> =www-plugins/adobe-flash-32.0.0.330" References ========= [ 1 ] CVE-2020-3757 https://nvd.nist.gov/vuln/detail/CVE-2020-3757 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202003-61 Concerns? ======== Security is a primary focus ofGentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2020 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Gentoo Linux Security Advisory GLSA 202003-62 highlights a severe vulnerability in Adobe Acrobat Reader, allowing for unauthorized file access.. Adobe Flash Player,Gentoo Security Advisory,Remote Execution,Arbitrary Code. . LinuxSecurity.com Team

Calendar%202 Mar 26, 2020 Gentoo
91

Gentoo: GLSA-201709-16 High: Adobe Flash Player Remote Code Threats

Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201709-16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Adobe Flash Player: Multiple vulnerabilities Date: September 24, 2017 Bugs: #627336, #630964 ID: 201709-16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code. Background ========= The Adobe Flash Player is a renderer for the SWF file format, which is commonly used to provide interactive websites. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-plugins/adobe-flash < 27.0.0.130-r1 > = 27.0.0.130-r1 Description ========== Multiple vulnerabilities have been discovered in Adobe Flash Player. Please review the referenced CVE identifiers for details. Impact ===== A remote attacker could possibly execute arbitrary code with the privileges of the process or bypass security restrictions. Workaround ========= There is no known workaround at this time. Resolution ========= All Adobe Flash Player users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v "> =www-plugins/adobe-flash-26.0.0.151" References ========= [ 1 ] CVE-2017-11281 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-11281 [ 2 ] CVE-2017-11282 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-11282 [ 3 ] CVE-2017-3085 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-3085 [ 4 ] CVE-2017-3106 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-3106 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201709-16 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2017 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Adobe Flash Player is facing serious security flaws that could permit unauthorized execution of commands on Gentoo Linux systems. Update promptly to ensure protection.. Gentoo Security Advisory, Adobe Flash Player Threats, Remote Exploit Risks. . LinuxSecurity.com Team

Calendar%202 Sep 24, 2017 Gentoo
91

Gentoo: GLSA-201702-20 Normal: Adobe Flash Remote Code Execution

Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201702-20 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Adobe Flash Player: Multiple vulnerabilities Date: February 20, 2017 Bugs: #605314, #609330 ID: 201702-20 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code. Background ========= The Adobe Flash Player is a renderer for the SWF file format, which is commonly used to provide interactive websites. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-plugins/adobe-flash < 24.0.0.221 > = 24.0.0.221 Description ========== Multiple vulnerabilities have been discovered in Adobe Flash Player. Please review the CVE identifiers referenced below for details. Impact ===== A remote attacker could possibly execute arbitrary code with the privileges of the process or bypass security restrictions. Workaround ========= There is no known workaround at this time. Resolution ========= All Adobe Flash users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v "> =www-plugins/adobe-flash-24.0.0.221" References ========= [ 1 ] CVE-2017-2925 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2925 [ 2 ] CVE-2017-2926 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2926 [ 3 ] CVE-2017-2927 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2927 [ 4 ] CVE-2017-2928 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2928 [ 5 ] CVE-2017-2930 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2930 [ 6 ] CVE-2017-2931 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2931 [ 7 ] CVE-2017-2932 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2932 [ 8 ] CVE-2017-2933 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2933 [ 9 ] CVE-2017-2934 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2934 [ 10 ] CVE-2017-2935 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2935 [ 11 ] CVE-2017-2936 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2936 [ 12 ] CVE-2017-2937 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2937 [ 13 ] CVE-2017-2938 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2938 [ 14 ] CVE-2017-2982 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2982 [ 15 ] CVE-2017-2984 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2984 [ 16 ] CVE-2017-2985 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2985 [ 17 ] CVE-2017-2986 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2986 [ 18 ] CVE-2017-2987 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2987 [ 19 ] CVE-2017-2988 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2988 [ 20 ] CVE-2017-2990 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2990 [ 21 ] CVE-2017-2991 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2991 [ 22 ] CVE-2017-2992 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2992 [ 23 ] CVE-2017-2993 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2993 [ 24 ] CVE-2017-2994 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2994 [ 25 ] CVE-2017-2995 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2995 [ 26 ] CVE-2017-2996 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-2996 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201702-20 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2017 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Serious flaws identified in Adobe Flash Player pose significant threats for remote code execution. Immediate updates are necessary!. Gentoo Advisory, Adobe Flash Security, Remote Code Threat, Update Adobe Flash. . LinuxSecurity.com Team

Calendar%202 Feb 21, 2017 Gentoo
91

Gentoo: GLSA-202303-14 Normal: Adobe Flash Player Remote Exploit

Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201412-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Adobe Flash Player: Multiple vulnerabilities Date: December 11, 2014 Bugs: #530692, #532074 ID: 201412-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code. Background ========= The Adobe Flash Player is a renderer for the SWF file format, which is commonly used to provide interactive websites. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-plugins/adobe-flash < 11.2.202.425 > = 11.2.202.425 Description ========== Multiple vulnerabilities have been discovered in Adobe Flash Player. Please review the CVE identifiers referenced below for details. Impact ===== A remote attacker could possibly execute arbitrary code with the privileges of the process or bypass security restrictions. Workaround ========= There is no known workaround at this time. Resolution ========= All Adobe Flash Player users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v "> =www-plugins/adobe-flash-11.2.202.425" References ========= [ 1 ] CVE-2014-0580 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0580 [ 2 ] CVE-2014-0587 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0587 [ 3 ] CVE-2014-8439 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-8439 [ 4 ] CVE-2014-8443 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-8443 [ 5 ] CVE-2014-9162 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-9162 [ 6 ] CVE-2014-9163 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-9163 [ 7 ] CVE-2014-9164 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-9164 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201412-07 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2014 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Security flaws in Adobe Flash Player can lead to unauthorized remote code execution; users on Gentoo systems should apply updates promptly.. Adobe Flash Player, Remote Code Execution, Gentoo Security Advisory. . LinuxSecurity.com Team

Calendar%202 Dec 11, 2014 Gentoo
98

Red Hat: RHSA-2013:0941-01 Critical: Adobe Flash Code Execution

An updated Adobe Flash Player package that fixes one security issue is now available for Red Hat Enterprise Linux 5 and 6 Supplementary. The Red Hat Security Response Team has rated this update as having critical [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Critical: flash-plugin security update Advisory ID: RHSA-2013:0941-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://access.redhat.com/errata/RHSA-2013:0941.html Issue date: 2013-06-12 CVE Names: CVE-2013-3343 ==================================================================== 1. Summary: An updated Adobe Flash Player package that fixes one security issue is now available for Red Hat Enterprise Linux 5 and 6 Supplementary. The Red Hat Security Response Team has rated this update as having critical security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop Supplementary (v. 5) - i386, x86_64 Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 5) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, x86_64 3. Description: The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. This update fixes one vulnerability in Adobe Flash Player. This vulnerability is detailed in the Adobe Security bulletin APSB13-16, listed in the References section. Specially-crafted SWF content could cause flash-plugin to crash or, potentially, execute arbitrary code when a victim loads a page containing the malicious SWF content. (CVE-2013-3343) All users of Adobe Flash Player should install this updated package, which upgrades FlashPlayer to version 11.2.202.291. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/articles/11258 5. Bugs fixed (http://bugzilla.redhat.com/): 973404 - CVE-2013-3343 flash-plugin: code execution flaw (APSB13-16) 6. Package List: Red Hat Enterprise Linux Desktop Supplementary (v. 5): i386: flash-plugin-11.2.202.291-1.el5.i386.rpm x86_64: flash-plugin-11.2.202.291-1.el5.i386.rpm Red Hat Enterprise Linux Server Supplementary (v. 5): i386: flash-plugin-11.2.202.291-1.el5.i386.rpm x86_64: flash-plugin-11.2.202.291-1.el5.i386.rpm Red Hat Enterprise Linux Desktop Supplementary (v. 6): i386: flash-plugin-11.2.202.291-1.el6.i686.rpm x86_64: flash-plugin-11.2.202.291-1.el6.i686.rpm Red Hat Enterprise Linux Server Supplementary (v. 6): i386: flash-plugin-11.2.202.291-1.el6.i686.rpm x86_64: flash-plugin-11.2.202.291-1.el6.i686.rpm Red Hat Enterprise Linux Workstation Supplementary (v. 6): i386: flash-plugin-11.2.202.291-1.el6.i686.rpm x86_64: flash-plugin-11.2.202.291-1.el6.i686.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/cve/CVE-2013-3343 https://access.redhat.com/security/updates/classification#critical 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2013 Red Hat, Inc. . Important security patch for flash-plugin resolves an Adobe Flash flaw in CentOS Linux distros.. Red Hat, Flash Update, Security Patch, Adobe Flash, Critical Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 12, 2013 Critical Red Hat
91

Gentoo GLSA 201101-09 Normal: Adobe Flash Player Remote Threats

Multiple vulnerabilities in Adobe Flash Player might allow remote attackers to execute arbitrary code or cause a Denial of Service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201101-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Adobe Flash Player: Multiple vulnerabilities Date: January 21, 2011 Bugs: #307749, #322855, #332205, #337204, #343089 ID: 201101-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities in Adobe Flash Player might allow remote attackers to execute arbitrary code or cause a Denial of Service. Background ========= The Adobe Flash Player is a renderer for the SWF file format, which is commonly used to provide interactive websites. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-plugins/adobe-flash < 10.1.102.64 > = 10.1.102.64 Description ========== Multiple vulnerabilities were discovered in Adobe Flash Player. For further information please consult the CVE entries and the Adobe Security Bulletins referenced below. Impact ===== A remote attacker could entice a user to open a specially crafted SWF file, possibly resulting in the execution of arbitrary code with the privileges of the user running the application, or a Denial of Service. Workaround ========= There is no known workaround at this time. Resolution ========= All Adobe Flash Player users should upgrade to the latest stable version: # emerge --sync # emerge --ask --oneshot --verbose ">=www-plugins/adobe-flash-10.1.102.64" References ========= [ 1 ] APSB10-06 [ 2 ] APSB10-14 [ 3 ] APSB10-16 [ 4 ] APSB10-22 [ 5 ] APSB10-26 [ 6 ] CVE-2008-4546 https://www.cve.org/CVERecord?id=CVE-2008-4546 [ 7 ] CVE-2009-3793 https://www.cve.org/CVERecord?id=CVE-2009-3793 [ 8 ] CVE-2010-0186 https://www.cve.org/CVERecord?id=CVE-2010-0186 [ 9 ] CVE-2010-0187 https://www.cve.org/CVERecord?id=CVE-2010-0187 [ 10 ] CVE-2010-0209 https://www.cve.org/CVERecord?id=CVE-2010-0209 [ 11 ] CVE-2010-1297 https://www.cve.org/CVERecord?id=CVE-2010-1297 [ 12 ] CVE-2010-2160 https://www.cve.org/CVERecord?id=CVE-2010-2160 [ 13 ] CVE-2010-2161 https://www.cve.org/CVERecord?id=CVE-2010-2161 [ 14 ] CVE-2010-2162 https://www.cve.org/CVERecord?id=CVE-2010-2162 [ 15 ] CVE-2010-2163 https://www.cve.org/CVERecord?id=CVE-2010-2163 [ 16 ] CVE-2010-2164 https://www.cve.org/CVERecord?id=CVE-2010-2164 [ 17 ] CVE-2010-2165 https://www.cve.org/CVERecord?id=CVE-2010-2165 [ 18 ] CVE-2010-2166 https://www.cve.org/CVERecord?id=CVE-2010-2166 [ 19 ] CVE-2010-2167 https://www.cve.org/CVERecord?id=CVE-2010-2167 [ 20 ] CVE-2010-2169 https://www.cve.org/CVERecord?id=CVE-2010-2169 [ 21 ] CVE-2010-2170 https://www.cve.org/CVERecord?id=CVE-2010-2170 [ 22 ] CVE-2010-2171 https://www.cve.org/CVERecord?id=CVE-2010-2171 [ 23 ] CVE-2010-2172 https://www.cve.org/CVERecord?id=CVE-2010-2172 [ 24 ] CVE-2010-2173 https://www.cve.org/CVERecord?id=CVE-2010-2173 [ 25 ] CVE-2010-2174 https://www.cve.org/CVERecord?id=CVE-2010-2174 [ 26 ] CVE-2010-2175 https://www.cve.org/CVERecord?id=CVE-2010-2175 [ 27 ] CVE-2010-2176 https://www.cve.org/CVERecord?id=CVE-2010-2176 [ 28 ] CVE-2010-2177 https://www.cve.org/CVERecord?id=CVE-2010-2177 [ 29 ] CVE-2010-2178 https://www.cve.org/CVERecord?id=CVE-2010-2178 [ 30 ] CVE-2010-2179 https://www.cve.org/CVERecord?id=CVE-2010-2179 [ 31 ] CVE-2010-2180 https://www.cve.org/CVERecord?id=CVE-2010-2180 [ 32 ] CVE-2010-2181 https://www.cve.org/CVERecord?id=CVE-2010-2181 [ 33 ] CVE-2010-2182 https://www.cve.org/CVERecord?id=CVE-2010-2182 [ 34 ] CVE-2010-2183 https://www.cve.org/CVERecord?id=CVE-2010-2183 [ 35 ] CVE-2010-2184 https://www.cve.org/CVERecord?id=CVE-2010-2184 [ 36 ] CVE-2010-2185 https://www.cve.org/CVERecord?id=CVE-2010-2185 [ 37 ] CVE-2010-2186 https://www.cve.org/CVERecord?id=CVE-2010-2186 [ 38 ] CVE-2010-2187 https://www.cve.org/CVERecord?id=CVE-2010-2187 [ 39 ] CVE-2010-2188 https://www.cve.org/CVERecord?id=CVE-2010-2188 [ 40 ] CVE-2010-2189 https://www.cve.org/CVERecord?id=CVE-2010-2189 [ 41 ] CVE-2010-2213 https://www.cve.org/CVERecord?id=CVE-2010-2213 [ 42 ] CVE-2010-2214 https://www.cve.org/CVERecord?id=CVE-2010-2214 [ 43 ] CVE-2010-2215 https://www.cve.org/CVERecord?id=CVE-2010-2215 [ 44 ] CVE-2010-2216 https://www.cve.org/CVERecord?id=CVE-2010-2216 [ 45 ] CVE-2010-2884 https://www.cve.org/CVERecord?id=CVE-2010-2884 [ 46 ] CVE-2010-3636 https://www.cve.org/CVERecord?id=CVE-2010-3636 [ 47 ] CVE-2010-3639 https://www.cve.org/CVERecord?id=CVE-2010-3639 [ 48 ] CVE-2010-3640 https://www.cve.org/CVERecord?id=CVE-2010-3640 [ 49 ] CVE-2010-3641 https://www.cve.org/CVERecord?id=CVE-2010-3641 [ 50 ] CVE-2010-3642 https://www.cve.org/CVERecord?id=CVE-2010-3642 [ 51 ] CVE-2010-3643 https://www.cve.org/CVERecord?id=CVE-2010-3643 [ 52 ] CVE-2010-3644 https://www.cve.org/CVERecord?id=CVE-2010-3644 [ 53 ] CVE-2010-3645 https://www.cve.org/CVERecord?id=CVE-2010-3645 [ 54 ] CVE-2010-3646 https://www.cve.org/CVERecord?id=CVE-2010-3646 [ 55 ] CVE-2010-3647 https://www.cve.org/CVERecord?id=CVE-2010-3647 [ 56 ] CVE-2010-3648 https://www.cve.org/CVERecord?id=CVE-2010-3648 [ 57 ] CVE-2010-3649 https://www.cve.org/CVERecord?id=CVE-2010-3649 [ 58 ] CVE-2010-3650 https://www.cve.org/CVERecord?id=CVE-2010-3650 [ 59 ] CVE-2010-3652 https://www.cve.org/CVERecord?id=CVE-2010-3652 [ 60 ] CVE-2010-3654 https://www.cve.org/CVERecord?id=CVE-2010-3654 [ 61 ] CVE-2010-3976 https://www.cve.org/CVERecord?id=CVE-2010-3976 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201101-09 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2011 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . The use of Adobe Flash Player on Gentoo systems presents numerous security risks, potentially resulting in unauthorized remote code execution and disruptions of service.. Adobe Flash Security,Gentoo Flash Advisory,Remote Code Execution,Denial of Service Risks. . LinuxSecurity.com Team

Calendar%202 Jan 21, 2011 Gentoo
98

RedHat RHEL 5: RHSA-2010-0102-01 Critical Flash Plugin Update

An updated Adobe Flash Player package that fixes two security issues is now available for Red Hat Enterprise Linux 5 Supplementary. This update has been rated as having important security impact by the Red Hat Security Response Team.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: flash-plugin security update Advisory ID: RHSA-2010:0102-01 Product: Red Hat Enterprise Linux Extras Advisory URL: https://access.redhat.com/errata/RHSA-2010:0102.html Issue date: 2010-02-12 CVE Names: CVE-2010-0186 CVE-2010-0187 ==================================================================== 1. Summary: An updated Adobe Flash Player package that fixes two security issues is now available for Red Hat Enterprise Linux 5 Supplementary. This update has been rated as having important security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: RHEL Desktop Supplementary (v. 5 client) - i386, x86_64 RHEL Supplementary (v. 5 server) - i386, x86_64 3. Description: The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. This update fixes two vulnerabilities in Adobe Flash Player. These vulnerabilities are summarized on the Adobe Security Advisory APSB10-06 page listed in the References section. If a victim loaded a web page containing specially-crafted SWF content, it could cause Flash Player to perform unauthorized cross-domain requests, leading to the disclosure of sensitive data. (CVE-2010-0186, CVE-2010-0187) All users of Adobe Flash Player should install this updated package, which upgrades Flash Player to version 10.0.45.2. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update areavailable at 5. Bugs fixed (http://bugzilla.redhat.com/): 563819 - CVE-2010-0186 flash-plugin: unauthorized cross-domain requests (APSB10-06) 564287 - CVE-2010-0187 flash-plugin: possible player crash (APSB10-06) 6. Package List: RHEL Desktop Supplementary (v. 5 client): i386: flash-plugin-10.0.45.2-1.el5.i386.rpm x86_64: flash-plugin-10.0.45.2-1.el5.i386.rpm RHEL Supplementary (v. 5 server): i386: flash-plugin-10.0.45.2-1.el5.i386.rpm x86_64: flash-plugin-10.0.45.2-1.el5.i386.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/cve/CVE-2010-0186 https://access.redhat.com/security/cve/CVE-2010-0187 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2010 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFLdYE+XlSAg2UNWIIRAsL4AJkB2m7gjB+gxxFQ9WRKz7RTSE4NHgCgkn/q HMgQlRzQ/G20AGJj8nxzX4Q=31YX -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . An important patch for Adobe Flash on Red Hat Enterprise Linux addresses significant vulnerabilities. Update now to protect your confidential information.. Adobe Flash Player, Red Hat Advisory, Security Patch, Flash Plugin, Linux Security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 12, 2010 Important Red Hat
91

Gentoo GLSA-200908-04 Normal: Adobe Reader And Flash Remote Code Exec

Multiple vulnerabilities in Adobe Reader and Adobe Flash Player allow for attacks including the remote execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200908-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Adobe products: Multiple vulnerabilities Date: August 07, 2009 Bugs: #278813, #278819 ID: 200908-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities in Adobe Reader and Adobe Flash Player allow for attacks including the remote execution of arbitrary code. Background ========= Adobe Flash Player is a closed-source playback software for Flash SWF files. Adobe Reader is a closed-source PDF reader that plays Flash content as well. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-plugins/adobe-flash < 10.0.32.18 > = 10.0.32.18 2 app-text/acroread < 9.1.3 > = 9.1.3 ------------------------------------------------------------------- 2 affected packages on all of their supported architectures. ------------------------------------------------------------------- Description ========== Multiple vulnerabilities have been reported in Adobe Flash Player: * lakehu of Tencent Security Center reported an unspecified memory corruption vulnerability (CVE-2009-1862). * Mike Wroe reported an unspecified vulnerability, related to "privilege escalation" (CVE-2009-1863). * An anonymous researcher through iDefense reported an unspecified heap-based bufferoverflow (CVE-2009-1864). * Chen Chen of Venustech reported an unspecified "null pointer vulnerability" (CVE-2009-1865). * Chen Chen of Venustech reported an unspecified stack-based buffer overflow (CVE-2009-1866). * Joran Benker reported that Adobe Flash Player facilitates "clickjacking" attacks (CVE-2009-1867). * Jun Mao of iDefense reported a heap-based buffer overflow, related to URL parsing (CVE-2009-1868). * Roee Hay of IBM Rational Application Security reported an unspecified integer overflow (CVE-2009-1869). * Gareth Heyes and Microsoft Vulnerability Research reported that the sandbox in Adobe Flash Player allows for information disclosure, when "SWFs are saved to the hard drive" (CVE-2009-1870). Impact ===== A remote attacker could entice a user to open a specially crafted PDF file or web site containing Adobe Flash (SWF) contents, possibly resulting in the execution of arbitrary code with the privileges of the user running the application, or a Denial of Service (application crash). Furthermore, a remote attacker could trick a user into clicking a button on a dialog by supplying a specially crafted SWF file and disclose sensitive information by exploiting a sandbox issue. Workaround ========= There is no known workaround at this time. Resolution ========= All Adobe Flash Player users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v "> =www-plugins/adobe-flash-10.0.32.18" All Adobe Reader users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-text/acroread-9.1.3" References ========= [ 1 ] CVE-2009-1862 https://www.cve.org/CVERecord?id=CVE-2009-1862 [ 2 ] CVE-2009-1863 https://www.cve.org/CVERecord?id=CVE-2009-1863 [ 3 ] CVE-2009-1864 https://www.cve.org/CVERecord?id=CVE-2009-1864 [ 4 ] CVE-2009-1865 https://www.cve.org/CVERecord?id=CVE-2009-1865 [ 5 ] CVE-2009-1866 https://www.cve.org/CVERecord?id=CVE-2009-1866 [ 6 ]CVE-2009-1867 https://www.cve.org/CVERecord?id=CVE-2009-1867 [ 7 ] CVE-2009-1868 https://www.cve.org/CVERecord?id=CVE-2009-1868 [ 8 ] CVE-2009-1869 https://www.cve.org/CVERecord?id=CVE-2009-1869 [ 9 ] CVE-2009-1870 https://www.cve.org/CVERecord?id=CVE-2009-1870 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200908-04 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2009 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Numerous security flaws in Adobe Acrobat and Flash Player enable unauthorized code execution, highlighting the need for updates to ensure protection.. Adobe Reader, Adobe Flash, security advisory, remote exploit, code execution. . LinuxSecurity.com Team

Calendar%202 Aug 07, 2009 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200