Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Critical: flash-plugin security update Advisory ID: RHSA-2020:2547-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://access.redhat.com/errata/RHSA-2020:2547 Issue date: 2020-06-15 CVE Names: CVE-2020-9633 ==================================================================== 1. Summary: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, x86_64 3. Description: The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. This update upgrades Flash Player to version 32.0.0.387. Security Fix(es): * flash-plugin: Arbitrary Code Execution vulnerability (APSB20-30) (CVE-2020-9633) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed(https://bugzilla.redhat.com/): 1845700 - CVE-2020-9633 flash-plugin: Arbitrary Code Execution vulnerability (APSB20-30) 6. Package List: Red Hat Enterprise Linux Desktop Supplementary (v. 6): i386: flash-plugin-32.0.0.387-1.el6_10.i686.rpm x86_64: flash-plugin-32.0.0.387-1.el6_10.i686.rpm Red Hat Enterprise Linux Server Supplementary (v. 6): i386: flash-plugin-32.0.0.387-1.el6_10.i686.rpm x86_64: flash-plugin-32.0.0.387-1.el6_10.i686.rpm Red Hat Enterprise Linux Workstation Supplementary (v. 6): i386: flash-plugin-32.0.0.387-1.el6_10.i686.rpm x86_64: flash-plugin-32.0.0.387-1.el6_10.i686.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2020-9633 https://access.redhat.com/security/updates/classification#critical 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXudv0dzjgjWX9erEAQhuEQ//U1Tl4Hqd37/cbfxWxhyxNHIb0MBGhmGR Cs22UFqTAEirDi9T6ubNJ7+iAmsrUh5l8Q7uSRx9w0eUIRoYvHcYCHhEZjQXGAgR X/imZUS3URP9SuejO8OYSdK3ySw/SEGJHCKIAIm05yxdWJSKmB4WfiECyoOzpty6 BYhPKzOmP04sHHzjSnh85PO/Sb2gzw9BS0bb+BFFn2ZiJg3NEVnpue1RHYRr6vra lDoEDoKRlsWnUiUKfYsDcNABIQ13rUNFYA8K/MMnZmE+Z/h8X0vOpkEKW1czyh5E 2LCTIaxNW3vT8/sxg0yBenVe8Nb+7mmdZDNw5Oabu/E5DSpLr3t3vvF/c6YNnb2l e5XrDb0hZk2+YAZxEqN3976izpzVWx/iETBbN4yNwL9XfKicgzNUKxxy8p47/ZeO 0Klh5Xoman2dPex8dl0QFCotDDKhBA+VOc02IueWF1bNGbDXPvRla5wEUpy1nC21 oHzlMAVeJN5prTEbkKe+pAAk20xU3877ltdNkz4zhltArp+hIdunc80LSQx+E0dR 2gZZB8LZ01dELe9/cVLLeNqcNoc4JlZuP+i900cIcWyZH9YdHgGPOFh3ZA8T7Fyw muWdOSyXH31s1K2nxMg1d3twdOk7p4CaHoVltBiSb6q0zYL3PEbkUtoCj41rZXug WEhggb1lqQg=H8Xz -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: flash-plugin security update Advisory ID: RHSA-2018:3618-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://access.redhat.com/errata/RHSA-2018:3618 Issue date: 2018-11-14 CVE Names: CVE-2018-15978 ==================================================================== 1. Summary: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, x86_64 3. Description: The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. This update upgrades Flash Player to version 31.0.0.148. Security Fix(es): * flash-plugin: Information Disclosure vulnerability (APSB18-39) (CVE-2018-15978) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed(https://bugzilla.redhat.com/): 1649537 - CVE-2018-15978 flash-plugin: Information Disclosure vulnerability (APSB18-39) 6. Package List: Red Hat Enterprise Linux Desktop Supplementary (v. 6): i386: flash-plugin-31.0.0.148-1.el6_10.i686.rpm x86_64: flash-plugin-31.0.0.148-1.el6_10.i686.rpm Red Hat Enterprise Linux Server Supplementary (v. 6): i386: flash-plugin-31.0.0.148-1.el6_10.i686.rpm x86_64: flash-plugin-31.0.0.148-1.el6_10.i686.rpm Red Hat Enterprise Linux Workstation Supplementary (v. 6): i386: flash-plugin-31.0.0.148-1.el6_10.i686.rpm x86_64: flash-plugin-31.0.0.148-1.el6_10.i686.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2018-15978 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2018 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBW+x6VNzjgjWX9erEAQgvTRAAkzadx1pCzgXnkfdK0FjMs2UXfIWAvJ6w Oy8y6fxk/Uk3awgUhW/cEDGD6kXSygOr35FQGtCstiSnfRBucDyuFCHeG0b13fPx WuA100Iik9ufv681zBhXhfCjP1TDZ5Gmnqg1fxLjDqNmjEGO5TATHY8AVt45+YjS 0I/ovd8hUkWW7x7jotsWhGwqo8FFiYGTdd39OYKBfRZD5o/W6gkPWevA4aslarBu j/0AFH5B/xRUdwcpAXh/Cw3GIkEmn5cKEWEt7zW93hwac9ACdH+tEv2QdVCyX5uy BUXEn19IKGvXI/UjFhOdn/J7EkLsHmu8jp4KIQXJFHZy4JinKK4Wb/1aqR8hSiaP 2MYqe86dY1dPccOiEFitcCi9U/M4TdBQfc2/HzdgMD6OCLYq+TWF0E98A/mXitam Lrr4vS5EZwHUw/tKrN3B+mTJSMs3PqJOPYTf6nJpD3pUV70cYMrwY4Y13GdfXctA jqvrPX1fu15BCiHVPA1ymweV+yCCKnW+3Nnyp695adT1OS701NUJ+sSuwn+vJKPB 1LS5Ilve5B2VCCzwwd82uLkZTgFRqN9cjI2uEPxaSo5yT4skZEYA9Th7rRZZD4uF IaJkR2lv9Q/jsm2aSRUr4z8IUcwoR92+ITyPYAfj/CJk+uFIxFqLnR2R20ZaPEXp d+meD702JzM=U3sY -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: flash-plugin security update Advisory ID: RHSA-2018:2435-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://access.redhat.com/errata/RHSA-2018:2435 Issue date: 2018-08-15 CVE Names: CVE-2018-12824 CVE-2018-12825 CVE-2018-12826 CVE-2018-12827 CVE-2018-12828 ==================================================================== 1. Summary: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, x86_64 3. Description: The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. This update upgrades Flash Player to version 30.0.0.154. Security Fix(es): * flash-plugin: Information Disclosure vulnerabilities (APSB18-25) (CVE-2018-12824, CVE-2018-12826, CVE-2018-12827) * flash-plugin: Security Mitigation Bypass vulnerability (APSB18-25) (CVE-2018-12825) * flash-plugin: Privilege Escalation vulnerability (APSB18-25) (CVE-2018-12828) For more details about the security issue(s), including the impact, a CVSS score, and other relatedinformation, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1616026 - CVE-2018-12824 CVE-2018-12826 CVE-2018-12827 flash-plugin: Information Disclosure vulnerabilities (APSB18-25) 1616027 - CVE-2018-12828 flash-plugin: Privilege Escalation vulnerability (APSB18-25) 1616028 - CVE-2018-12825 flash-plugin: Security Mitigation Bypass vulnerability (APSB18-25) 6. Package List: Red Hat Enterprise Linux Desktop Supplementary (v. 6): i386: flash-plugin-30.0.0.154-1.el6_10.i686.rpm x86_64: flash-plugin-30.0.0.154-1.el6_10.i686.rpm Red Hat Enterprise Linux Server Supplementary (v. 6): i386: flash-plugin-30.0.0.154-1.el6_10.i686.rpm x86_64: flash-plugin-30.0.0.154-1.el6_10.i686.rpm Red Hat Enterprise Linux Workstation Supplementary (v. 6): i386: flash-plugin-30.0.0.154-1.el6_10.i686.rpm x86_64: flash-plugin-30.0.0.154-1.el6_10.i686.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2018-12824 https://access.redhat.com/security/cve/CVE-2018-12825 https://access.redhat.com/security/cve/CVE-2018-12826 https://access.redhat.com/security/cve/CVE-2018-12827 https://access.redhat.com/security/cve/CVE-2018-12828 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2018 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBW3SNFNzjgjWX9erEAQh2vg/+MaMaB2ZNBXY8rJGfjJo56+fxL6nC0DdJ 0RUB0yuJ/xsUVU5+uM67n4gm3pqgt+6chGVT1q8N0P2E6kDywPGJ12tbnou4i0C8 QRreEjunbW4aYGFOMs1eEvryRO5Na+SfT+aqkvEwGSa/64L1j78B35G7J9b5U6v/ HHROM0+Z3D3nAJQZsK82C6E2x/PO+rnXLixDeHJJERWicY0mIa98gZo5nfGiKZpP wtFFdptI8qVDkMhsKluFw/Vm5QeWgrzVNZCjRnYYRO6NQ8nlfAQ1KETD9m8/OdkG 1HYuU3AEW5agKDQGt+xysmTtyZHQqA/xCnKHQ2SsyyVru46Olq7+ac4YAMMJbmAC jAVCs3IwQkzU6qxFzG21fk3I2KAYnUi2WJEZLTLD+SubD4kZGRNIy0tKLEIxxT3f qqpnL7S9eZoRNCbXyDcYJQu5vqAm86nK4h0MF7+w+yARnIZBe+w8WiP7tmA6lK+R gwa82wh12Zno7SydWxkZq29fF0vGULb7T9aByJk4BJTwbmEGZcgZJdJFqhbpI+CY NhSmjublU6qBtk+CZDPw7Z71Dm5wHX+PoOUaD+5EKG6b6FwFc7AGdR3xOfjxJPtW C9qUfYXl5kTdJNdUSm+7aTF2yktyTQcfRO2Hxtlr6SaFqG81DMKiGqQ01+qbHHQD m1o//4d12M4=x2ph -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Critical: flash-plugin security update Advisory ID: RHSA-2017:2899-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://access.redhat.com/errata/RHSA-2017:2899 Issue date: 2017-10-17 CVE Names: CVE-2017-11292 ==================================================================== 1. Summary: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, x86_64 3. Description: The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. This update upgrades Flash Player to version 27.0.0.170. Security Fix(es): * This update fixes one vulnerability in Adobe Flash Player. This vulnerability, detailed in the Adobe Security Bulletin listed in the References section, could allow an attacker to create a specially crafted SWF file that would cause flash-plugin to crash, execute arbitrary code, or disclose sensitive information when the victim loaded a page containing the malicious SWF content. (CVE-2017-11292) 4. Solution: For details on how to apply this update, whichincludes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1502726 - CVE-2017-11292 flash-plugin: remote code execution vulnerability (APSB17-32) 6. Package List: Red Hat Enterprise Linux Desktop Supplementary (v. 6): i386: flash-plugin-27.0.0.170-1.el6_9.i686.rpm x86_64: flash-plugin-27.0.0.170-1.el6_9.i686.rpm Red Hat Enterprise Linux Server Supplementary (v. 6): i386: flash-plugin-27.0.0.170-1.el6_9.i686.rpm x86_64: flash-plugin-27.0.0.170-1.el6_9.i686.rpm Red Hat Enterprise Linux Workstation Supplementary (v. 6): i386: flash-plugin-27.0.0.170-1.el6_9.i686.rpm x86_64: flash-plugin-27.0.0.170-1.el6_9.i686.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2017-11292 https://access.redhat.com/security/updates/classification#critical 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2017 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFZ5d19XlSAg2UNWIIRAmWQAKCeLL6irBg9hEDWZmPeXVCc/gUO0wCdFqqA TiI8nRIwtzd2pnyGIOgmvBA=r2XO -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Critical: flash-plugin security update Advisory ID: RHSA-2017:1219-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://access.redhat.com/errata/RHSA-2017:1219 Issue date: 2017-05-09 CVE Names: CVE-2017-3068 CVE-2017-3069 CVE-2017-3070 CVE-2017-3071 CVE-2017-3072 CVE-2017-3073 CVE-2017-3074 ==================================================================== 1. Summary: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, x86_64 3. Description: The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. This update upgrades Flash Player to version 25.0.0.171. Security Fix(es): * This update fixes multiple vulnerabilities in Adobe Flash Player. These vulnerabilities, detailed in the Adobe Security Bulletin listed in the References section, could allow an attacker to create a specially crafted SWF file that would cause flash-plugin to crash, execute arbitrary code, or disclose sensitive information when the victimloaded a page containing the malicious SWF content. (CVE-2017-3068, CVE-2017-3069, CVE-2017-3070, CVE-2017-3071, CVE-2017-3072, CVE-2017-3073, CVE-2017-3074) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1449340 - CVE-2017-3068 CVE-2017-3069 CVE-2017-3070 CVE-2017-3071 CVE-2017-3072 CVE-2017-3073 CVE-2017-3074 flash-plugin: multiple code execution issues fixed in APSB17-15 6. Package List: Red Hat Enterprise Linux Desktop Supplementary (v. 6): i386: flash-plugin-25.0.0.171-1.el6_9.i686.rpm x86_64: flash-plugin-25.0.0.171-1.el6_9.i686.rpm Red Hat Enterprise Linux Server Supplementary (v. 6): i386: flash-plugin-25.0.0.171-1.el6_9.i686.rpm x86_64: flash-plugin-25.0.0.171-1.el6_9.i686.rpm Red Hat Enterprise Linux Workstation Supplementary (v. 6): i386: flash-plugin-25.0.0.171-1.el6_9.i686.rpm x86_64: flash-plugin-25.0.0.171-1.el6_9.i686.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2017-3068 https://access.redhat.com/security/cve/CVE-2017-3069 https://access.redhat.com/security/cve/CVE-2017-3070 https://access.redhat.com/security/cve/CVE-2017-3071 https://access.redhat.com/security/cve/CVE-2017-3072 https://access.redhat.com/security/cve/CVE-2017-3073 https://access.redhat.com/security/cve/CVE-2017-3074 https://access.redhat.com/security/updates/classification#critical 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2017 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFZEiw3XlSAg2UNWIIRAhaeAJ4mcuUFYqalURuxtRIkDAj18bhKngCdEmXc RbVXnEIBVk91J3+sVOK5H5c=PsAM -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
The package flashplugin before version 25.0.0.127-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure. . Arch Linux Security Advisory ASA-201703-11 ========================================= Severity: Critical Date : 2017-03-15 CVE-ID : CVE-2017-2997 CVE-2017-2998 CVE-2017-2999 CVE-2017-3000 CVE-2017-3001 CVE-2017-3002 CVE-2017-3003 Package : flashplugin Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-208 Summary ====== The package flashplugin before version 25.0.0.127-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure. Resolution ========= Upgrade to 25.0.0.127-1. # pacman -Syu "flashplugin> =25.0.0.127-1" The problems have been fixed upstream in version 25.0.0.127. Workaround ========= None. Description ========== - CVE-2017-2997 (arbitrary code execution) A buffer overflow vulnerability that could lead to code execution has been found in Adobe Flash Player
An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Critical: flash-plugin security update Advisory ID: RHSA-2017:0057-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://access.redhat.com/errata/RHSA-2017:0057.html Issue date: 2017-01-11 CVE Names: CVE-2017-2925 CVE-2017-2926 CVE-2017-2927 CVE-2017-2928 CVE-2017-2930 CVE-2017-2931 CVE-2017-2932 CVE-2017-2933 CVE-2017-2934 CVE-2017-2935 CVE-2017-2936 CVE-2017-2937 CVE-2017-2938 ==================================================================== 1. Summary: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, x86_64 3. Description: The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. This update upgrades Flash Player to version 24.0.0.194. Security Fix(es): * This update fixes multiple vulnerabilities in Adobe Flash Player. These vulnerabilities, detailed in the Adobe Security Bulletin listed in the References section, could allow an attacker to create a speciallycrafted SWF file that would cause flash-plugin to crash, execute arbitrary code, or disclose sensitive information when the victim loaded a page containing the malicious SWF content. (CVE-2017-2925, CVE-2017-2926, CVE-2017-2927, CVE-2017-2928, CVE-2017-2930, CVE-2017-2931, CVE-2017-2932, CVE-2017-2933, CVE-2017-2934, CVE-2017-2935, CVE-2017-2936, CVE-2017-2937, CVE-2017-2938) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1411929 - CVE-2017-2925 CVE-2017-2926 CVE-2017-2927 CVE-2017-2928 CVE-2017-2930 CVE-2017-2931 CVE-2017-2932 CVE-2017-2933 CVE-2017-2934 CVE-2017-2935 CVE-2017-2936 CVE-2017-2937 CVE-2017-2938 flash-plugin: multiple code execution issues fixed in APSB17-02 6. Package List: Red Hat Enterprise Linux Desktop Supplementary (v. 6): i386: flash-plugin-24.0.0.194-1.el6_8.i686.rpm x86_64: flash-plugin-24.0.0.194-1.el6_8.i686.rpm Red Hat Enterprise Linux Server Supplementary (v. 6): i386: flash-plugin-24.0.0.194-1.el6_8.i686.rpm x86_64: flash-plugin-24.0.0.194-1.el6_8.i686.rpm Red Hat Enterprise Linux Workstation Supplementary (v. 6): i386: flash-plugin-24.0.0.194-1.el6_8.i686.rpm x86_64: flash-plugin-24.0.0.194-1.el6_8.i686.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7.References: https://access.redhat.com/security/cve/CVE-2017-2925 https://access.redhat.com/security/cve/CVE-2017-2926 https://access.redhat.com/security/cve/CVE-2017-2927 https://access.redhat.com/security/cve/CVE-2017-2928 https://access.redhat.com/security/cve/CVE-2017-2930 https://access.redhat.com/security/cve/CVE-2017-2931 https://access.redhat.com/security/cve/CVE-2017-2932 https://access.redhat.com/security/cve/CVE-2017-2933 https://access.redhat.com/security/cve/CVE-2017-2934 https://access.redhat.com/security/cve/CVE-2017-2935 https://access.redhat.com/security/cve/CVE-2017-2936 https://access.redhat.com/security/cve/CVE-2017-2937 https://access.redhat.com/security/cve/CVE-2017-2938 https://access.redhat.com/security/updates/classification/#critical 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2017 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFYdfJ/XlSAg2UNWIIRAsNHAKCrlcYaBmSYZ/8vlx3tDvSILA9GygCeJKZQ KfSBeTmt1CjZsJdMAGUad/0=RlPf -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
An update for flash-plugin is now available for Red Hat Enterprise Linux 5 Supplementary and Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Critical: flash-plugin security update Advisory ID: RHSA-2016:2057-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://access.redhat.com/errata/RHSA-2016:2057.html Issue date: 2016-10-12 CVE Names: CVE-2016-4273 CVE-2016-4286 CVE-2016-6981 CVE-2016-6982 CVE-2016-6983 CVE-2016-6984 CVE-2016-6985 CVE-2016-6986 CVE-2016-6987 CVE-2016-6989 CVE-2016-6990 CVE-2016-6992 ==================================================================== 1. Summary: An update for flash-plugin is now available for Red Hat Enterprise Linux 5 Supplementary and Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop Supplementary (v. 5) - i386, x86_64 Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 5) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, x86_64 3. Description: The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. This update upgrades Flash Player to version 11.2.202.637. Security Fix(es): * This update fixesmultiple vulnerabilities in Adobe Flash Player. These vulnerabilities, detailed in the Adobe Security Bulletin listed in the References section, could allow an attacker to create a specially crafted SWF file that would cause flash-plugin to crash, execute arbitrary code, or disclose sensitive information when the victim loaded a page containing the malicious SWF content. (CVE-2016-4273, CVE-2016-4286, CVE-2016-6981, CVE-2016-6982, CVE-2016-6983, CVE-2016-6984, CVE-2016-6985, CVE-2016-6986, CVE-2016-6987, CVE-2016-6989, CVE-2016-6990, CVE-2016-6992) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1383931 - CVE-2016-4273 CVE-2016-4286 CVE-2016-6981 CVE-2016-6982 CVE-2016-6983 CVE-2016-6984 CVE-2016-6985 CVE-2016-6986 CVE-2016-6987 CVE-2016-6989 CVE-2016-6990 CVE-2016-6992 flash-plugin: multiple code execution issues fixed in APSB16-32 6. Package List: Red Hat Enterprise Linux Desktop Supplementary (v. 5): i386: flash-plugin-11.2.202.637-1.el5_11.i386.rpm x86_64: flash-plugin-11.2.202.637-1.el5_11.i386.rpm Red Hat Enterprise Linux Server Supplementary (v. 5): i386: flash-plugin-11.2.202.637-1.el5_11.i386.rpm x86_64: flash-plugin-11.2.202.637-1.el5_11.i386.rpm Red Hat Enterprise Linux Desktop Supplementary (v. 6): i386: flash-plugin-11.2.202.637-1.el6_8.i686.rpm x86_64: flash-plugin-11.2.202.637-1.el6_8.i686.rpm Red Hat Enterprise Linux Server Supplementary (v. 6): i386: flash-plugin-11.2.202.637-1.el6_8.i686.rpm x86_64: flash-plugin-11.2.202.637-1.el6_8.i686.rpm Red Hat Enterprise Linux Workstation Supplementary (v. 6): i386: flash-plugin-11.2.202.637-1.el6_8.i686.rpm x86_64: flash-plugin-11.2.202.637-1.el6_8.i686.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7.References: https://access.redhat.com/security/cve/CVE-2016-4273 https://access.redhat.com/security/cve/CVE-2016-4286 https://access.redhat.com/security/cve/CVE-2016-6981 https://access.redhat.com/security/cve/CVE-2016-6982 https://access.redhat.com/security/cve/CVE-2016-6983 https://access.redhat.com/security/cve/CVE-2016-6984 https://access.redhat.com/security/cve/CVE-2016-6985 https://access.redhat.com/security/cve/CVE-2016-6986 https://access.redhat.com/security/cve/CVE-2016-6987 https://access.redhat.com/security/cve/CVE-2016-6989 https://access.redhat.com/security/cve/CVE-2016-6990 https://access.redhat.com/security/cve/CVE-2016-6992 https://access.redhat.com/security/updates/classification#critical 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2016 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFX/n7xXlSAg2UNWIIRAsVXAJwL/4ZCoClD7cAvqvPN13L7ccpYNQCgogk5 6UAFhMbkHmPLVjTeEA1eCe8=qe9H -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
Get the latest Linux and open source security news straight to your inbox.