Bugzilla – Full Text Bug Listing |
Summary: | VUL-0: EMU: flash-player: december 13 release (APSB16-39) | ||
---|---|---|---|
Product: | [Novell Products] SUSE Security Incidents | Reporter: | Marcus Meissner <meissner> |
Component: | Incidents | Assignee: | Security Team bot <security-team> |
Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
Severity: | Normal | ||
Priority: | P5 - None | CC: | astieger, sbrabec, simonf.lees |
Version: | unspecified | ||
Target Milestone: | --- | ||
Hardware: | Other | ||
OS: | Other | ||
Whiteboard: | |||
Found By: | --- | Services Priority: | |
Business Priority: | Blocker: | --- | |
Marketing QA Status: | --- | IT Deployment: | --- |
Description
Marcus Meissner
2016-12-13 16:32:30 UTC
The fix for Linux is to go to 24.0.0.186, a major version jump. I just inspected the update. The new update lacks the standalone player. Or exactly: Adobe stopped to offer standalone player many years ago, but they continued to put new versions in URL https://fpdownload.macromedia.com/pub/flashplayer/updaters/11/flashplayer_11_sa.i386.tar.gz. It was i386 only, x86_64 stopped being updated in 2011. I tried some guesses of the new URL. All failed. To not break existing setup, I'll keep the old insecure flashplayer binary version 11, exactly as we did for x86_64. Done. I adapted update.sh, verified dlopen()ed dependencies, and modified spec file to match the new names. I also found a new version of the EULA, so I updated it as well. SLE 12: https://build.suse.de/request/show/125446 openSUSE 13.2: https://build.opensuse.org/request/show/445647 Packages were not tested yet. Update released reassigning to security SUSE-SU-2016:3148-1: An update that fixes 17 vulnerabilities is now available. Category: security (critical) Bug References: 1015379 CVE References: CVE-2016-7867,CVE-2016-7868,CVE-2016-7869,CVE-2016-7870,CVE-2016-7871,CVE-2016-7872,CVE-2016-7873,CVE-2016-7874,CVE-2016-7875,CVE-2016-7876,CVE-2016-7877,CVE-2016-7878,CVE-2016-7879,CVE-2016-7880,CVE-2016-7881,CVE-2016-7890,CVE-2016-7892 Sources used: SUSE Linux Enterprise Workstation Extension 12-SP1 (src): flash-player-24.0.0.186-152.1 SUSE Linux Enterprise Desktop 12-SP1 (src): flash-player-24.0.0.186-152.1 release 13.2 openSUSE-SU-2016:3160-1: An update that fixes 17 vulnerabilities is now available. Category: security (moderate) Bug References: 1015379 CVE References: CVE-2016-7867,CVE-2016-7868,CVE-2016-7869,CVE-2016-7870,CVE-2016-7871,CVE-2016-7872,CVE-2016-7873,CVE-2016-7874,CVE-2016-7875,CVE-2016-7876,CVE-2016-7877,CVE-2016-7878,CVE-2016-7879,CVE-2016-7880,CVE-2016-7881,CVE-2016-7890,CVE-2016-7892 Sources used: openSUSE 13.2 NonFree (src): flash-player-24.0.0.186-2.121.1 |