Bug 788450 - VUL-0: flash-player: 11.2.202.251
VUL-0: flash-player: 11.2.202.251
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Major
: ---
Assigned To: Security Team bot
Security Team bot
maint:released:sle10-sp4:50005
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2012-11-06 22:24 UTC by Marcus Meissner
Modified: 2013-02-28 17:27 UTC (History)
1 user (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2012-11-06 22:24:06 UTC
flash player was updated to 11.2.202.251 apparentky

https://www.adobe.com/support/security/bulletins/apsb12-24.html

Release date: November 6, 2012

Vulnerability identifier: APSB12-24

Priority: See table below

CVE number: CVE-2012-5274, CVE-2012-5275, CVE-2012-5276, CVE-2012-5277, CVE-2012-5278, CVE-2012-5279, CVE-2012-5280

Platform: All Platforms
Summary

Adobe has released security updates for Adobe Flash Player 11.4.402.287 and earlier versions for Windows and Macintosh, Adobe Flash Player 11.2.202.243 and earlier versions for Linux, Adobe Flash Player 11.1.115.20 and earlier versions for Android 4.x, and Adobe Flash Player 11.1.111.19 and earlier versions for Android 3.x and 2.x. These updates address vulnerabilities that could cause a crash and potentially allow an attacker to take control of the affected system.

Adobe recommends users update their product installations to the latest versions:

    Users of Adobe Flash Player 11.4.402.287 and earlier versions for Windows and Macintosh should update to Adobe Flash Player 11.5.502.110.
    Users of Adobe Flash Player 11.2.202.243 and earlier versions for Linux should update to Adobe Flash Player 11.2.202.251.
    Flash Player installed with Google Chrome will automatically be updated to the latest Google Chrome version, which will include Adobe Flash Player 11.5.31.2 for Windows, Macintosh and Linux.
    Flash Player installed with Internet Explorer 10 will automatically be updated to the latest Internet Explorer 10 version, which will include Adobe Flash Player 11.3.376.12 for Windows.
    Users of Adobe Flash Player 11.1.115.20 and earlier versions on Android 4.x devices should update to Adobe Flash Player 11.1.115.27.
    Users of Adobe Flash Player 11.1.111.19 and earlier versions for Android 3.x and earlier versions should update to Flash Player 11.1.111.24.
    Users of Adobe AIR 3.4.0.2710 and earlier versions for Windows and Macintosh, SDK (including AIR for iOS) and Android should update to Adobe AIR 3.5.0.600.

Affected software versions

    Adobe Flash Player 11.4.402.287 and earlier versions for Windows and Macintosh
    Adobe Flash Player 11.2.202.243 and earlier versions for Linux
    Adobe Flash Player 11.1.115.20 and earlier versions for Android 4.x
    Adobe Flash Player 11.1.111.19 and earlier versions for Android 3.x and 2.x
    Adobe AIR 3.4.0.2710 and earlier versions for Windows and Macintosh, SDK (includes AIR for iOS) and Android
Comment 1 Swamp Workflow Management 2012-11-06 22:25:47 UTC
The SWAMPID for this issue is 49997.
This issue was rated as important.
Please submit fixed packages until 2012-11-13.
When done, please reassign the bug to security-team@suse.de.
Patchinfo will be handled by security team.
Comment 2 Swamp Workflow Management 2012-11-06 23:00:14 UTC
bugbot adjusting priority
Comment 3 Dirk Mueller 2012-11-08 10:36:58 UTC
Updates submitted before bug creation already.
Comment 4 Marcus Meissner 2012-11-08 10:42:37 UTC
Maintenace updates need to have a valid bnc# im their changes entry.

So please resubmit with this bnc# listed in .changes.
Comment 5 Swamp Workflow Management 2012-11-14 09:08:47 UTC
openSUSE-SU-2012:1480-1: An update that fixes 7 vulnerabilities is now available.

Category: security (important)
Bug References: 788450
CVE References: CVE-2012-5274,CVE-2012-5275,CVE-2012-5276,CVE-2012-5277,CVE-2012-5278,CVE-2012-5279,CVE-2012-5280
Sources used:
Comment 7 Swamp Workflow Management 2012-11-15 18:50:14 UTC
Update released for: flash-player, flash-player-gnome, flash-player-kde4
Products:
SLE-DESKTOP 11-SP2 (i386, x86_64)
Comment 8 Swamp Workflow Management 2012-11-15 18:54:33 UTC
Update released for: flash-player
Products:
SLE-DESKTOP 10-SP4 (i386, x86_64)
Comment 9 Marcus Meissner 2012-11-16 09:25:57 UTC
released
Comment 10 Swamp Workflow Management 2013-02-28 17:27:51 UTC
openSUSE-SU-2013:0367-1: An update that fixes 7 vulnerabilities is now available.

Category: security (important)
Bug References: 788450
CVE References: CVE-2012-5274,CVE-2012-5275,CVE-2012-5276,CVE-2012-5277,CVE-2012-5278,CVE-2012-5279,CVE-2012-5280
Sources used: