FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

linux-flashplugin -- multiple vulnerabilities

Affected packages
linux-flashplugin <= 9.0r289
linux-f10-flashplugin < 10.3r181.14

Details

VuXML ID d226626c-857f-11e0-95cc-001b2134ef46
Discovery 2011-01-20
Entry 2011-05-23

Adobe Product Security Incident Response Team reports:

Critical vulnerabilities have been identified in Adobe Flash Player 10.2.159.1 and earlier versions (Adobe Flash Player 10.2.154.28 and earlier for Chrome users) for Windows, Macintosh, Linux and Solaris, and Adobe Flash Player 10.2.157.51 and earlier versions for Android. These vulnerabilities could cause the application to crash and could potentially allow an attacker to take control of the affected system. There are reports of malware attempting to exploit one of the vulnerabilities, CVE-2011-0627, in the wild via a Flash (.swf) file embedded in a Microsoft Word (.doc) or Microsoft Excel (.xls) file delivered as an email attachment targeting the Windows platform. However, to date, Adobe has not obtained a sample that successfully completes an attack.

References

CVE Name CVE-2011-0579
CVE Name CVE-2011-0618
CVE Name CVE-2011-0619
CVE Name CVE-2011-0620
CVE Name CVE-2011-0621
CVE Name CVE-2011-0622
CVE Name CVE-2011-0623
CVE Name CVE-2011-0624
CVE Name CVE-2011-0625
CVE Name CVE-2011-0626
CVE Name CVE-2011-0627
URL http://www.adobe.com/support/security/bulletins/apsb11-12.html