GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Sun Sep 24, 2017 5:26 pm Post subject: [ GLSA 201709-16 ] Adobe Flash Player |
|
|
Gentoo Linux Security Advisory
Title: Adobe Flash Player: Multiple vulnerabilities (GLSA 201709-16)
Severity: high
Exploitable: remote
Date: 2017-09-24
Bug(s): #627336, #630964
ID: 201709-16
Synopsis
Multiple vulnerabilities have been found in Adobe Flash Player, the
worst of which allows remote attackers to execute arbitrary code.
Background
The Adobe Flash Player is a renderer for the SWF file format, which is
commonly used to provide interactive websites.
Affected Packages
Package: www-plugins/adobe-flash
Vulnerable: < 27.0.0.130-r1
Unaffected: >= 27.0.0.130-r1
Architectures: All supported architectures
Description
Multiple vulnerabilities have been discovered in Adobe Flash Player.
Please review the referenced CVE identifiers for details.
Impact
A remote attacker could possibly execute arbitrary code with the
privileges of the process or bypass security restrictions.
Workaround
There is no known workaround at this time.
Resolution
All Adobe Flash Player users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose
">=www-plugins/adobe-flash-26.0.0.151"
|
References
CVE-2017-11281
CVE-2017-11282
CVE-2017-3085
CVE-2017-3106
|
|