[Bug 886454] New: flash-player, multiple vulnerabilities: CVE-2014-0537, CVE-2014-0539, CVE-2014-4671
https://bugzilla.novell.com/show_bug.cgi?id=886454 https://bugzilla.novell.com/show_bug.cgi?id=886454#c0 Summary: flash-player, multiple vulnerabilities: CVE-2014-0537, CVE-2014-0539, CVE-2014-4671 Classification: openSUSE Product: openSUSE 13.1 Version: Final Platform: x86-64 OS/Version: openSUSE 13.1 Status: NEW Severity: Normal Priority: P5 - None Component: Other AssignedTo: bnc-team-screening@forge.provo.novell.com ReportedBy: aloisio@gmx.com QAContact: qa-bugs@suse.de Found By: --- Blocker: --- User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:30.0) Gecko/20100101 Firefox/30.0 Adobe has released security updates for Adobe Flash Player 14.0.0.125 and earlier versions for Windows and Macintosh and Adobe Flash Player 11.2.202.378 and earlier versions for Linux. These updates address vulnerabilities that could potentially allow an attacker to take control of the affected system. Adobe recommends users update their product installations to the latest versions: Users of Adobe Flash Player 14.0.0.125 and earlier versions for Windows and Macintosh should update to Adobe Flash Player 14.0.0.145. Users of Adobe Flash Player 11.2.202.378 and earlier versions for Linux should update to Adobe Flash Player 11.2.202.394. Adobe Flash Player 14.0.0.125 installed with Google Chrome will automatically be updated to the latest Google Chrome version, which will include Adobe Flash Player 14.0.0.145 for Windows, Macintosh and Linux. Adobe Flash Player 14.0.0.125 installed with Internet Explorer 10 will automatically be updated to the latest Internet Explorer 10 version, which will include Adobe Flash Player 14.0.0.145 for Windows 8.0. Adobe Flash Player 14.0.0.125 installed with Internet Explorer 11 will automatically be updated to the latest Internet Explorer 11 version, which will include Adobe Flash Player 14.0.0.145 for Windows 8.1. Users of the Adobe AIR 14.0.0.110 SDK and earlier versions should update to the Adobe AIR 14.0.0.137 SDK. Users of the Adobe AIR 14.0.0.110 SDK & Compiler and earlier versions should update to the Adobe AIR 14.0.0.137 SDK & Compiler. Users of Adobe AIR 14.0.0.110 and earlier versions for Android should update to Adobe AIR 14.0.0.137. Affected software versions Adobe Flash Player 14.0.0.125 and earlier versions for Windows and Macintosh Adobe Flash Player 11.2.202.378 and earlier versions for Linux Adobe AIR 14.0.0.110 SDK and earlier versions Adobe AIR 14.0.0.110 SDK & Compiler and earlier versions Adobe AIR 14.0.0.110 and earlier versions for Android Reproducible: Always Steps to Reproduce: 1. 2. 3. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=886454 https://bugzilla.novell.com/show_bug.cgi?id=886454#c Luigi baldoni <aloisio@gmx.com> changed: What |Removed |Added ---------------------------------------------------------------------------- AssignedTo|bnc-team-screening@forge.pr |sbrabec@suse.cz |ovo.novell.com | -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=886454 https://bugzilla.novell.com/show_bug.cgi?id=886454#c1 Stanislav Brabec <sbrabec@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |ASSIGNED CC| |sbrabec@suse.com --- Comment #1 from Stanislav Brabec <sbrabec@suse.com> 2014-07-09 17:07:44 CEST --- APSB14-17 mentions these CVE numbers: CVE-2014-0537, CVE-2014-0539, CVE-2014-4671 but: CVE-2014-0515 refers to APSB14-13, and it is already mentioned in the bug 875577 CVE-2014-0539 refers to APSB14-14, but not vice versa Only CVE-2014-4671 refers to APSB14-17. References: http://helpx.adobe.com/security/products/flash-player/apsb14-17.html http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-0515 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-0539 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-4671 -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=886454 https://bugzilla.novell.com/show_bug.cgi?id=886454#c3 Victor Pereira <vpereira@novell.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|ASSIGNED |CLOSED CC| |vpereira@novell.com Resolution| |DUPLICATE --- Comment #3 from Victor Pereira <vpereira@novell.com> 2014-07-09 15:44:39 UTC --- duplicated from bnc#886472 *** This bug has been marked as a duplicate of bug 886472 *** http://bugzilla.novell.com/show_bug.cgi?id=886472 -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=886454 https://bugzilla.novell.com/show_bug.cgi?id=886454#c5 --- Comment #5 from Bernhard Wiedemann <bwiedemann@suse.com> 2014-07-09 18:00:33 CEST --- This is an autogenerated message for OBS integration: This bug (886454) was mentioned in https://build.opensuse.org/request/show/240004 Factory:NonFree / flash-player -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=886454 https://bugzilla.novell.com/show_bug.cgi?id=886454#c10 SMASH SMASH <smash_bz@suse.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Status Whiteboard| | maint:planned:update --- Comment #10 from SMASH SMASH <smash_bz@suse.de> 2014-07-10 14:45:36 UTC --- Affected packages: SLE-11-SP1: flash-player -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=886454 https://bugzilla.novell.com/show_bug.cgi?id=886454#c11 Anja Stock <ast@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|CLOSED |REOPENED Resolution|DUPLICATE | --- Comment #11 from Anja Stock <ast@suse.com> 2014-07-22 13:38:06 UTC --- Reopening to track both packages with Legal -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=886454 https://bugzilla.novell.com/show_bug.cgi?id=886454#c17 --- Comment #17 from Stanislav Brabec <sbrabec@suse.com> 2014-07-28 22:25:12 CEST --- Adding AdobeICCProfiles.en to devel:openSUSE:Factory openSUSE-EULAs, as it has a different license agreement than flash-player. Keeping deleted only flash-player*. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=886454 https://bugzilla.novell.com/show_bug.cgi?id=886454#c Stanislav Brabec <sbrabec@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|REOPENED |ASSIGNED -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=886454 https://bugzilla.novell.com/show_bug.cgi?id=886454#c20 --- Comment #20 from Stanislav Brabec <sbrabec@suse.com> 2014-07-29 15:51:32 CEST --- Created an attachment (id=600181) --> (http://bugzilla.novell.com/attachment.cgi?id=600181) AdobeICCProfiles.en Click-wrap license agreement for AdobeICCProfiles. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
http://bugzilla.novell.com/show_bug.cgi?id=886454 --- Comment #23 from Stanislav Brabec <sbrabec@suse.com> --- The bug itself is already long time fixed, but the bug was open for confirmation of comment 20 (only partially related). The fix was left unsubmitted and I was waiting for a reply. https://build.opensuse.org/package/show/home:sbrabec:branches:devel:openSUSE... -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.novell.com/show_bug.cgi?id=886454 Swamp Workflow Management <swamp@suse.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Whiteboard| maint:planned:update | -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com