[ GLSA 201711-13 ] Adobe Flash Player: Multiple vulnerabilities

\n\n
–=-Qxdw6Jc1YGcK2UYj/duz
Content-Type: text/plain; charset=”UTF-8″
Content-Transfer-Encoding: quoted-printable

– – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – –
Gentoo Linux Security Advisory=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=
=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0GLSA 201711-13
– – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – –
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=
=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=
=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0https://security.gentoo.org/
– – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – –

=C2=A0Severity: Normal
=C2=A0=C2=A0=C2=A0=C2=A0Title: Adobe Flash Player: Multiple vulnerabilities
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0Date: November 19, 2017
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0Bugs: #637630
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0ID: 201711-13

– – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – –

Synopsis
=3D=3D=3D=3D=3D=3D=3D=3D

Multiple vulnerabilities have been found in Adobe Flash Player, the
worst of which allows remote attackers to execute arbitrary code.

Background
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

The Adobe Flash Player is a renderer for the SWF file format, which is
commonly used to provide interactive websites.

Affected packages
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

=C2=A0=C2=A0=C2=A0=C2=A0—————————————————=
—————-
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0Package=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0/=C2=A0=C2=A0=C2=A0=C2=A0=
=C2=A0Vulnerable=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0/=C2=A0=C2=A0=C2=A0=C2=A0=C2=
=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0Unaffected
=C2=A0=C2=A0=C2=A0=C2=A0—————————————————=
—————-
=C2=A0 1=C2=A0=C2=A0www-plugins/adobe-flash=C2=A0=C2=A0=C2=A0=C2=A0=3D 27.0.0.187=C2=A0

Description
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

Multiple vulnerabilities have been discovered in Adobe Flash Player.
Please review the referenced CVE identifiers and Adobe Security
Bulletin for details.

Impact
=3D=3D=3D=3D=3D=3D

A remote attacker could possibly execute arbitrary code with the
privileges of the process.

Workaround
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

There is no known workaround at this time.

Resolution
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

All Adobe Flash Player users should upgrade to the latest version:

=C2=A0 # emerge –sync
=C2=A0 # emerge –ask –oneshot -v “>=3Dwww-plugins/adobe-flash-27.0.0.187″

References
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

[ 1 ] Adobe Security Bulletin
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0https://helpx.adobe.com/security/produc=
ts/flash-player/apsb17-33.
html
[ 2 ] CVE-2017-11213
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0https://nvd.nist.gov/nvd.cfm?cvename=3D=
CVE-2017-11213
[ 3 ] CVE-2017-11215
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0https://nvd.nist.gov/nvd.cfm?cvename=3D=
CVE-2017-11215
[ 4 ] CVE-2017-11225
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0https://nvd.nist.gov/nvd.cfm?cvename=3D=
CVE-2017-11225
[ 5 ] CVE-2017-3112
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0https://nvd.nist.gov/nvd.cfm?cvename=3D=
CVE-2017-3112
[ 6 ] CVE-2017-3114
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0https://nvd.nist.gov/nvd.cfm?cvename=3D=
CVE-2017-3114

Availability
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

=C2=A0https://security.gentoo.org/glsa/201711-13

Concerns?
=3D=3D=3D=3D=3D=3D=3D=3D=3D

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users’ machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=3D=3D=3D=3D=3D=3D=3D

Copyright 2017 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons – Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.5
–=-Qxdw6Jc1YGcK2UYj/duz
Content-Type: application/pgp-signature; name=”signature.asc”
Content-Description: This is a digitally signed message part
Content-Transfer-Encoding: 7bit

—–BEGIN PGP SIGNATURE—–
Version: GnuPG v2

iQGTBAABCgB9FiEE5Rdey4FSmOT+vCuqTbvRDw/dJUcFAloR6OFfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEU1
MTc1RUNCODE1Mjk4RTRGRUJDMkJBQTREQkJEMTBGMEZERDI1NDcACgkQTbvRDw/d
JUf58wgAvzAjkWprw2rTTmdRu6oaKljkD/DRmYhRGJVa/y9YMxu1y3eYlX7YUlJA
NClOuXc+5eK4PDANUfDKDgVj3bwFGgSbgfzBOh/MYgFJvjQvVbtHGDc7AeozGuls
nkE0N0o+en/FDt0BqtXf0BHgy+TNpFR8TBh5vPA/1Qb8KSS+RVeUhd+vGpbmWf8p
/1v59KDbwcs5946nQOQWA8vCIAlpt5Y9/T+w9S7sXbYnxd6RI+3kTwBZ1JX1nr/o
jjeg2wTHsLUULljChiu09i4PUDFnAKZy2dgWIAL21NOUCWt0NilIUAQkRGF8YojP
T4YPMMH2BqUjeMrrY3EslUb3mueuoA==
=xjbf
—–END PGP SIGNATURE—–

–=-Qxdw6Jc1YGcK2UYj/duz–