copyright | disclaimer | privacy | contact  
Australia's Leading Computer Emergency Response Team
 
Search this site

 
On this site

 > HOME
 > About AusCERT
 > Membership
 > Contact Us
 > PKI Services
 > Training
 > Publications
 > Sec. Bulletins
 > Conferences
 > News & Media
 > Services
 > Web Log
 > Site Map
 > Site Help
 > Member login





 

ESB-2008.1008 -- [RedHat] -- Important: flash-plugin security update

Date: 29 October 2008
References: ESB-2007.1046  ESB-2008.0006  ESB-2008.0249  ESB-2008.0310  AA-2008.0213  ESB-2008.0361  ESB-2008.0367  ESB-2008.0560  ESB-2008.0580  

Click here for printable version
Click here for PGP verifiable version
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                         ESB-2008.1008 -- [RedHat]
                  Important: flash-plugin security update
                              29 October 2008

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:              Red Hat Enterprise Linux Extras
Publisher:            Red Hat
Operating System:     Red Hat Linux 5
Impact:               Execute Arbitrary Code/Commands
                      Create Arbitrary Files
                      Modify Arbitrary Files
                      Modify Arbitrary Files
                      Cross-site Scripting
                      Inappropriate Access
                      Access Confidential Data
Access:               Remote/Unauthenticated
CVE Names:            CVE-2008-4503 CVE-2008-4401 CVE-2008-3873
                      CVE-2007-6243 CVE-2007-4324

Ref:                  ESB-2007.1046
                      ESB-2008.0006
                      ESB-2008.0249
                      ESB-2008.0310
                      ESB-2008.0361
                      ESB-2008.0367
                      ESB-2008.0560
                      ESB-2008.0580
                      AA-2008.0213

Original Bulletin:    https://rhn.redhat.com/errata/RHSA-2008-0945.html

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

=====================================================================
                   Red Hat Security Advisory

Synopsis:          Important: flash-plugin security update
Advisory ID:       RHSA-2008:0945-01
Product:           Red Hat Enterprise Linux Extras
Advisory URL:      https://rhn.redhat.com/errata/RHSA-2008-0945.html
Issue date:        2008-10-28
CVE Names:         CVE-2007-4324 CVE-2007-6243 CVE-2008-3873 
                   CVE-2008-4401 CVE-2008-4503 
=====================================================================

1. Summary:

An updated Adobe Flash Player package that fixes several security issues is
now available for Red Hat Enterprise Linux 5 Supplementary.

This update has been rated as having important security impact by the Red
Hat Security Response Team.

2. Relevant releases/architectures:

RHEL Desktop Supplementary (v. 5 client) - i386, x86_64
RHEL Supplementary (v. 5 server) - i386, x86_64

3. Description:

The flash-plugin package contains a Firefox-compatible Adobe Flash Player
Web browser plug-in.

A flaw was found in the way Adobe Flash Player wrote content to the
clipboard. A malicious SWF file could populate the clipboard with a URL
that could cause the user to mistakenly load an attacker-controlled URL.
(CVE-2008-3873)

A flaw was found which allowed Adobe Flash Player's ActionScript to
initiate file uploads and downloads without user interaction.
FileReference.browse and FileReference.download calls can now only be
initiated via user interaction, such as mouse-clicks or key-presses on the
keyboard. (CVE-2008-4401)

A flaw was found in Adobe Flash Player's display of the Settings Manager
content. A malicious SWF file could trick the user into unknowingly
clicking a link or dialog. This could then give the malicious SWF file
permission to access the local machine's camera or microphone.
(CVE-2008-4503)

Flaws were found in the way Flash Player restricted the interpretation and
usage of cross-domain policy files.  A remote attacker could use Flash
Player to conduct cross-domain and cross-site scripting attacks
(CVE-2007-4324, CVE-2007-6243). This update provides enhanced fixes for
these issues.

Adobe Flash Player 10 also includes bug fixes and feature enhancements
including:

* improved stability on the Linux platform by fixing a race condition issue
in sound output.

* new support for custom filters and effects, native 3D transformation and
animation, advanced audio processing, a new, more flexible text engine, and
GPU hardware acceleration. 

For more information on new features and enhancements, see the Adobe Flash
Player site and the Adobe Labs Release Notes.

Note: some users may have installed a 3rd-party component, libflashsupport,
for older versions of Flash Player. Adobe Flash Player 10 no longer
supports libflashsupport. Users are advised to remove libflashsupport if
they have it installed.

All users of Adobe Flash Player should upgrade to this updated package,
which contains Flash Player version 10.0.12.36.

4. Solution:

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network.  Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/FAQ_58_10188

5. Bugs fixed (http://bugzilla.redhat.com/):

252292 - CVE-2007-4324 Flash movie can determine whether a TCP port is open
440664 - CVE-2007-6243 Flash Player cross-domain and cross-site scripting flaws
465736 - CVE-2008-3873 flash: clipboard hijack attack
466154 - CVE-2008-4401 flash-plugin: upload/download user interaction
466344 - CVE-2008-4503 Adobe Flash Player clickjacking

6. Package List:

RHEL Desktop Supplementary (v. 5 client):

i386:
flash-plugin-10.0.12.36-2.el5.i386.rpm

x86_64:
flash-plugin-10.0.12.36-2.el5.i386.rpm

RHEL Supplementary (v. 5 server):

i386:
flash-plugin-10.0.12.36-2.el5.i386.rpm

x86_64:
flash-plugin-10.0.12.36-2.el5.i386.rpm

These packages are GPG signed by Red Hat for security.  Our key and 
details on how to verify the signature are available from
https://www.redhat.com/security/team/key/#package

7. References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4324
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6243
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3873
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4401
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4503
http://adobe.com/products/flashplayer
http://labs.adobe.com/technologies/flashplayer10/releasenotes.html
http://www.redhat.com/security/updates/classification/#important

8. Contact:

The Red Hat security contact is <secalert@redhat.com>.  More contact
details at https://www.redhat.com/security/team/contact/

Copyright 2008 Red Hat, Inc.
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.4 (GNU/Linux)

iD8DBQFJByTSXlSAg2UNWIIRAlItAJ9aqlQwNSicgNI0KgBR5fPmR4m0QgCeJ55O
pa+gqJ3/Zs4KSEos+BKUnEw=
=2xVI
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        http://www.auscert.org.au/render.html?cid=1980

If you believe that your computer system has been compromised or attacked in 
any way, we encourage you to let us know by completing the secure National IT 
Incident Reporting Form at:

        http://www.auscert.org.au/render.html?it=3192

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================

-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQCVAwUBSQeiVyh9+71yA2DNAQIPnAP+No69OsmgUQZ4lmOoXI8XlfUS6Wsr5vqT
KOH/Fyq8ke/R6f/sHyr+FLCVMjJM8kbgxaFqEPBkS3Sp6oCMmuA/DfQZQcW427zx
QnDiiKGQUUsf/ydcPuU+4eWQhyHclBTi6/LWNzVv1KIwzTd8N/MuNG0XS7Noc4Un
+ksYNTJ8Tno=
=1fb9
-----END PGP SIGNATURE-----