ArchLinux: 201501-22: flashplugin: multiple issues
Summary
- CVE-2015-0311 (remote code execution)
Unspecified vulnerability allows remote attackers to execute arbitrary
code via unknown vectors, as exploited in the wild in January 2015.
- CVE-2015-0309 (remote code execution)
Heap-based buffer overflow allows attackers to execute arbitrary code
via unspecified vectors, a different vulnerability than CVE-2015-0304.
- CVE-2015-0308 (remote code execution)
Use-after-free vulnerability allows attackers to execute arbitrary code
via unspecified vectors.
- CVE-2015-0307 (memory leaks, denial of service)
A vulnerability allows remote attackers to obtain sensitive information
from process memory or cause a denial of service (out-of-bounds read)
via unspecified vectors.
- CVE-2015-0306 (remote code execution, denial of service)
A vulnerability allows attackers to execute arbitrary code or cause a
denial of service (memory corruption) via unspecified vectors, a
different vulnerability than CVE-2015-0303.
- CVE-2015-0305 (remote code execution)
A vulnerability allows attackers to execute arbitrary code by leveraging
an unspecified "type confusion".
- CVE-2015-0304 (remote code execution)
Heap-based buffer overflow allows attackers to execute arbitrary code
via unspecified vectors, a different vulnerability than CVE-2015-0309.
- CVE-2015-0303 (remote code execution, denial of service)
A vulnerability allows attackers to execute arbitrary code or cause a
denial of service (memory corruption) via unspecified vectors, a
different vulnerability than CVE-2015-0306.
- CVE-2015-0302 (keylogging)
A vulnerability allows attackers to obtain sensitive keystroke
information via unspecified vectors.
- CVE-2015-0301 (file validation)
The flashplugin does not properly validate files, which has unspecified
impact and attack vectors.
Resolution
Upgrade to 11.2.202.440-1.
# pacman -Syu "flashplugin>=11.2.202.440-1"
The problems have been fixed upstream in version 11.2.202.440.
References
https://malware.dontneedcoffee.com/2015/01/unpatched-vulnerability-0day-in-flash.html http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0311 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0309 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0308 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0307 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0306 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0305 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0304 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0303 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0302 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0301
Workaround
None.