MGASA-2018-0286
Dashboard / Vulnerabilities / MGASA-2018-0286
MGASA-2018-0286
Summary: Updated flash-player-plugin packages fixes security issues
Details: Updated flash-player-plugin packages fixes the following security issues A remote attacker could possibly execute arbitrary code with the privileges of the process or obtain sensitive information (CVE-2018-4945, CVE-2018-5000, CVE-2018-5001, CVE-2018-5002). In response to a class of recently disclosed vulnerabilities in popular CPU hardware related to data cache timing (CVE-2017-5753, CVE-2017-5715, CVE-2017-5754), known popularly as Spectre and Meltdown, Adobe are disabling the ‘shareable’ property of the ActionScript ByteArray class by default. For more info see the referenced adobe release notes.
References: https://advisories.mageia.org/MGASA-2018-0286.html, https://bugs.mageia.org/show_bug.cgi?id=23175, https://helpx.adobe.com/security/products/flash-player/apsb18-19.html, https://helpx.adobe.com/flash-player/release-note/fp_30_air_30_release_notes.html
Affected packages
Package
Name: flash-player-plugin
Purl: pkg:rpm/mageia/flash-player-plugin?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
