FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

linux-flashplugin -- multiple vulnerabilities

Affected packages
linux-flashplugin <= 9.0r289
linux-f10-flashplugin < 10.3r183.10

Details

VuXML ID 53e531a7-e559-11e0-b481-001b2134ef46
Discovery 2011-06-06
Entry 2011-09-22

Adobe Product Security Incident Response Team reports:

Critical vulnerabilities have been identified in Adobe Flash Player 10.3.183.7 and earlier versions for Windows, Macintosh, Linux and Solaris, and Adobe Flash Player 10.3.186.6 and earlier versions for Android. These vulnerabilities could cause a crash and potentially allow an attacker to take control of the affected system.

There are reports that one of these vulnerabilities (CVE-2011-2444) is being exploited in the wild in active targeted attacks designed to trick the user into clicking on a malicious link delivered in an email message. This universal cross-site scripting issue could be used to take actions on a user's behalf on any website or webmail provider if the user visits a malicious website.

References

CVE Name CVE-2011-2426
CVE Name CVE-2011-2427
CVE Name CVE-2011-2428
CVE Name CVE-2011-2429
CVE Name CVE-2011-2430
CVE Name CVE-2011-2444
URL https://www.adobe.com/support/security/bulletins/apsb11-26.html