Bug 156996 - www/linux-f10-flashplugin is vulnerable
Summary: www/linux-f10-flashplugin is vulnerable
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: Normal Affects Only Me
Assignee: freebsd-emulation (Nobody)
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2011-05-13 10:10 UTC by TsurutaniNaoki
Modified: 2011-05-23 22:20 UTC (History)
1 user (show)

See Also:


Attachments
file.diff (1.30 KB, patch)
2011-05-13 10:10 UTC, TsurutaniNaoki
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description TsurutaniNaoki 2011-05-13 10:10:07 UTC
	www/linux-f10-flashplugin is vulnerable.
	ref: http://www.adobe.com/support/security/bulletins/apsb11-12.html

Fix: a new version of flashplugin is available.
	here is a patch:
Comment 1 Tilman Keskinoz freebsd_committer freebsd_triage 2011-05-14 13:27:39 UTC
Responsible Changed
From-To: freebsd-ports-bugs->emulation

Over to maintainer group
Comment 2 Juergen Lock 2011-05-19 20:32:17 UTC
Here is an update that also installs the new flash-player-properties
config applet with icons and desktop menu entries, that one only
partly works (misses Linux /usr/lib/gio/modules/libgiofam.so and
at least `Learn more' links are broken, also only the gnome version
can work), but at least it should be good enough for first testing.

Index: Makefile
===================================================================
RCS file: /home/pcvs/ports/www/linux-f10-flashplugin10/Makefile,v
retrieving revision 1.16
diff -u -p -r1.16 Makefile
--- Makefile	17 Apr 2011 18:32:15 -0000	1.16
+++ Makefile	19 May 2011 18:44:12 -0000
@@ -7,7 +7,7 @@
 #
 
 PORTNAME=	flashplugin
-PORTVERSION=	10.2r159.1
+PORTVERSION=	10.3r181.14
 CATEGORIES=	www multimedia linux
 MASTER_SITES=	http://fpdownload.macromedia.com/get/flashplayer/current/:plugin \
 		ftp://ftp.ipt.ru/pub/download/:suplib
@@ -22,6 +22,8 @@ COMMENT=	Adobe Flash Player NPAPI Plugin
 ONLY_FOR_ARCHS=	amd64 i386
 USE_LINUX=	yes
 USE_LINUX_APPS=	openssl curl cyrus-sasl2 libssh2 nspr nss openldap gtk2
+USE_GNOME=	desktopfileutils
+INSTALLS_ICONS=	yes
 
 RESTRICTED=	Redistribution not allowed
 RESTRICTED_FILES=	${DISTFILES:Nlinux-f10-flashsupport*:C/:[^:]+$//}
@@ -34,8 +36,15 @@ NPAPI_FILES=	libflashplayer.so
 
 CONFLICTS=	linux-flashplugin-7* linux-flashplugin-9* linux-f8-flashplugin10-*
 
+post-patch:
+	@${REINPLACE_CMD} -e 's|/usr|${PREFIX}|' -e '/^NotShowIn=KDE/d' ${WRKDIR}/usr/share/applications/flash-player-properties.desktop
+
 post-install:
 	@${INSTALL_PROGRAM} ${WRKDIR}/libflashsupport.so ${LINUXBASE}/usr/lib
+	@${INSTALL_PROGRAM} ${WRKDIR}/usr/bin/flash-player-properties ${PREFIX}/bin
+	@${INSTALL_DATA} ${WRKDIR}/usr/share/applications/flash-player-properties.desktop ${DESKTOPDIR}
+	@(cd ${WRKDIR}/usr/share/icons && ${COPYTREE_SHARE} hicolor ${PREFIX}/share/icons)
+	-@update-desktop-database
 
 .include <bsd.port.pre.mk>
 .include "${PORTSDIR}/www/linux-mplayer-plugin/Makefile.npapi"
Index: distinfo
===================================================================
RCS file: /home/pcvs/ports/www/linux-f10-flashplugin10/distinfo,v
retrieving revision 1.14
diff -u -p -r1.14 distinfo
--- distinfo	17 Apr 2011 18:32:15 -0000	1.14
+++ distinfo	15 May 2011 17:13:50 -0000
@@ -1,4 +1,4 @@
-SHA256 (flashplugin/10.2r159.1/install_flash_player_10_linux.tar.gz) = e6844572fad1cef47dfa8afea6a6cf1e1191fde30041947d5beab1445e0ed742
-SIZE (flashplugin/10.2r159.1/install_flash_player_10_linux.tar.gz) = 4967668
-SHA256 (flashplugin/10.2r159.1/linux-f10-flashsupport-9.0.1.i386.tar.gz) = 4a309b1a326bd2212cc72480628659e5a7fd61d9e0572cb7350c206f030955bf
-SIZE (flashplugin/10.2r159.1/linux-f10-flashsupport-9.0.1.i386.tar.gz) = 3455
+SHA256 (flashplugin/10.3r181.14/install_flash_player_10_linux.tar.gz) = 2eaab07a2d066a436a9f8ff9b84e3cc89a969f032d6d9cf94cd81f285e115003
+SIZE (flashplugin/10.3r181.14/install_flash_player_10_linux.tar.gz) = 5456725
+SHA256 (flashplugin/10.3r181.14/linux-f10-flashsupport-9.0.1.i386.tar.gz) = 4a309b1a326bd2212cc72480628659e5a7fd61d9e0572cb7350c206f030955bf
+SIZE (flashplugin/10.3r181.14/linux-f10-flashsupport-9.0.1.i386.tar.gz) = 3455
Index: pkg-plist
===================================================================
RCS file: /home/pcvs/ports/www/linux-f10-flashplugin10/pkg-plist,v
retrieving revision 1.2
diff -u -p -r1.2 pkg-plist
--- pkg-plist	28 Jun 2009 20:29:15 -0000	1.2
+++ pkg-plist	19 May 2011 18:08:42 -0000
@@ -1,3 +1,23 @@
+bin/flash-player-properties
+share/applications/flash-player-properties.desktop
+share/icons/hicolor/16x16/apps/flash-player-properties.png
+share/icons/hicolor/22x22/apps/flash-player-properties.png
+share/icons/hicolor/24x24/apps/flash-player-properties.png
+share/icons/hicolor/32x32/apps/flash-player-properties.png
+share/icons/hicolor/48x48/apps/flash-player-properties.png
+@dirrmtry share/icons/hicolor/16x16/apps
+@dirrmtry share/icons/hicolor/22x22/apps
+@dirrmtry share/icons/hicolor/24x24/apps
+@dirrmtry share/icons/hicolor/32x32/apps
+@dirrmtry share/icons/hicolor/48x48/apps
+@dirrmtry share/icons/hicolor/16x16
+@dirrmtry share/icons/hicolor/22x22
+@dirrmtry share/icons/hicolor/24x24
+@dirrmtry share/icons/hicolor/32x32
+@dirrmtry share/icons/hicolor/48x48
+@dirrmtry share/icons/hicolor
+@dirrmtry share/icons
+@dirrmtry share/applications
 @cwd /compat/linux
 usr/lib/libflashsupport.so
 @cwd
Comment 3 TsurutaniNaoki 2011-05-20 04:07:36 UTC
Juergen Lock wrote:

>Here is an update that also installs the new flash-player-properties
>config applet with icons and desktop menu entries, that one only
>partly works (misses Linux /usr/lib/gio/modules/libgiofam.so and
>at least `Learn more' links are broken, also only the gnome version
>can work), but at least it should be good enough for first testing.

It seems to work fine. Great.
I was not aware of the files...
Comment 4 Mark Linimon freebsd_committer freebsd_triage 2011-05-23 19:07:13 UTC
Responsible Changed
From-To: emulation->freebsd-emulation

Canonicalize assignment.
Comment 5 dfilter service freebsd_committer freebsd_triage 2011-05-23 22:18:05 UTC
nox         2011-05-23 21:17:51 UTC

  FreeBSD ports repository

  Modified files:
    www/linux-f10-flashplugin10 Makefile distinfo pkg-plist 
    security/vuxml       vuln.xml 
  Log:
  Update to 10.3r181.14 .
  
  PR:             ports/156996
  Submitted by:   Tsurutani Naoki <turutani@scphys.kyoto-u.ac.jp>
  Security:       http://www.freebsd.org/ports/portaudit/d226626c-857f-11e0-95cc-001b2134ef46.html
  
  Revision  Changes    Path
  1.2363    +53 -1     ports/security/vuxml/vuln.xml
  1.17      +10 -1     ports/www/linux-f10-flashplugin10/Makefile
  1.15      +4 -4      ports/www/linux-f10-flashplugin10/distinfo
  1.3       +20 -0     ports/www/linux-f10-flashplugin10/pkg-plist
_______________________________________________
cvs-all@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/cvs-all
To unsubscribe, send any mail to "cvs-all-unsubscribe@freebsd.org"
Comment 6 Juergen Lock freebsd_committer freebsd_triage 2011-05-23 22:18:50 UTC
State Changed
From-To: open->closed

Committed, with minor changes. Thanks!