Bug 213831 - www/linux-c6-flashplugin11: 11.2r202.637 vulnerable, Update to >= 11.2r202.643
Summary: www/linux-c6-flashplugin11: 11.2r202.637 vulnerable, Update to >= 11.2r202.643
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: Normal Affects Many People
Assignee: freebsd-emulation (Nobody)
URL: https://helpx.adobe.com/security/prod...
Keywords: needs-patch, security
Depends on:
Blocks:
 
Reported: 2016-10-27 10:17 UTC by Ben Woods
Modified: 2016-10-27 16:32 UTC (History)
6 users (show)

See Also:
bugzilla: maintainer-feedback? (emulation)
koobs: maintainer-feedback? (ports-secteam)
koobs: merge-quarterly?


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Ben Woods freebsd_committer freebsd_triage 2016-10-27 10:17:00 UTC
Adobe has released security updates for Adobe Flash Player for Windows, Macintosh, Linux and Chrome OS.  These updates address a critical vulnerability that could potentially allow an attacker to take control of the affected system.  

Adobe is aware of a report that an exploit for CVE-2016-7855 exists in the wild, and is being used in limited, targeted attacks against users running Windows versions 7, 8.1 and 10.
https://helpx.adobe.com/security/products/flash-player/apsb16-36.html

Ports for flashplugin should be updated to 11.2r202.643 or later to avoid these vulnerabilities.
Comment 1 Kubilay Kocak freebsd_committer freebsd_triage 2016-10-27 10:28:48 UTC
@Ben Anyone can create the vuxml entry, which can independently be committed. If you'd like, create a new issue, assign yourself and have this one depend on it (for tracking purposes).
Comment 2 commit-hook freebsd_committer freebsd_triage 2016-10-27 12:53:37 UTC
A commit references this bug:

Author: tijl
Date: Thu Oct 27 12:53:13 UTC 2016
New revision: 424761
URL: https://svnweb.freebsd.org/changeset/ports/424761

Log:
  Update flash plugin to 11.2r202.643.
  Remove unnecessary USES=desktop-file-utils.

  PR:		213831
  MFH:		2016Q4
  Security:	https://helpx.adobe.com/security/products/flash-player/apsb16-36.html

Changes:
  head/www/linux-c6-flashplugin11/Makefile
  head/www/linux-c6-flashplugin11/distinfo
Comment 3 commit-hook freebsd_committer freebsd_triage 2016-10-27 13:14:40 UTC
A commit references this bug:

Author: tijl
Date: Thu Oct 27 13:14:18 UTC 2016
New revision: 424764
URL: https://svnweb.freebsd.org/changeset/ports/424764

Log:
  Document latest flash plugin vulnerability.

  PR:		213831

Changes:
  head/security/vuxml/vuln.xml
Comment 4 commit-hook freebsd_committer freebsd_triage 2016-10-27 16:31:03 UTC
A commit references this bug:

Author: tijl
Date: Thu Oct 27 16:30:44 UTC 2016
New revision: 424775
URL: https://svnweb.freebsd.org/changeset/ports/424775

Log:
  MFH: r424761

  Update flash plugin to 11.2r202.643.
  Remove unnecessary USES=desktop-file-utils.

  PR:		213831
  Security:	https://helpx.adobe.com/security/products/flash-player/apsb16-36.html
  Approved by:	ports-secteam (feld)

Changes:
_U  branches/2016Q4/
  branches/2016Q4/www/linux-c6-flashplugin11/Makefile
  branches/2016Q4/www/linux-c6-flashplugin11/distinfo