Bug 209592 - www/linux-c6-flashplugin11 / linux-f10-flashplugin11 - CVE-2016-4117
Summary: www/linux-c6-flashplugin11 / linux-f10-flashplugin11 - CVE-2016-4117
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: --- Affects Some People
Assignee: freebsd-emulation (Nobody)
URL:
Keywords: security
Depends on:
Blocks:
 
Reported: 2016-05-18 02:03 UTC by Sevan Janiyan
Modified: 2016-06-19 03:00 UTC (History)
4 users (show)

See Also:
bugzilla: maintainer-feedback? (emulation)
junovitch: merge-quarterly+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sevan Janiyan 2016-05-18 02:03:09 UTC
Version in ports is vulnerable to CVE-2016-4117, vuxml entry is missing
https://helpx.adobe.com/security/products/flash-player/apsa16-02.html
Comment 1 Johannes Jost Meixner freebsd_committer freebsd_triage 2016-05-18 05:19:20 UTC
Thanks Sevan for the submission, we'll have it fixed in no time. :)
Comment 2 commit-hook freebsd_committer freebsd_triage 2016-06-19 02:58:02 UTC
A commit references this bug:

Author: junovitch
Date: Sun Jun 19 02:57:04 UTC 2016
New revision: 417097
URL: https://svnweb.freebsd.org/changeset/ports/417097

Log:
  Document Flash vulnerabilities in Adobe Security Bulletins APSB16-10,
  APSB16-15, APSB16-18

  PR:		209592
  Reported by:	Sevan Janiyan <venture37@geeklan.co.uk>
  Security:	CVE-2016-1006, CVE-2016-1011, CVE-2016-1012, CVE-2016-1013,
  		CVE-2016-1014, CVE-2016-1015, CVE-2016-1016, CVE-2016-1017,
  		CVE-2016-1018, CVE-2016-1019, CVE-2016-1020, CVE-2016-1021,
  		CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025,
  		CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029,
  		CVE-2016-1030, CVE-2016-1031, CVE-2016-1032, CVE-2016-1033,
  		CVE-2016-1096, CVE-2016-1097, CVE-2016-1098, CVE-2016-1099,
  		CVE-2016-1100, CVE-2016-1101, CVE-2016-1102, CVE-2016-1103,
  		CVE-2016-1104, CVE-2016-1105, CVE-2016-1106, CVE-2016-1107,
  		CVE-2016-1108, CVE-2016-1109, CVE-2016-1110, CVE-2016-4108,
  		CVE-2016-4109, CVE-2016-4110, CVE-2016-4111, CVE-2016-4112,
  		CVE-2016-4113, CVE-2016-4114, CVE-2016-4115, CVE-2016-4116,
  		CVE-2016-4117, CVE-2016-4120, CVE-2016-4121, CVE-2016-4160,
  		CVE-2016-4161, CVE-2016-4162, CVE-2016-4163, CVE-2016-4122,
  		CVE-2016-4123, CVE-2016-4124, CVE-2016-4125, CVE-2016-4127,
  		CVE-2016-4128, CVE-2016-4129, CVE-2016-4130, CVE-2016-4131,
  		CVE-2016-4132, CVE-2016-4133, CVE-2016-4134, CVE-2016-4135,
  		CVE-2016-4136, CVE-2016-4137, CVE-2016-4138, CVE-2016-4139,
  		CVE-2016-4140, CVE-2016-4141, CVE-2016-4142, CVE-2016-4143,
  		CVE-2016-4144, CVE-2016-4145, CVE-2016-4146, CVE-2016-4147,
  		CVE-2016-4148, CVE-2016-4149, CVE-2016-4150, CVE-2016-4151,
  		CVE-2016-4152, CVE-2016-4153, CVE-2016-4154, CVE-2016-4155,
  		CVE-2016-4156, CVE-2016-4166, CVE-2016-4171
  Security:	https://vuxml.FreeBSD.org/freebsd/0e3dfdde-35c4-11e6-8e82-002590263bf5.html
  Security:	https://vuxml.FreeBSD.org/freebsd/07888b49-35c4-11e6-8e82-002590263bf5.html
  Security:	https://vuxml.FreeBSD.org/freebsd/0c6b008d-35c4-11e6-8e82-002590263bf5.html

Changes:
  head/security/vuxml/vuln.xml
Comment 3 commit-hook freebsd_committer freebsd_triage 2016-06-19 02:58:04 UTC
A commit references this bug:

Author: junovitch
Date: Sun Jun 19 02:57:30 UTC 2016
New revision: 417098
URL: https://svnweb.freebsd.org/changeset/ports/417098

Log:
  www/linux-*-flashplugin: update 11.2r202.577 -> 11.2r202.626

  PR:		209592
  Reported by:	Sevan Janiyan <venture37@geeklan.co.uk>
  Approved by:	port-secteam (with hat)
  Security:	CVE-2016-1006, CVE-2016-1011, CVE-2016-1012, CVE-2016-1013,
  		CVE-2016-1014, CVE-2016-1015, CVE-2016-1016, CVE-2016-1017,
  		CVE-2016-1018, CVE-2016-1019, CVE-2016-1020, CVE-2016-1021,
  		CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025,
  		CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029,
  		CVE-2016-1030, CVE-2016-1031, CVE-2016-1032, CVE-2016-1033,
  		CVE-2016-1096, CVE-2016-1097, CVE-2016-1098, CVE-2016-1099,
  		CVE-2016-1100, CVE-2016-1101, CVE-2016-1102, CVE-2016-1103,
  		CVE-2016-1104, CVE-2016-1105, CVE-2016-1106, CVE-2016-1107,
  		CVE-2016-1108, CVE-2016-1109, CVE-2016-1110, CVE-2016-4108,
  		CVE-2016-4109, CVE-2016-4110, CVE-2016-4111, CVE-2016-4112,
  		CVE-2016-4113, CVE-2016-4114, CVE-2016-4115, CVE-2016-4116,
  		CVE-2016-4117, CVE-2016-4120, CVE-2016-4121, CVE-2016-4160,
  		CVE-2016-4161, CVE-2016-4162, CVE-2016-4163, CVE-2016-4122,
  		CVE-2016-4123, CVE-2016-4124, CVE-2016-4125, CVE-2016-4127,
  		CVE-2016-4128, CVE-2016-4129, CVE-2016-4130, CVE-2016-4131,
  		CVE-2016-4132, CVE-2016-4133, CVE-2016-4134, CVE-2016-4135,
  		CVE-2016-4136, CVE-2016-4137, CVE-2016-4138, CVE-2016-4139,
  		CVE-2016-4140, CVE-2016-4141, CVE-2016-4142, CVE-2016-4143,
  		CVE-2016-4144, CVE-2016-4145, CVE-2016-4146, CVE-2016-4147,
  		CVE-2016-4148, CVE-2016-4149, CVE-2016-4150, CVE-2016-4151,
  		CVE-2016-4152, CVE-2016-4153, CVE-2016-4154, CVE-2016-4155,
  		CVE-2016-4156, CVE-2016-4166, CVE-2016-4171
  Security:	https://vuxml.FreeBSD.org/freebsd/0e3dfdde-35c4-11e6-8e82-002590263bf5.html
  Security:	https://vuxml.FreeBSD.org/freebsd/07888b49-35c4-11e6-8e82-002590263bf5.html
  Security:	https://vuxml.FreeBSD.org/freebsd/0c6b008d-35c4-11e6-8e82-002590263bf5.html
  MFH:		2016Q2

Changes:
  head/www/linux-c6-flashplugin11/Makefile
  head/www/linux-c6-flashplugin11/distinfo.i686
  head/www/linux-c6-flashplugin11/distinfo.x86_64
Comment 4 commit-hook freebsd_committer freebsd_triage 2016-06-19 02:59:06 UTC
A commit references this bug:

Author: junovitch
Date: Sun Jun 19 02:58:34 UTC 2016
New revision: 417099
URL: https://svnweb.freebsd.org/changeset/ports/417099

Log:
  MFH: r417098

  www/linux-*-flashplugin: update 11.2r202.577 -> 11.2r202.626

  PR:		209592
  Reported by:	Sevan Janiyan <venture37@geeklan.co.uk>
  Approved by:	ports-secteam (with hat)
  Security:	CVE-2016-1006, CVE-2016-1011, CVE-2016-1012, CVE-2016-1013,
  		CVE-2016-1014, CVE-2016-1015, CVE-2016-1016, CVE-2016-1017,
  		CVE-2016-1018, CVE-2016-1019, CVE-2016-1020, CVE-2016-1021,
  		CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025,
  		CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029,
  		CVE-2016-1030, CVE-2016-1031, CVE-2016-1032, CVE-2016-1033,
  		CVE-2016-1096, CVE-2016-1097, CVE-2016-1098, CVE-2016-1099,
  		CVE-2016-1100, CVE-2016-1101, CVE-2016-1102, CVE-2016-1103,
  		CVE-2016-1104, CVE-2016-1105, CVE-2016-1106, CVE-2016-1107,
  		CVE-2016-1108, CVE-2016-1109, CVE-2016-1110, CVE-2016-4108,
  		CVE-2016-4109, CVE-2016-4110, CVE-2016-4111, CVE-2016-4112,
  		CVE-2016-4113, CVE-2016-4114, CVE-2016-4115, CVE-2016-4116,
  		CVE-2016-4117, CVE-2016-4120, CVE-2016-4121, CVE-2016-4160,
  		CVE-2016-4161, CVE-2016-4162, CVE-2016-4163, CVE-2016-4122,
  		CVE-2016-4123, CVE-2016-4124, CVE-2016-4125, CVE-2016-4127,
  		CVE-2016-4128, CVE-2016-4129, CVE-2016-4130, CVE-2016-4131,
  		CVE-2016-4132, CVE-2016-4133, CVE-2016-4134, CVE-2016-4135,
  		CVE-2016-4136, CVE-2016-4137, CVE-2016-4138, CVE-2016-4139,
  		CVE-2016-4140, CVE-2016-4141, CVE-2016-4142, CVE-2016-4143,
  		CVE-2016-4144, CVE-2016-4145, CVE-2016-4146, CVE-2016-4147,
  		CVE-2016-4148, CVE-2016-4149, CVE-2016-4150, CVE-2016-4151,
  		CVE-2016-4152, CVE-2016-4153, CVE-2016-4154, CVE-2016-4155,
  		CVE-2016-4156, CVE-2016-4166, CVE-2016-4171
  Security:	https://vuxml.FreeBSD.org/freebsd/0e3dfdde-35c4-11e6-8e82-002590263bf5.html
  Security:	https://vuxml.FreeBSD.org/freebsd/07888b49-35c4-11e6-8e82-002590263bf5.html
  Security:	https://vuxml.FreeBSD.org/freebsd/0c6b008d-35c4-11e6-8e82-002590263bf5.html

Changes:
_U  branches/2016Q2/
  branches/2016Q2/www/linux-c6-flashplugin11/Makefile
  branches/2016Q2/www/linux-c6-flashplugin11/distinfo.i686
  branches/2016Q2/www/linux-c6-flashplugin11/distinfo.x86_64
Comment 5 Jason Unovitch freebsd_committer freebsd_triage 2016-06-19 03:00:12 UTC
Updated.  Thank you Sevan!