Chapter 1. Package Updates
1.58. flash-plugin
1.58.1. RHSA-2009:1188: Critical security update
Important
This update has already been released (prior to the GA of this release) as the security
RHSA-2009:1188
errata
An updated Adobe Flash Player package that fixes multiple security issues is now available for Red
Hat Enterprise Linux 5 Supplementary.
This update has been rated as having critical security impact by the Red Hat Security Response
Team.
The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-
in.
Multiple security flaws were found in the way Flash Player displayed certain SWF content. An attacker
could use these flaws to create a specially-crafted SWF file that would cause flash-plugin to crash
or, possibly, execute arbitrary code when the victim loaded a page containing the specially-crafted
SWF content.
(CVE-2009-1862
392
CVE-2009-1866
CVE-2009-1868
,
A clickjacking flaw was discovered in Flash Player. A specially-crafted SWF file could trick a user into
unintentionally or mistakenly clicking a link or a dialog.
A flaw was found in the Flash Player local sandbox. A specially-crafted SWF file could cause
information disclosure when it was saved to the hard drive.
All users of Adobe Flash Player should install this updated package, which upgrades Flash Player to
version 10.0.32.18.
1.58.2. RHSA-2009:0332: Critical security update
Important
This update has already been released (prior to the GA of this release) as the security
RHSA-2009:0332
errata
An updated Adobe Flash Player package that fixes several security issues is now available for Red
Hat Enterprise Linux 5 Supplementary.
388
https://www.redhat.com/security/data/cve/CVE-2009-1862.html
389
https://www.redhat.com/security/data/cve/CVE-2009-1863.html
390
https://www.redhat.com/security/data/cve/CVE-2009-1864.html
391
https://www.redhat.com/security/data/cve/CVE-2009-1865.html
392
https://www.redhat.com/security/data/cve/CVE-2009-1866.html
393
https://www.redhat.com/security/data/cve/CVE-2009-1868.html
394
https://www.redhat.com/security/data/cve/CVE-2009-1869.html
395
https://www.redhat.com/security/data/cve/CVE-2009-1867.html
396
https://www.redhat.com/security/data/cve/CVE-2009-1870.html
64
387
388
389
CVE-2009-1863
,
393
CVE-2009-1869
,
397
390
CVE-2009-1864
CVE-2009-1865
,
,
394
)
395
(CVE-2009-1867
)
(CVE-2009-1870
391
,
396
)
Need help?
Do you have a question about the ENTERPRISE LINUX 5.4 - TECHNICAL NOTES and is the answer not in the manual?
Questions and answers