LWN.net Logo

flash-plugin: abandon all hope

Package(s):flash-plugin CVE #(s):CVE-2011-2445 CVE-2011-2450 CVE-2011-2451 CVE-2011-2452 CVE-2011-2453 CVE-2011-2454 CVE-2011-2455 CVE-2011-2456 CVE-2011-2457 CVE-2011-2459 CVE-2011-2460
Created:November 11, 2011 Updated:November 17, 2011
Description:

From the Red Hat advisory:

Multiple security flaws were found in the way flash-plugin displayed certain SWF content. An attacker could use these flaws to create a specially-crafted SWF file that would cause flash-plugin to crash or, potentially, execute arbitrary code when the victim loaded a page containing the specially-crafted SWF content. (CVE-2011-2445, CVE-2011-2450, CVE-2011-2451, CVE-2011-2452, CVE-2011-2453, CVE-2011-2454, CVE-2011-2455, CVE-2011-2456, CVE-2011-2457, CVE-2011-2459, CVE-2011-2460)

Alerts:
SUSE   2011-11-15
openSUSE openSUSE-SU-2011:1240-2 2011-11-16
openSUSE openSUSE-SU-2011:1240-1 2011-11-15
Red Hat RHSA-2011:1445-01 2011-11-11
SUSE SUSE-SU-2011:1244-1 2011-11-15

(Log in to post comments)

flash-plugin: abandon all hope

Posted Nov 17, 2011 14:32 UTC (Thu) by nix (subscriber, #2304) [Link]

Bear in mind that Flash is being pounded very hard by the Chrome hackers, who do things like large-scale fuzzing, and running every .swf Google can find on the net through it. Most of these vulns came from there, so may never have been encountered in the real world.

I suspect that most software of the complexity of Flash has a similar number of vulnerabilities: they're just not being scrutinized so hard. (Most of them aren't network-accessible either.)

Now if only Adobe would release a PPAPI version of Flash, so those of us using Chromium could sandbox this horrible non-free lump away and still get at the large chunk of web content that requires Flash...

Sadly it's just not possible...

Posted Nov 17, 2011 16:06 UTC (Thu) by khim (subscriber, #9252) [Link]

Now if only Adobe would release a PPAPI version of Flash, so those of us using Chromium could sandbox this horrible non-free lump away and still get at the large chunk of web content that requires Flash...

Not gonna happen. Flash requires bunch of things (like raw file access, raw UDP access, atc) which are not accessible in pure PPAPI plugins. Sure, PPAPI may be extended to give this ability to one particular PPAPI plugin... but then your sandbox will look like a sieve.

flash-plugin: abandon all hope

Posted Nov 17, 2011 17:17 UTC (Thu) by raven667 (subscriber, #5198) [Link]

I'm sure that all the work google is doing is helping but it has always seemed like flash isn't developed with the highest standards of security and quality in mind although I can't possibly know that for sure, maybe it is just technically unfeasible for something as complex as that to not be riddled with holes.

nice title summary

Posted Nov 17, 2011 14:43 UTC (Thu) by mattdm (guest, #18) [Link]

I don't usually LOL when reading through the week's vulnerabilities. Thanks. :)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds