flashplugin-nonfree-9.0.31 is vulnerable CVE-2007-3456

Bug #130993 reported by David H
258
Affects Status Importance Assigned to Milestone
Dapper Backports
Fix Released
Undecided
Unassigned

Bug Description

Could you please update flashplugin-nonfree package to 9.0.48. 9.0.31 is vulnerable. See https://bugs.launchpad.net/bugs/125986
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3456

I'm running flashplugin-nonfree 9.0.48.0.0ubuntu1~7.04.1 (from feisty-updates) on dapper and it seems to work fine.

Thanks

Revision history for this message
Scott Kitterman (kitterman) wrote :

Additionally, we need confirmation that it will build correctly in the dapper environment too.

Revision history for this message
Scott Kitterman (kitterman) wrote :

Marked the bug not confidential because it's already a public security vulnerability.

Revision history for this message
Saivann Carignan (oxmosys) wrote :

I suspect that this bug has been forgotten since the actual dapper backport flash version is 9.0.48. According to this fact, I set the status to fix released but you can set it back to new if there's still some work to do on this bug.

Changed in dapper-backports:
status: New → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.