Arch Linux Security Advisory ASA-201806-7 ========================================= Severity: Critical Date : 2018-06-09 CVE-ID : CVE-2018-4945 CVE-2018-5000 CVE-2018-5001 CVE-2018-5002 Package : flashplugin Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-716 Summary ======= The package flashplugin before version 30.0.0.113-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure. Resolution ========== Upgrade to 30.0.0.113-1. # pacman -Syu "flashplugin>=30.0.0.113-1" The problems have been fixed upstream in version 30.0.0.113. Workaround ========== None. Description =========== - CVE-2018-4945 (arbitrary code execution) A type confusion issue has been found in Adobe Flash Player before 30.0.0.113, leading to arbitrary code execution. - CVE-2018-5000 (information disclosure) An integer overflow issue has been found in Adobe Flash Player before 30.0.0.113, leading to information disclosure. - CVE-2018-5001 (information disclosure) An out-of-bounds read has been found in Adobe Flash Player before 30.0.0.113, leading to information disclosure. - CVE-2018-5002 (arbitrary code execution) A stack-based buffer overflow has been found in Adobe Flash Player before 30.0.0.113, leading to arbitrary code execution. Impact ====== A remote attacker can access sensitive information or execute arbitrary code via a crafted Flash file. References ========== https://helpx.adobe.com/security/products/flash-player/apsb18-19.html https://security.archlinux.org/CVE-2018-4945 https://security.archlinux.org/CVE-2018-5000 https://security.archlinux.org/CVE-2018-5001 https://security.archlinux.org/CVE-2018-5002