Adobe Flash Player: Multiple vulnerabilities Multiple vulnerabilities have been identified, the worst of which allow arbitrary code execution on a user's system via a malicious Flash file. adobe-flash April 18, 2008 May 28, 2009: 02 204344 remote 9.0.124.0 9.0.124.0

The Adobe Flash Player is a renderer for the popular SWF file format, which is commonly used to provide interactive websites, digital experiences and mobile content.

Multiple vulnerabilities have been discovered in Adobe Flash:

A remote attacker could entice a user to open a specially crafted file (usually in a web browser), possibly leading to the execution of arbitrary code with the privileges of the user running the Adobe Flash Player. The attacker could also cause a user's machine to send HTTP requests to other hosts, establish TCP sessions with arbitrary hosts, bypass the security sandbox model, or conduct Cross-Site Scripting and Cross-Site Request Forgery attacks.

There is no known workaround at this time.

All Adobe Flash Player users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=www-plugins/adobe-flash-9.0.124.0"
CVE-2007-0071 CVE-2007-5275 CVE-2007-6019 CVE-2007-6243 CVE-2007-6637 CVE-2008-1654 CVE-2008-1655 vorlon rbu rbu