http://macromedia.mplug.org/ Yeah, this isn't a Fedora package, however I know many Fedora users are using the older version of this package so I figure it would be appropriate to announce here. You can optionally configure yum to point to the repository for auto-upgrade in the future. --------------------------------------------------------------------- Macromedia Flash Player Update Notification CVE-2005-2628 --------------------------------------------------------------------- Name : flash-plugin Version : 7.0.61 Release : 1 Summary : Flash Player for x86 Linux Description : Macromedia Flash Plugin 7.0.61 --------------------------------------------------------------------- Update Information: Updated Macromedia Flash Player packages that fix a security issue are now available. This update has been rated as having critical security impact by the Red Hat Security Response Team. The flash-plugin package contains a Mozilla-compatible Macromedia Flash Player browser plug-in. A buffer overflow bug was discovered in the Macromedia Flash Player. It may be possible to execute arbitrary code on a victim's machine if the victim opens a malicious Macromedia Flash file. The Common Vulnerabilities and Exposures project assigned the name CVE-2005-2628 to this issue. http://macromedia.mplug.org/ Users of Macromedia Flash Player should download the package from this site, which contains version 7.0.61 and is not vulnerable to this issue. --------------------------------------------------------------------- -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 This update can be downloaded from: http://macromedia.mplug.org/ SHA1SUM: 04861e5d6ded433549caf9a70b5195d341c15103 flash-plugin-7.0.61-1.i386.rpm MD5SUM: 7ef4f4c53270c4930c873181fa9a1a96 flash-plugin-7.0.61-1.i386.rpm -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.1 (GNU/Linux) iD8DBQFDh4Sla93+jlSirPERAntMAJ9EOhR7JtODNjLUo19o/9Ch6ROsngCdFG05 UNSlq0bFBiCFgBaTpDyEyxc= =F9Pw -----END PGP SIGNATURE----- --------------------------------------------------------------------- Warren Togami wtogami@xxxxxxxxxx