Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.61120
Kategorie:FreeBSD Local Security Checks
Titel:FreeBSD Ports: linux-flashplugin
Zusammenfassung:The remote host is missing an update to the system; as announced in the referenced advisory.
Beschreibung:Summary:
The remote host is missing an update to the system
as announced in the referenced advisory.

Vulnerability Insight:
The following package is affected: linux-flashplugin

CVE-2007-0071
Integer overflow in Adobe Flash Player 9.0.115.0 and earlier, and
8.0.39.0 and earlier, allows remote attackers to execute arbitrary
code via a crafted SWF file with a negative Scene Count value, which
passes a signed comparison, is used as an offset of a NULL pointer,
and triggers a buffer overflow.

Solution:
Update your system with the appropriate patches or
software upgrades.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2007-0071
http://lists.apple.com/archives/security-announce/2008//May/msg00001.html
BugTraq ID: 28695
http://www.securityfocus.com/bid/28695
BugTraq ID: 29386
http://www.securityfocus.com/bid/29386
Cert/CC Advisory: TA08-100A
http://www.us-cert.gov/cas/techalerts/TA08-100A.html
Cert/CC Advisory: TA08-149A
http://www.us-cert.gov/cas/techalerts/TA08-149A.html
Cert/CC Advisory: TA08-150A
http://www.us-cert.gov/cas/techalerts/TA08-150A.html
CERT/CC vulnerability note: VU#159523
http://www.kb.cert.org/vuls/id/159523
CERT/CC vulnerability note: VU#395473
http://www.kb.cert.org/vuls/id/395473
http://www.gentoo.org/security/en/glsa/glsa-200804-21.xml
ISS Security Advisory: 20080408 Adobe Flash Player Invalid Pointer Vulnerability
http://www.iss.net/threats/289.html
http://blogs.adobe.com/psirt/2008/05/potential_flash_player_issue.html
http://documents.iss.net/whitepapers/IBM_X-Force_WP_final.pdf
http://isc.sans.org/diary.html?storyid=4465
http://www.matasano.com/log/1032/this-new-vulnerability-dowds-inhuman-flash-exploit/
http://www.zerodayinitiative.com/advisories/ZDI-08-032/
http://www.osvdb.org/44282
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10379
http://www.redhat.com/support/errata/RHSA-2008-0221.html
http://www.securitytracker.com/id?1019811
http://www.securitytracker.com/id?1020114
http://secunia.com/advisories/29763
http://secunia.com/advisories/29865
http://secunia.com/advisories/30404
http://secunia.com/advisories/30430
http://secunia.com/advisories/30507
http://sunsolve.sun.com/search/document.do?assetkey=1-26-238305-1
SuSE Security Announcement: SUSE-SA:2008:022 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00006.html
http://www.vupen.com/english/advisories/2008/1662/references
http://www.vupen.com/english/advisories/2008/1697
http://www.vupen.com/english/advisories/2008/1724/references
XForce ISS Database: multimedia-file-integer-overflow(37277)
https://exchange.xforce.ibmcloud.com/vulnerabilities/37277
CopyrightCopyright (C) 2008 E-Soft Inc.

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.