Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.801465
Kategorie:General
Titel:Adobe Flash Player Untrusted search path vulnerability (windows)
Zusammenfassung:This host is installed with Adobe Flash Player and is prone to;untrusted search path vulnerability.
Beschreibung:Summary:
This host is installed with Adobe Flash Player and is prone to
untrusted search path vulnerability.

Vulnerability Insight:
The application passes an insufficiently qualified path in
loading its external libraries 'dwmapi.dll'.

Vulnerability Impact:
Successful exploitation will allow attackers to trigger user to
save a malicious dll file in users Desktop.

Affected Software/OS:
Adobe Flash Player version 10.1.0 through 10.1.82.76

Solution:
Upgrade to Adobe Flash Player version 10.1.102.64 or later.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2010-3976
http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html
BugTraq ID: 44671
http://www.securityfocus.com/bid/44671
Bugtraq: 20100910 Adobe Flash Player IE version 10.1.x Insecure DLL Hijacking Vulnerability (dwmapi.dll) (Google Search)
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-09/msg00070.html
Bugtraq: 20101105 ASPR #2010-11-05-01: Remote Binary Planting in Adobe Flash Player (Google Search)
http://www.securityfocus.com/archive/1/514653/100/0/threaded
http://security.gentoo.org/glsa/glsa-201101-09.xml
HPdes Security Advisory: HPSBMA02663
http://marc.info/?l=bugtraq&m=130331642631603&w=2
HPdes Security Advisory: SSRT100428
http://core.yehg.net/lab/pr0js/advisories/dll_hijacking/%5Bflash_player%5D_10.1.x_insecure_dll_hijacking_%28dwmapi.dll%29
http://www.acrossecurity.com/aspr/ASPR-2010-11-05-1-PUB.txt
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6926
http://secunia.com/advisories/43026
SuSE Security Announcement: SUSE-SA:2010:055 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00002.html
http://www.vupen.com/english/advisories/2010/2903
http://www.vupen.com/english/advisories/2011/0192
CopyrightCopyright (C) 2010 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.