Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.1.10.2015.0109
Categoría:Mageia Linux Local Security Checks
Título:Mageia: Security Advisory (MGASA-2015-0109)
Resumen:The remote host is missing an update for the 'flash-player-plugin' package(s) announced via the MGASA-2015-0109 advisory.
Descripción:Summary:
The remote host is missing an update for the 'flash-player-plugin' package(s) announced via the MGASA-2015-0109 advisory.

Vulnerability Insight:
Adobe Flash Player 11.2.202.451 contains fixes to critical security
vulnerabilities found in earlier versions that could cause a crash and
potentially allow an attacker to take control of the affected system.

This update resolves memory corruption vulnerabilities that could lead
to code execution (CVE-2015-0332, CVE-2015-0333, CVE-2015-0335,
CVE-2015-0339).

This update resolves type confusion vulnerabilities that could lead
to code execution (CVE-2015-0334, CVE-2015-0336).

This update resolves a vulnerability that could lead to a cross-domain
policy bypass (CVE-2015-0337).

This update resolves a vulnerability that could lead to a file upload
restriction bypass (CVE-2015-0340).

This update resolves an integer overflow vulnerability that could lead
to code execution (CVE-2015-0338).

This update resolves use-after-free vulnerabilities that could lead
to code execution (CVE-2015-0341, CVE-2015-0342).

Additionally, the Flash Plugin package downloaded from Adobe is now
verified using recorded sha256sum and file size instead of using
insecure md5sum (mga#15229).

Affected Software/OS:
'flash-player-plugin' package(s) on Mageia 4.

Solution:
Please install the updated package(s).

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2015-0332
https://security.gentoo.org/glsa/201503-09
RedHat Security Advisories: RHSA-2015:0697
http://rhn.redhat.com/errata/RHSA-2015-0697.html
http://www.securitytracker.com/id/1031922
SuSE Security Announcement: SUSE-SU-2015:0491 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00015.html
SuSE Security Announcement: SUSE-SU-2015:0493 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00016.html
SuSE Security Announcement: openSUSE-SU-2015:0490 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00014.html
SuSE Security Announcement: openSUSE-SU-2015:0496 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00017.html
SuSE Security Announcement: openSUSE-SU-2015:0725 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00013.html
Common Vulnerability Exposure (CVE) ID: CVE-2015-0333
Common Vulnerability Exposure (CVE) ID: CVE-2015-0334
Common Vulnerability Exposure (CVE) ID: CVE-2015-0335
Common Vulnerability Exposure (CVE) ID: CVE-2015-0336
BugTraq ID: 73084
http://www.securityfocus.com/bid/73084
https://www.exploit-db.com/exploits/36962/
Common Vulnerability Exposure (CVE) ID: CVE-2015-0337
Common Vulnerability Exposure (CVE) ID: CVE-2015-0338
Common Vulnerability Exposure (CVE) ID: CVE-2015-0339
Common Vulnerability Exposure (CVE) ID: CVE-2015-0340
Common Vulnerability Exposure (CVE) ID: CVE-2015-0341
Common Vulnerability Exposure (CVE) ID: CVE-2015-0342
CopyrightCopyright (C) 2022 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.