Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.58033
Category:SuSE Local Security Checks
Title:SuSE Security Advisory SUSE-SA:2006:077 (flash-player)
Summary:NOSUMMARY
Description:Description:

The remote host is missing updates announced in
advisory SUSE-SA:2006:077.

This security update brings the Adobe Flash Player to version 7.0.69.
The update fixes the following security problem:

CVE-2006-5330: CRLF injection vulnerabilities in Adobe Flash Player
allows remote attackers to modify HTTP headers of client requests
and conduct HTTP Request Splitting attacks via CRLF sequences in
arguments to the ActionScript functions (1) XML.addRequestHeader and
(2) XML.contentType.

The flexibility of the attack varies depending on the type of web
browser being used.

Solution:
Update your system with the packages as indicated in
the referenced security advisory.

http://www.securityspace.com/smysecure/catid.html?in=SUSE-SA:2006:077

Risk factor : Medium

CVSS Score:
5.0

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2006-5330
http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html
BugTraq ID: 20592
http://www.securityfocus.com/bid/20592
Bugtraq: 20061017 Rapid7 Advisory R7-0026: HTTP Header Injection Vulnerabilities in the Flash Player Plugin (Google Search)
http://www.securityfocus.com/archive/1/448997/100/0/threaded
Cert/CC Advisory: TA07-072A
http://www.us-cert.gov/cas/techalerts/TA07-072A.html
http://www.rapid7.com/advisories/R7-0026.jsp
http://www.osvdb.org/29863
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11405
http://www.redhat.com/support/errata/RHSA-2007-0009.html
http://securitytracker.com/id?1017078
http://secunia.com/advisories/22467
http://secunia.com/advisories/23324
http://secunia.com/advisories/23581
http://secunia.com/advisories/24479
http://secunia.com/advisories/25467
http://securityreason.com/securityalert/1737
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102932-1
SuSE Security Announcement: SUSE-SA:2006:077 (Google Search)
http://lists.suse.com/archive/suse-security-announce/2006-Dec/0006.html
http://www.vupen.com/english/advisories/2006/4094
http://www.vupen.com/english/advisories/2007/0930
http://www.vupen.com/english/advisories/2007/1999
XForce ISS Database: flashplayer-multiple-xsrf(29634)
https://exchange.xforce.ibmcloud.com/vulnerabilities/29634
CopyrightCopyright (c) 2007 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.