| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.900806 |
| Category: | General |
| Title: | Adobe Products '.pdf' and '.swf' Code Execution Vulnerability - July09 (Win) |
| Summary: | Check for the version of Adobe Products |
| Description: | Overview: This host is installed with Adobe products and are prone to remote code execution vulnerability. Vulnerability Insight: - An unspecified error exists in Adobe Flash Player which can be exploited via a specially crafted flash application in a '.pdf' file. - Error occurs in 'authplay.dll' in Adobe Reader/Acrobat whlie processing '.swf' content and can be exploited to execute arbitrary code. Impact: Successful exploitation will allow remote attackers to cause code execution. Impact Level: Application Affected Software/OS: Adobe Reader/Acrobat version 9.x to 9.1.2 Adobe Flash Player version 9.x to 9.0.159.0 and 10.x to 10.0.22.87 on Windows. Fix: Upgrade to Adobe Reader/Acrobat version 9.1.3 or later Upgrade to Adobe Flash Player version 9.0.246.0 or 10.0.32.18 or later For updates refer to http://www.adobe.com/ References: http://secunia.com/advisories/35948/ http://secunia.com/advisories/35949/ http://www.kb.cert.org/vuls/id/259425 http://www.adobe.com/support/security/advisories/apsa09-03.html |
| Cross-Ref: |
BugTraq ID: 35759 Common Vulnerability Exposure (CVE) ID: CVE-2009-1862 http://blogs.adobe.com/psirt/2009/07/potential_adobe_reader_and_fla.html http://bugs.adobe.com/jira/browse/FP-1265 http://isc.sans.org/diary.html?storyid=6847 http://news.cnet.com/8301-27080_3-10293389-245.html http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-072209-2512-99 http://www.symantec.com/connect/blogs/next-generation-flash-vulnerability http://lists.apple.com/archives/security-announce/2009/Sep/msg00003.html http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html http://security.gentoo.org/glsa/glsa-200908-04.xml http://sunsolve.sun.com/search/document.do?assetkey=1-66-266108-1 CERT/CC vulnerability note: VU#259425 http://www.kb.cert.org/vuls/id/259425 http://www.securityfocus.com/bid/35759 http://secunia.com/advisories/36193 http://secunia.com/advisories/36374 http://secunia.com/advisories/36701 |
| Copyright | Copyright (C) 2009 SecPod |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|