![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.900807 |
Category: | General |
Title: | Adobe Products '.pdf' and '.swf' RCE Vulnerability (APSA09-03) - Linux |
Summary: | Multiple Adobe products are prone to a remote code execution; (RCE) vulnerability. |
Description: | Summary: Multiple Adobe products are prone to a remote code execution (RCE) vulnerability. Vulnerability Insight: - An unspecified error exists in Adobe Flash Player which can be exploited via a specially crafted flash application in a '.pdf' file. - Error occurs in 'authplay.dll' in Adobe Reader/Acrobat while processing '.swf' content and can be exploited to execute arbitrary code. Vulnerability Impact: Successful exploitation will allow remote attackers to cause code execution on the affected application. Affected Software/OS: - Adobe Reader/Acrobat version 9.x through 9.1.2 - Adobe Flash Player version 9.x through 9.0.159.0 and 10.x through 10.0.22.87 Solution: - Update to Adobe Reader/Acrobat version 9.1.3 or later - Update to Adobe Flash Player version 9.0.246.0, 10.0.32.18 or later CVSS Score: 9.3 CVSS Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2009-1862 http://lists.apple.com/archives/security-announce/2009/Sep/msg00003.html http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html BugTraq ID: 35759 http://www.securityfocus.com/bid/35759 CERT/CC vulnerability note: VU#259425 http://www.kb.cert.org/vuls/id/259425 http://security.gentoo.org/glsa/glsa-200908-04.xml http://blogs.adobe.com/psirt/2009/07/potential_adobe_reader_and_fla.html http://bugs.adobe.com/jira/browse/FP-1265 http://isc.sans.org/diary.html?storyid=6847 http://news.cnet.com/8301-27080_3-10293389-245.html http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-072209-2512-99 http://www.symantec.com/connect/blogs/next-generation-flash-vulnerability http://secunia.com/advisories/36193 http://secunia.com/advisories/36374 http://secunia.com/advisories/36701 http://sunsolve.sun.com/search/document.do?assetkey=1-66-266108-1 |
Copyright | Copyright (C) 2009 Greenbone AG |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |