Flash Player < 10.3.181.14 Multiple Vulnerabilities (APSB11-12)

high Nessus Plugin ID 54299

Synopsis

A browser plugin is affected by multiple vulnerabilities.

Description

Several critical vulnerabilities exist in versions of Flash Player earlier than 10.3.181.14 :

- An unspecified information disclosure vulnerability exists. (CVE-2011-0579)

- An unspecified integer overflow vulnerability exists.
(CVE-2011-0618, CVE-2011-0628)

- Unspecified memory corruption vulnerabilities exist.
(CVE-2011-0619, CVE-2011-0620, CVE-2011-0621, CVE-2011-0622, CVE-2011-0627)

- Unspecified boundary-checking errors exist.
(CVE-2011-0623, CVE-2011-0624, CVE-2011-0625, CVE-2011-0626)

Solution

Upgrade to Adobe Flash version 10.3.181.14 or later.

See Also

http://www.nessus.org/u?8f9d009b

http://www.nessus.org/u?185a7880

http://www.nessus.org/u?03a97fa4

http://www.adobe.com/support/security/bulletins/apsb11-12.html

Plugin Details

Severity: High

ID: 54299

File Name: flash_player_apsb11-12.nasl

Version: 1.12

Type: local

Agent: windows

Family: Windows

Published: 5/18/2011

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.4

CVSS v2

Risk Factor: High

Base Score: 9.3

Temporal Score: 8.1

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/a:adobe:flash_player

Required KB Items: SMB/Flash_Player/installed

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 5/12/2011

Vulnerability Publication Date: 5/12/2011

Reference Information

CVE: CVE-2011-0579, CVE-2011-0618, CVE-2011-0619, CVE-2011-0620, CVE-2011-0621, CVE-2011-0622, CVE-2011-0623, CVE-2011-0624, CVE-2011-0625, CVE-2011-0626, CVE-2011-0627, CVE-2011-0628

BID: 47806, 47807, 47808, 47809, 47810, 47811, 47812, 47813, 47814, 47815, 47847, 47961

SECUNIA: 44590