RHEL 3 / 4 : flash-plugin (RHSA-2007:0009)

This script is Copyright (C) 2013-2014 Tenable Network Security, Inc.


Synopsis :

The remote Red Hat host is missing a security update.

Description :

An updated Adobe Flash Player package that fixes a security issue is
now available.

This update has been rated as having moderate security impact by the
Red Hat Security Response Team.

The flash-plugin package contains a Firefox-compatible Adobe Flash
Player browser plug-in.

A flaw was found in the way the Adobe Flash Player generates HTTP
requests. It was possible for a malicious Adobe Flash file to modify
the HTTP header of the client request, which could be leveraged to
exploit certain HTTP proxy and web server flaws. (CVE-2006-5330)

Users of Adobe Flash Player should upgrade to this updated package,
which contains version 7.0.69 and is not vulnerable to this issue.

See also :

https://www.redhat.com/security/data/cve/CVE-2006-5330.html
http://rhn.redhat.com/errata/RHSA-2007-0009.html

Solution :

Update the affected flash-plugin package.

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N)

Family: Red Hat Local Security Checks

Nessus Plugin ID: 63834 ()

Bugtraq ID:

CVE ID: CVE-2006-5330