Adobe AIR for Mac <= 19.0.0.190 Multiple Vulnerabilities (APSB15-25)

This script is Copyright (C) 2015-2016 Tenable Network Security, Inc.


Synopsis :

The remote Mac OS X host has a browser plugin installed that is
affected by multiple vulnerabilities.

Description :

The version of Adobe AIR installed on the remote Mac OS X host is
equal or prior to version 19.0.0.190. It is, therefore, affected by
multiple vulnerabilities :

- An unspecified vulnerability exists related to the
defense-in-depth feature in the Flash Broker API. No
other details are available. (CVE-2015-5569)

- Multiple unspecified memory corruption issues exist due
to improper validation of user-supplied input. A remote
attacker can exploit this to execute arbitrary code.
(CVE-2015-7625, CVE-2015-7626, CVE-2015-7627,
CVE-2015-7630, CVE-2015-7633, CVE-2015-7634)

- A unspecified vulnerability exists that can be exploited
by a remote attacker to bypass the same-origin policy,
allowing the disclosure of sensitive information.
(CVE-2015-7628)

- Multiple unspecified use-after-free errors exist that
can be exploited by a remote attacker to deference
already freed memory, potentially allowing the
execution of arbitrary code. (CVE-2015-7629,
CVE-2015-7631, CVE-2015-7643, CVE-2015-7644)

- An unspecified buffer overflow condition exists due to
improper validation of user-supplied input. An attacker
can exploit this to execute arbitrary code.
(CVE-2015-7632)

See also :

https://helpx.adobe.com/security/products/flash-player/apsb15-25.html

Solution :

Upgrade to Adobe AIR version 19.0.0.213 or later.

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 6.9
(CVSS2#E:U/RL:OF/RC:C)
Public Exploit Available : false

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now