Adobe AIR <= 3.0 Multiple Vulnerabilities (APSB11-28)
Critical Nessus Plugin ID 56959
SynopsisThe remote Windows host contains a version of Adobe AIR that is affected by multiple vulnerabilities.
DescriptionAccording to its version, the instance of Adobe AIR installed on the remote Windows host is 3.0 or earlier and is reportedly affected by several critical vulnerabilities :
- Several unspecified memory corruption errors exist that could lead to code execution.
(CVE-2011-2445, CVE-2011-2451, CVE-2011-2452, CVE-2011-2453, CVE-2011-2454, CVE-2011-2455, CVE-2011-2459, CVE-2011-2460)
- An unspecified heap corruption error exists that could lead to code execution. (CVE-2011-2450)
- An unspecified buffer overflow error exists that could lead to code execution. (CVE-2011-2456)
- An unspecified stack overflow error exists that could lead to code execution. (CVE-2011-2457)
- An unspecified error related to Internet Explorer can allow cross-domain policy violations. (CVE-2011-2458)
By tricking a user on the affected system into opening a specially crafted document with Flash content, an attacker could leverage these vulnerabilities to execute arbitrary code remotely on the system subject to the user's privileges.
SolutionUpgrade to Adobe AIR 3.1 (188.8.131.5280) or later.