Adobe AIR < 1.5.3 Multiple Vulnerabilities (APSB09-19)

Medium Nessus Network Monitor Plugin ID 5256

Synopsis

The remote host is vulnerable to multiple attack vectors.

Description

The remote Windows host contains a version of Adobe AIR player that is earlier than 1.5.3. Such versions are reportedly affected by multiple vulnerabilities :

- A vulnerability in the parsing of JPEG data that could potentially lead to code execution. (CVE-2009-3794)

- A data injection vulnerability that could potentially lead to code execution. (CVE-2009-3796)

- A memory corruption vulnerability that could potentially lead to code execution. (CVE-2009-3797)

- A memory corruption vulnerability that could potentially lead to code execution. (CVE-2009-3798)

- An integer overflow vulnerability that could potentially lead to code execution. (CVE-2009-3799)

- Multiple crash vulnerabilities that could potentially lead to code execution. (CVE-2009-3800)

- A Windows-only local file name access vulnerability in the Flash Player ActiveX control that could potentially lead to information disclosure. (CVE-2009-3951)

Solution

Upgrade to Adobe AIR 1.5.3 or later.

See Also

http://www.adobe.com/support/security/bulletins/apsb09-19.html

Plugin Details

Severity: Medium

ID: 5256

File Name: 5256.prm

Family: Web Clients

Published: 2009/12/09

Modified: 2016/01/19

Dependencies: 4759

Nessus ID: 43069

Risk Information

Risk Factor: Medium

CVSSv2

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

CVSSv3

Base Score: 5.6

Temporal Score: 4.9

Vector: CVSS3#AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS3#E:U/RL:O/RC:C

Vulnerability Information

Patch Publication Date: 2009/12/08

Vulnerability Publication Date: 2009/12/03

Reference Information

CVE: CVE-2009-3794, CVE-2009-3796, CVE-2009-3797, CVE-2009-3798, CVE-2009-3799, CVE-2009-3800, CVE-2009-3951

BID: 37199, 37266, 37267, 37269, 37270, 37273, 37275

OSVDB: 60885, 60886, 60887, 60888, 60889, 60890, 60891