NASLDB: Flash Player <= 10.3.183.19 / 11.3.300.256 Multiple Vulnerabilities (APSB12-14)
General
ID: 59426
Name: Flash Player <= 10.3.183.19 / 11.3.300.256 Multiple Vulnerabilities (APSB12-14)
Summary: Checks version of Flash Player
Credits: Tenable Network Security, Inc.
Classification
Risk: –
CVSS: –
CVSS Base Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C
CVSS Temporal Vector: CVSS2#E:U/RL:OF/RC:C
Port: –
Family: Windows
Type: Local
Description
According to its version, the instance of Flash Player installed on
the remote Windows host is 10.x equal to or earlier than 10.3.183.19
or 11.x equal to or earlier than 11.3.300.256. It is, therefore,
potentially affected by multiple vulnerabilities :
– Multiple memory corruption vulnerabilities exist that
could lead to code execution. (CVE-2012-2034,
CVE-2012-2037)
– A stack overflow vulnerability exists that could lead to
code execution. (CVE-2012-2035)
– An integer overflow vulnerability exists that could lead
to code execution. (CVE-2012-2036)
– A security bypass vulnerability exists that could lead
to information disclosure. (CVE-2012-2038)
– A null dereference vulnerability exists that could lead
to code execution. (CVE-2012-2039)
– A binary planting vulnerability exists in the Flash
Player installer that could lead to code execution.
(CVE-2012-2040)
Exploiting
Exploit Available: False
Exploitability Ease: No known exploits are available
Sources
CVE: CVE-2012-2034
OSVDB: –
Bugtraq: –
scipID: –
Timeline
Vulnerability Disclosure: 2012/06/08
Patch Release: 2012/06/08
Plugin Release: 2012/06/09
Plugin
Version: 1.5
Filename: flash_player_apsb12-14.nasl
Filesize: 5593 bytes
MD5 Hash: de487099400c6cd50285e088d1c31965
Identification: SMB/transport
Require Keys: SMB/Flash_Player/installed
Dependencies: "flash_player_installed.nasl"
Copyright: This script is Copyright© 2012 Tenable Network Security, Inc.
- Letzte Plugins
- USN-1611-1 : thunderbird vulnerabilities
- USN-1610-1 : linux vulnerability
- USN-1609-1 : linux-ti-omap4 vulnerability
- SuSE 10 Security Update : PostgreSQL
- RHSA-2012-1364: bind97
- RHSA-2012-1363: bind
- RHSA-2012-1362: thunderbird
- RHSA-2012-1361: xulrunner
- Mandriva Linux Security Advisory : graphicsmagick
- FreeBSD : phpMyAdmin — Multiple XSS due to unescaped HTML output in Trigger, Procedure and Event pages and Fetching the version information from a non-SSL site is vulnerable to a MITM attack













