Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.59670
Categoría:Turbolinux Local Security Tests
Título:Turbolinux TLSA-2007-36 (flash-player)
Resumen:NOSUMMARY
Descripción:Description:

The remote host is missing an update to flash-player
announced via advisory TLSA-2007-36.

Adobe Flash Player for Mozilla and Mozilla compatible.

- Flash Player allows remote attackers to obtain sensitive information
(browser keystrokes), which are leaked to the Flash Player applet.
- Integer overflow vulnerabilities have been discovered in Flash Playey.
- Flash Player insufficiently validates HTTP Referer headers,
which potentially allows remote attackers to conduct a CSRF attack
via a crafted SWF file.

This vulnerabilities may allow remote attackers to execute arbitrary code or
to obtain sensitive information via Flash File.

Solution: Please use the turbopkg (zabom) tool to apply the update.
http://www.securityspace.com/smysecure/catid.html?in=TLSA-2007-36

Risk factor : Critical

CVSS Score:
9.3

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2007-2022
BugTraq ID: 23437
http://www.securityfocus.com/bid/23437
Cert/CC Advisory: TA07-192A
http://www.us-cert.gov/cas/techalerts/TA07-192A.html
http://www.gentoo.org/security/en/glsa/glsa-200708-01.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2007:138
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9332
http://www.redhat.com/support/errata/RHSA-2007-0494.html
http://www.securitytracker.com/id?1017903
http://secunia.com/advisories/24877
http://secunia.com/advisories/25027
http://secunia.com/advisories/25432
http://secunia.com/advisories/25662
http://secunia.com/advisories/25669
http://secunia.com/advisories/25894
http://secunia.com/advisories/25933
http://secunia.com/advisories/26027
http://secunia.com/advisories/26118
http://secunia.com/advisories/26357
http://secunia.com/advisories/26860
http://secunia.com/advisories/28068
SGI Security Advisory: 20070602-01-P
ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.asc
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103167-1
http://sunsolve.sun.com/search/document.do?assetkey=1-66-201506-1
SuSE Security Announcement: SUSE-SA:2007:028 (Google Search)
http://www.novell.com/linux/security/advisories/2007_28_opera.html
SuSE Security Announcement: SUSE-SA:2007:046 (Google Search)
http://www.novell.com/linux/security/advisories/2007_46_flashplayer.html
SuSE Security Announcement: SUSE-SR:2007:012 (Google Search)
http://www.novell.com/linux/security/advisories/2007_12_sr.html
http://www.vupen.com/english/advisories/2007/1361
http://www.vupen.com/english/advisories/2007/2497
http://www.vupen.com/english/advisories/2007/4190
XForce ISS Database: opera-flash-player-unspecified(33595)
https://exchange.xforce.ibmcloud.com/vulnerabilities/33595
Common Vulnerability Exposure (CVE) ID: CVE-2007-3456
http://lists.apple.com/archives/security-announce/2007/Nov/msg00002.html
BugTraq ID: 24856
http://www.securityfocus.com/bid/24856
BugTraq ID: 26444
http://www.securityfocus.com/bid/26444
Bugtraq: 20070713 [MSA01110707] Flash Player/Plugin Video file parsing Remote CodeExecution (Google Search)
http://www.securityfocus.com/archive/1/473655/100/0/threaded
Bugtraq: 20070719 Wii's Internet Channel affected to Flash FLV parser vulnerability (Google Search)
http://www.securityfocus.com/archive/1/474163/100/200/threaded
Bugtraq: 20070720 FLEA-2007-0032-1: flashplayer (Google Search)
http://www.securityfocus.com/archive/1/474248/30/5760/threaded
Cert/CC Advisory: TA07-319A
http://www.us-cert.gov/cas/techalerts/TA07-319A.html
CERT/CC vulnerability note: VU#730785
http://www.kb.cert.org/vuls/id/730785
http://www.mindedsecurity.com/labs/advisories/MSA01110707
http://osvdb.org/38054
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11493
RedHat Security Advisories: RHSA-2007:0696
https://rhn.redhat.com/errata/RHSA-2007-0696.html
http://www.securitytracker.com/id?1018359
http://secunia.com/advisories/26057
http://secunia.com/advisories/27643
http://www.vupen.com/english/advisories/2007/3868
XForce ISS Database: flashplayer-swf-code-execution(35337)
https://exchange.xforce.ibmcloud.com/vulnerabilities/35337
Common Vulnerability Exposure (CVE) ID: CVE-2007-3457
CERT/CC vulnerability note: VU#138457
http://www.kb.cert.org/vuls/id/138457
http://www.osvdb.org/38049
XForce ISS Database: flashplayer-swf-httpreferer-csrf(35338)
https://exchange.xforce.ibmcloud.com/vulnerabilities/35338
CopyrightCopyright (c) 2007 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.