SuSE 11 / 11.1 Security Update : flash-player (SAT Patch Numbers 2539 / 2541)

high Nessus Plugin ID 50901

Language:

Synopsis

The remote SuSE 11 host is missing a security update.

Description

This update fixes multiple critical security vulnerabilities which allow an attacker to remotely execute arbitrary code or to cause a denial of service. The following CVE numbers have been assigned :

- CVE-2008-4546

- CVE-2009-3793

- CVE-2010-1297

- CVE-2010-2160

- CVE-2010-2161

- CVE-2010-2162

- CVE-2010-2163

- CVE-2010-2164

- CVE-2010-2165

- CVE-2010-2166

- CVE-2010-2167

- CVE-2010-2169

- CVE-2010-2170

- CVE-2010-2171

- CVE-2010-2172

- CVE-2010-2173

- CVE-2010-2174

- CVE-2010-2175

- CVE-2010-2176

- CVE-2010-2177

- CVE-2010-2178

- CVE-2010-2179

- CVE-2010-2180

- CVE-2010-2181

- CVE-2010-2182

- CVE-2010-2183

- CVE-2010-2184

- CVE-2010-2185

- CVE-2010-2186

- CVE-2010-2187

- CVE-2010-2188

- CVE-2010-2189

Solution

Apply SAT patch number 2539 / 2541 as appropriate.

See Also

https://bugzilla.novell.com/show_bug.cgi?id=612063

http://support.novell.com/security/cve/CVE-2008-4546.html

http://support.novell.com/security/cve/CVE-2009-3793.html

http://support.novell.com/security/cve/CVE-2010-1297.html

http://support.novell.com/security/cve/CVE-2010-2160.html

http://support.novell.com/security/cve/CVE-2010-2161.html

http://support.novell.com/security/cve/CVE-2010-2162.html

http://support.novell.com/security/cve/CVE-2010-2163.html

http://support.novell.com/security/cve/CVE-2010-2164.html

http://support.novell.com/security/cve/CVE-2010-2165.html

http://support.novell.com/security/cve/CVE-2010-2166.html

http://support.novell.com/security/cve/CVE-2010-2167.html

http://support.novell.com/security/cve/CVE-2010-2169.html

http://support.novell.com/security/cve/CVE-2010-2170.html

http://support.novell.com/security/cve/CVE-2010-2171.html

http://support.novell.com/security/cve/CVE-2010-2172.html

http://support.novell.com/security/cve/CVE-2010-2173.html

http://support.novell.com/security/cve/CVE-2010-2174.html

http://support.novell.com/security/cve/CVE-2010-2175.html

http://support.novell.com/security/cve/CVE-2010-2176.html

http://support.novell.com/security/cve/CVE-2010-2177.html

http://support.novell.com/security/cve/CVE-2010-2178.html

http://support.novell.com/security/cve/CVE-2010-2179.html

http://support.novell.com/security/cve/CVE-2010-2180.html

http://support.novell.com/security/cve/CVE-2010-2181.html

http://support.novell.com/security/cve/CVE-2010-2182.html

http://support.novell.com/security/cve/CVE-2010-2183.html

http://support.novell.com/security/cve/CVE-2010-2184.html

http://support.novell.com/security/cve/CVE-2010-2185.html

http://support.novell.com/security/cve/CVE-2010-2186.html

http://support.novell.com/security/cve/CVE-2010-2187.html

http://support.novell.com/security/cve/CVE-2010-2188.html

http://support.novell.com/security/cve/CVE-2010-2189.html

Plugin Details

Severity: High

ID: 50901

File Name: suse_11_flash-player-100611.nasl

Version: 1.35

Type: local

Agent: unix

Published: 12/2/2010

Updated: 6/8/2022

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.6

CVSS v2

Risk Factor: High

Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:novell:suse_linux:11:flash-player, cpe:/o:novell:suse_linux:11

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 6/11/2010

CISA Known Exploited Vulnerability Due Dates: 6/22/2022

Exploitable With

CANVAS (CANVAS)

Core Impact

Metasploit (Adobe Flash Player "newfunction" Invalid Pointer Use)

ExploitHub (EH-11-164)

Reference Information

CVE: CVE-2008-4546, CVE-2009-3793, CVE-2010-1297, CVE-2010-2160, CVE-2010-2161, CVE-2010-2162, CVE-2010-2163, CVE-2010-2164, CVE-2010-2165, CVE-2010-2166, CVE-2010-2167, CVE-2010-2169, CVE-2010-2170, CVE-2010-2171, CVE-2010-2172, CVE-2010-2173, CVE-2010-2174, CVE-2010-2175, CVE-2010-2176, CVE-2010-2177, CVE-2010-2178, CVE-2010-2179, CVE-2010-2180, CVE-2010-2181, CVE-2010-2182, CVE-2010-2183, CVE-2010-2184, CVE-2010-2185, CVE-2010-2186, CVE-2010-2187, CVE-2010-2188, CVE-2010-2189

CWE: 399