SuSE 11.2 / 11.3 Security Update : flash-player (SAT Patch Numbers 8038 / 8039)

critical Nessus Plugin ID 68950

Synopsis

The remote SuSE 11 host is missing one or more security updates.

Description

Adobe flash-player has been updated to version 11.2.202.291 (ABSP13-17) which fixes bugs and security issues.

This update fixes the following security issues :

- a heap buffer overflow vulnerability that could have lead to code execution. (CVE-2013-3344)

- a memory corruption vulnerability that could have lead to code execution. (CVE-2013-3345)

- an integer overflow when resampling a user-supplied PCM buffer (CVE-2013-3347). Official advisory can be found on

http://www.adobe.com/support/security/bulletins/apsb13-17.html

Solution

Apply SAT patch number 8038 / 8039 as appropriate.

See Also

https://bugzilla.novell.com/show_bug.cgi?id=828810

http://support.novell.com/security/cve/CVE-2013-3344.html

http://support.novell.com/security/cve/CVE-2013-3345.html

http://support.novell.com/security/cve/CVE-2013-3347.html

Plugin Details

Severity: Critical

ID: 68950

File Name: suse_11_flash-player-130711.nasl

Version: 1.6

Type: local

Agent: unix

Published: 7/18/2013

Updated: 1/19/2021

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:novell:suse_linux:11:flash-player, p-cpe:/a:novell:suse_linux:11:flash-player-gnome, p-cpe:/a:novell:suse_linux:11:flash-player-kde4, cpe:/o:novell:suse_linux:11

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Patch Publication Date: 7/11/2013

Reference Information

CVE: CVE-2013-3344, CVE-2013-3345, CVE-2013-3347