SuSE 11.2 / 11.3 Security Update : flash-player (SAT Patch Numbers 8876 / 8880)

critical Nessus Plugin ID 72455

Synopsis

The remote SuSE 11 host is missing one or more security updates.

Description

This update resolves an integer underflow vulnerability that could have been exploited to execute arbitrary code on the affected system.
(CVE-2014-0497)

More information:
http://helpx.adobe.com/security/products/flash-player/apsb14-04.html

Solution

Apply SAT patch number 8876 / 8880 as appropriate.

See Also

https://bugzilla.novell.com/show_bug.cgi?id=862288

http://support.novell.com/security/cve/CVE-2014-0497.html

Plugin Details

Severity: Critical

ID: 72455

File Name: suse_11_flash-player-140206.nasl

Version: 1.9

Type: local

Agent: unix

Published: 2/12/2014

Updated: 9/17/2024

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.5

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2014-0497

Vulnerability Information

CPE: p-cpe:/a:novell:suse_linux:11:flash-player, p-cpe:/a:novell:suse_linux:11:flash-player-gnome, p-cpe:/a:novell:suse_linux:11:flash-player-kde4, cpe:/o:novell:suse_linux:11

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2/6/2014

CISA Known Exploited Vulnerability Due Dates: 10/8/2024

Exploitable With

Core Impact

Metasploit (Adobe Flash Player Integer Underflow Remote Code Execution)

Reference Information

CVE: CVE-2014-0497