SuSE 10 安全更新:flash-player(ZYPP 修补程序编号 7071)

high Nessus 插件 ID 51736

简介

远程 SuSE 10 主机缺少与安全有关的修补程序。

描述

此更新修复了多个关键安全漏洞,攻击者可通过这些漏洞远程执行任意代码或造成拒绝服务。已分配下列 CVE 编号:

- CVE-2008-4546

- CVE-2009-3793

- CVE-2010-1297

- CVE-2010-2160

- CVE-2010-2161

- CVE-2010-2162

- CVE-2010-2163

- CVE-2010-2164

- CVE-2010-2165

- CVE-2010-2166

- CVE-2010-2167

- CVE-2010-2169

- CVE-2010-2170

- CVE-2010-2171

- CVE-2010-2172

- CVE-2010-2173

- CVE-2010-2174

- CVE-2010-2175

- CVE-2010-2176

- CVE-2010-2177

- CVE-2010-2178

- CVE-2010-2179

- CVE-2010-2180

- CVE-2010-2181

- CVE-2010-2182

- CVE-2010-2183

- CVE-2010-2184

- CVE-2010-2185

- CVE-2010-2186

- CVE-2010-2187

- CVE-2010-2188

- CVE-2010-2189

解决方案

应用 ZYPP 修补程序编号 7071。

另见

http://support.novell.com/security/cve/CVE-2010-2166.html

http://support.novell.com/security/cve/CVE-2010-2167.html

http://support.novell.com/security/cve/CVE-2010-2169.html

http://support.novell.com/security/cve/CVE-2010-2170.html

http://support.novell.com/security/cve/CVE-2010-2171.html

http://support.novell.com/security/cve/CVE-2010-2172.html

http://support.novell.com/security/cve/CVE-2010-2173.html

http://support.novell.com/security/cve/CVE-2010-2174.html

http://support.novell.com/security/cve/CVE-2010-2175.html

http://support.novell.com/security/cve/CVE-2010-2176.html

http://support.novell.com/security/cve/CVE-2010-2177.html

http://support.novell.com/security/cve/CVE-2010-2178.html

http://support.novell.com/security/cve/CVE-2010-2179.html

http://support.novell.com/security/cve/CVE-2010-2180.html

http://support.novell.com/security/cve/CVE-2010-2181.html

http://support.novell.com/security/cve/CVE-2010-2182.html

http://support.novell.com/security/cve/CVE-2008-4546.html

http://support.novell.com/security/cve/CVE-2009-3793.html

http://support.novell.com/security/cve/CVE-2010-1297.html

http://support.novell.com/security/cve/CVE-2010-2160.html

http://support.novell.com/security/cve/CVE-2010-2161.html

http://support.novell.com/security/cve/CVE-2010-2162.html

http://support.novell.com/security/cve/CVE-2010-2163.html

http://support.novell.com/security/cve/CVE-2010-2164.html

http://support.novell.com/security/cve/CVE-2010-2165.html

http://support.novell.com/security/cve/CVE-2010-2183.html

http://support.novell.com/security/cve/CVE-2010-2184.html

http://support.novell.com/security/cve/CVE-2010-2185.html

http://support.novell.com/security/cve/CVE-2010-2186.html

http://support.novell.com/security/cve/CVE-2010-2187.html

http://support.novell.com/security/cve/CVE-2010-2188.html

http://support.novell.com/security/cve/CVE-2010-2189.html

插件详情

严重性: High

ID: 51736

文件名: suse_flash-player-7071.nasl

版本: 1.33

类型: local

代理: unix

发布时间: 2011/1/27

最近更新时间: 2022/6/8

支持的传感器: Nessus Agent, Nessus

风险信息

VPR

风险因素: Critical

分数: 9.6

CVSS v2

风险因素: High

基本分数: 9.3

矢量: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

漏洞信息

CPE: cpe:/o:suse:suse_linux

必需的 KB 项: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

可利用: true

易利用性: Exploits are available

补丁发布日期: 2010/6/11

CISA 已知可遭利用的漏洞到期日期: 2022/6/22

可利用的方式

CANVAS (CANVAS)

Core Impact

Metasploit (Adobe Flash Player "newfunction" Invalid Pointer Use)

ExploitHub (EH-11-164)

参考资料信息

CVE: CVE-2008-4546, CVE-2009-3793, CVE-2010-1297, CVE-2010-2160, CVE-2010-2161, CVE-2010-2162, CVE-2010-2163, CVE-2010-2164, CVE-2010-2165, CVE-2010-2166, CVE-2010-2167, CVE-2010-2169, CVE-2010-2170, CVE-2010-2171, CVE-2010-2172, CVE-2010-2173, CVE-2010-2174, CVE-2010-2175, CVE-2010-2176, CVE-2010-2177, CVE-2010-2178, CVE-2010-2179, CVE-2010-2180, CVE-2010-2181, CVE-2010-2182, CVE-2010-2183, CVE-2010-2184, CVE-2010-2185, CVE-2010-2186, CVE-2010-2187, CVE-2010-2188, CVE-2010-2189

CWE: 399