Korean
<< Back
VID 28260
Severity 40
Port 139,445
Protocol TCP
Class SMB
Detailed Description A version of Adobe Flash Player that is earlier than 10.0.42.34 / 9.0.260. Such Versions are reportedly affected by multiple vulnerabilities.

- A vulnerability in the parsing of JPEG data could lead to code execution (CVE-2009-3794)
- A data injection vulnerability could lead to code execution. (CVE-2009-3796)
- A memory corruption vulnerability could lead to code execution. (CVE-2009-3797)
- A memory corruption vulnerability could lead to code execution. (CVE-2009-3798)
- An integer overflow vulnerability could lead to code execution. (CVE-2009-3799)
- Multiple crash vulnerabilities could lead to code execution. (CVE-2009-3800)
- A Windows-only local file name access vulnerability could lead to information disclosure. (CVE-2009-3591)

* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of these condition will result in the check not being performed and a False Negative for all vulnerable hosts.

* References:
http://www.adobe.com/support/security/bulletins/apsb09-19.html

* Platforms Affected:
Adobe Flash Player 9.0.260 and 10.0.42.34 and earlier 9.x and 10.x versions.
Apple Mac OS X Any version
Linux Any version
Microsoft Windows Any version
Recommendation Upgrade to the latest version of Adobe Flash Player (9.0.260 or 10.0.42.34 or later), available from the Adobe Web site at http://get.adobe.com/kr/air/
Related URL CVE-2009-3794,CVE-2009-3796,CVE-2009-3797,CVE-2009-3798,CVE-2009-3799,CVE-2009-3800,CVE-2009-3951 (CVE)
Related URL 37266,37267,37269,37270,37272,37273,37275 (SecurityFocus)
Related URL (ISS)