Korean
<< Back
VID 50017
Severity 40
Port 139,445
Protocol TCP
Class SMB
Detailed Description A version of Adobe Flash Player that is earlier than 10.3.183.20 This version is affected by multiple vulnerabilities.

- An error when parsing ActionScript could lead to code execution. (CVE-2012-2034)
- A stack overflow vulnerability exists that could lead to code execution. (CVE-2012-2035)
- An integer overflow vulnerability exists that could lead to code execution. (CVE-2012-2036)
- An error when parsing certain tags can be exploited to corrupt memory. (CVE-2012-2037)
- A Same Origin Policy bypass vulnerability exists that could lead to information disclosure. (CVE-2012-2038)
- A null dereference vulnerability exists that could lead to code execution. (CVE-2012-2039)
- A binary planting(DLL Preloading) vulnerability exists in the Flash Player installer that could lead to code execution. (CVE-2012-2040)

* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of these condition will result in the check not being performed and a False Negative for all vulnerable hosts.

* References:
http://www.adobe.com/support/security/bulletins/apsb12-14.html

* Platforms Affected:
Adobe Flash Player 10.3.183.19 and earlier 10.x versions.
Apple Mac OS X Any version
Linux Any version
Microsoft Windows Any version
Recommendation Upgrade to the latest version of Adobe Flash Player (10.3.183.20 or later), available from the Adobe Web site at http://www.adobe.com/support/flashplayer/downloads.html
Related URL CVE-2012-2034,CVE-2012-2035,CVE-2012-2036,CVE-2012-2037,CVE-2012-2038,CVE-2012-2039,CVE-2012-2040 (CVE)
Related URL 53887 (SecurityFocus)
Related URL (ISS)