Adobe Flash Player and AIR Unspecified Privilege Escalation Vulnerability
BID:35900
Info
Adobe Flash Player and AIR Unspecified Privilege Escalation Vulnerability
| Bugtraq ID: | 35900 |
| Class: | Unknown |
| CVE: |
CVE-2009-1863 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 30 2009 12:00AM |
| Updated: | May 12 2015 07:49PM |
| Credit: | Mike Wroe |
| Vulnerable: |
Turbolinux Client 2008 SuSE Suse Linux Enterprise Desktop 11 SuSE Suse Linux Enterprise Desktop 10 SP2 S.u.S.E. openSUSE 11.1 S.u.S.E. openSUSE 11.0 S.u.S.E. openSUSE 10.3 S.u.S.E. Novell Linux Desktop 9.0 Redhat Enterprise Linux WS Extras 4 Redhat Enterprise Linux WS Extras 3 Redhat Enterprise Linux Supplementary 5 server Redhat Enterprise Linux Extras 4 Redhat Enterprise Linux Extras 3 Redhat Enterprise Linux ES Extras 4 Redhat Enterprise Linux ES Extras 3 Redhat Enterprise Linux Desktop Supplementary 5 client Redhat Enterprise Linux AS Extras 4 Redhat Enterprise Linux AS Extras 3 Redhat Desktop Extras 4 Redhat Desktop Extras 3 Pardus Linux 2009 0 Pardus Linux 2008 0 Gentoo Linux Avaya Interactive Response 4.0 Avaya Interactive Response 3.0 Apple Mac OS X Server 10.5.8 Apple Mac OS X Server 10.5.7 Apple Mac OS X Server 10.5.6 Apple Mac OS X Server 10.5.5 Apple Mac OS X Server 10.5.4 Apple Mac OS X Server 10.5.3 Apple Mac OS X Server 10.5.2 Apple Mac OS X Server 10.5.1 Apple Mac OS X Server 10.4.11 Apple Mac OS X Server 10.4.10 Apple Mac OS X Server 10.4.9 Apple Mac OS X Server 10.4.8 Apple Mac OS X Server 10.4.7 Apple Mac OS X Server 10.4.6 Apple Mac OS X Server 10.4.5 Apple Mac OS X Server 10.4.4 Apple Mac OS X Server 10.4.3 Apple Mac OS X Server 10.4.2 Apple Mac OS X Server 10.4.1 Apple Mac OS X Server 10.4 Apple Mac OS X Server 10.6 Apple Mac OS X Server 10.5 Apple Mac OS X 10.5.8 Apple Mac OS X 10.5.7 Apple Mac OS X 10.5.6 Apple Mac OS X 10.5.5 Apple Mac OS X 10.5.4 Apple Mac OS X 10.5.3 Apple Mac OS X 10.5.2 Apple Mac OS X 10.5.1 Apple Mac OS X 10.4.11 Apple Mac OS X 10.4.10 Apple Mac OS X 10.4.9 Apple Mac OS X 10.4.8 Apple Mac OS X 10.4.7 Apple Mac OS X 10.4.6 Apple Mac OS X 10.4.5 Apple Mac OS X 10.4.4 Apple Mac OS X 10.4.3 Apple Mac OS X 10.4.2 Apple Mac OS X 10.4.1 Apple Mac OS X 10.4 Apple Mac OS X 10.6 Apple Mac OS X 10.5 Adobe Flash Player 10.0.22 .87 Adobe Flash Player 10.0.15 .3 Adobe Flash Player 10.0.12 .36 Adobe Flash Player 10.0.12 .35 Adobe Flash Player 9.0.152 .0 Adobe Flash Player 9.0.151 .0 Adobe Flash Player 9.0.124 .0 Adobe Flash Player 9.0.48.0 Adobe Flash Player 9.0.47.0 Adobe Flash Player 9.0.45.0 Adobe Flash Player 9.0.31.0 Adobe Flash Player 9.0.28.0 Adobe Flash Player 9.0.159.0 Adobe Flash Player 9.0.115.0 Adobe Flash Player 9 Adobe Flash Player 10 Adobe AIR 1.5.1 Adobe AIR 1.5 Adobe AIR 1.1 Adobe AIR 1.01 Adobe AIR 1.0 |
| Not Vulnerable: |
Apple Mac OS X Server 10.6.1 Apple Mac OS X 10.6.1 Adobe Flash Player 9.0.246 0 Adobe Flash Player 10.0.32.18 Adobe AIR 1.5.2 |
Discussion
Adobe Flash Player and AIR Unspecified Privilege Escalation Vulnerability
Adobe Flash Player and Adobe AIR are prone to an unspecified privilege-escalation vulnerability.
Very few details are available regarding this issue. We will update this BID as more information emerges.
Attackers can exploit this issue to execute arbitrary code with elevated privileges. Successful exploits will compromise the affected application and possibly the computer.
NOTE: This issue was previously covered in BID 35890 (Adobe Flash Player and AIR Multiple Security Vulnerabilities) but has been given its own record to better document it.
UPDATE (September 4, 2009): Mac OS X 10.6 reportedly ships with Flash Player 10.0.23.1, which will overwrite any installed version of Flash Player when Mac OS X is being installed.
This issue affects versions *prior to* the following:
Flash Player 10.0.32.18
AIR 1.5.2
Adobe Flash Player and Adobe AIR are prone to an unspecified privilege-escalation vulnerability.
Very few details are available regarding this issue. We will update this BID as more information emerges.
Attackers can exploit this issue to execute arbitrary code with elevated privileges. Successful exploits will compromise the affected application and possibly the computer.
NOTE: This issue was previously covered in BID 35890 (Adobe Flash Player and AIR Multiple Security Vulnerabilities) but has been given its own record to better document it.
UPDATE (September 4, 2009): Mac OS X 10.6 reportedly ships with Flash Player 10.0.23.1, which will overwrite any installed version of Flash Player when Mac OS X is being installed.
This issue affects versions *prior to* the following:
Flash Player 10.0.32.18
AIR 1.5.2
Exploit / POC
Adobe Flash Player and AIR Unspecified Privilege Escalation Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Adobe Flash Player and AIR Unspecified Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references for details.
Apple Mac OS X Server 10.6
S.u.S.E. openSUSE 11.0
Apple Mac OS X 10.6
S.u.S.E. openSUSE 11.1
Turbolinux Client 2008
Apple Mac OS X 10.4.11
Apple Mac OS X Server 10.4.11
Apple Mac OS X Server 10.5.8
Apple Mac OS X 10.5.8
Solution:
Updates are available. Please see the references for details.
Apple Mac OS X Server 10.6
-
Apple MacOSXServerUpd10.6.1.dmg
http://www.apple.com/support/downloads/
S.u.S.E. openSUSE 11.0
-
S.u.S.E. flash-player-9.0.246.0-0.1.i586.rpm
http://download.opensuse.org/update/11.0/rpm/i586/flash-player-9.0.246 .0-0.1.i586.rpm
Apple Mac OS X 10.6
-
Apple MacOSXUpd10.6.1.dmg
http://www.apple.com/support/downloads/
S.u.S.E. openSUSE 11.1
-
S.u.S.E. flash-player-10.0.32.18-0.1.1.i586.rpm
http://download.opensuse.org/update/11.1/rpm/i586/flash-player-10.0.32 .18-0.1.1.i586.rpm
Turbolinux Client 2008
-
Turbolinux flash-player-10.0.32.18-1.i586.rpm
http://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Client/12/n on-free-updates/flash-player-10.0.32.18-1.i586.rpm
Apple Mac OS X 10.4.11
-
Apple SecUpd2009-005Intel.dmg
Intel
http://www.apple.com/support/downloads/ -
Apple SecUpd2009-005PPC.dmg
PPC
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.4.11
-
Apple SecUpdSrvr2009-005PPC.dmg
PPC
http://www.apple.com/support/downloads/ -
Apple SecUpdSrvr2009-005Univ.dmg
Universal
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.5.8
-
Apple SecUpdSrvr2009-005.dmg
http://www.apple.com/support/downloads/
Apple Mac OS X 10.5.8
-
Apple SecUpd2009-005.dmg
http://www.apple.com/support/downloads/
References
Adobe Flash Player and AIR Unspecified Privilege Escalation Vulnerability
References:
References: