Summary
This host is installed with Air and is prone to code execution and denial of service vulnerabilities.
Impact
Successful exploitation will allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors.
Solution
Update to Adobe Air version 3.2.0.2070 or later,
For updates refer to http://get.adobe.com/air
Insight
The flaws are due to
- An error within an ActiveX Control when checking the URL security domain.
- An unspecified error within the NetStream class.
Affected
Adobe AIR version prior to 3.2.0.2070 on MAC OS X
Detection
Get the installed version with the help of detect NVT and check the version is vulnerable or not.
References
Severity
Classification
-
CVE CVE-2012-0724, CVE-2012-0725, CVE-2012-0772, CVE-2012-0773 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Adobe Air Multiple Vulnerabilities -01 May 13 (Mac OS X)
- Adobe Captivate Insecure Library Loading Vulnerability
- Adobe Flash Player 'SWF' File Multiple Code Execution Vulnerability - Mac OS X
- Aastra IP Telephone Hardcoded Telnet Password Security Bypass Vulnerability
- Adobe Acrobat Multiple Unspecified Vulnerabilities - Windows