RHEL 4/5/6:acroread (RHSA-2011:0301)

high Nessus 插件 ID 52161

简介

远程 Red Hat 主机缺少一个或多个安全更新。

描述

更新后的 acroread 程序包修复了多个安全问题,现在可用于 Red Hat Enterprise Linux 4 Extras 和 Red Hat Enterprise Linux 5 及 6 Supplementary。

Red Hat 安全响应团队已将此更新评级为具有严重安全影响。可从“参考”部分中的 CVE 链接获取针对每个漏洞的通用漏洞评分系统 (CVSS) 基本分数,其给出了详细的严重性等级。

Adobe Reader 允许用户查看和打印可移植文档格式 (PDF) 的文档。

此更新修复了 Adobe Reader 中的多种漏洞。请参阅“参考”部分的 Adobe 安全页面 APSB11-03,了解这些漏洞的详情。

打开特别构建的 PDF 文件时可导致 Adobe Reader 崩溃,或者以运行 Adobe Reader 的用户的身份执行任意代码。(CVE-2011-0562、CVE-2011-0563、CVE-2011-0565、CVE-2011-0566、CVE-2011-0567、CVE-2011-0585、CVE-2011-0586、CVE-2011-0589、CVE-2011-0590、CVE-2011-0591、CVE-2011-0592、CVE-2011-0593、CVE-2011-0594、CVE-2011-0595、CVE-2011-0596、CVE-2011-0598、CVE-2011-0599、CVE-2011-0600、CVE-2011-0602、CVE-2011-0603、CVE-2011-0606)

在 Adobe Reader 中发现多个安全缺陷。特别构建的 PDF 文件在打开时可导致运行 Adobe Reader 的用户遭受跨站脚本 (XSS) 攻击。(CVE-2011-0587、CVE-2011-0604)

所有 Adobe Reader 用户都应安装这些更新后的程序包。它们包含 Adobe Reader 版本 9.4.2,不易受到这些问题的影响。必须重新启动所有正在运行的 Adobe Reader 实例才能使更新生效。

解决方案

更新受影响的 acroread 和/或 acroread-plugin 程序包。

另见

https://access.redhat.com/security/cve/cve-2011-0562

https://access.redhat.com/security/cve/cve-2011-0563

https://access.redhat.com/security/cve/cve-2011-0565

https://access.redhat.com/security/cve/cve-2011-0566

https://access.redhat.com/security/cve/cve-2011-0567

https://access.redhat.com/security/cve/cve-2011-0585

https://access.redhat.com/security/cve/cve-2011-0586

https://access.redhat.com/security/cve/cve-2011-0587

https://access.redhat.com/security/cve/cve-2011-0589

https://access.redhat.com/security/cve/cve-2011-0590

https://access.redhat.com/security/cve/cve-2011-0591

https://access.redhat.com/security/cve/cve-2011-0592

https://access.redhat.com/security/cve/cve-2011-0593

https://access.redhat.com/security/cve/cve-2011-0594

https://access.redhat.com/security/cve/cve-2011-0595

https://access.redhat.com/security/cve/cve-2011-0596

https://access.redhat.com/security/cve/cve-2011-0598

https://access.redhat.com/security/cve/cve-2011-0599

https://access.redhat.com/security/cve/cve-2011-0600

https://access.redhat.com/security/cve/cve-2011-0602

https://access.redhat.com/security/cve/cve-2011-0603

https://access.redhat.com/security/cve/cve-2011-0604

https://access.redhat.com/security/cve/cve-2011-0606

https://www.adobe.com/support/security/bulletins/apsb11-03.html

https://access.redhat.com/errata/RHSA-2011:0301

插件详情

严重性: High

ID: 52161

文件名: redhat-RHSA-2011-0301.nasl

版本: 1.23

类型: local

代理: unix

发布时间: 2011/2/24

最近更新时间: 2021/1/14

支持的传感器: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

风险信息

VPR

风险因素: Medium

分数: 5.9

CVSS v2

风险因素: High

基本分数: 9.3

时间分数: 6.9

矢量: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

漏洞信息

CPE: cpe:/o:redhat:enterprise_linux:4.8, p-cpe:/a:redhat:enterprise_linux:acroread, cpe:/o:redhat:enterprise_linux:5, cpe:/o:redhat:enterprise_linux:6.0, cpe:/o:redhat:enterprise_linux:6, cpe:/o:redhat:enterprise_linux:4, p-cpe:/a:redhat:enterprise_linux:acroread-plugin

必需的 KB 项: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

易利用性: No known exploits are available

补丁发布日期: 2011/2/23

漏洞发布日期: 2011/2/10

参考资料信息

CVE: CVE-2011-0562, CVE-2011-0563, CVE-2011-0565, CVE-2011-0566, CVE-2011-0567, CVE-2011-0585, CVE-2011-0586, CVE-2011-0587, CVE-2011-0589, CVE-2011-0590, CVE-2011-0591, CVE-2011-0592, CVE-2011-0593, CVE-2011-0594, CVE-2011-0595, CVE-2011-0596, CVE-2011-0598, CVE-2011-0599, CVE-2011-0600, CVE-2011-0602, CVE-2011-0603, CVE-2011-0604, CVE-2011-0606

BID: 46187, 46198, 46199, 46201, 46202, 46204, 46207, 46208, 46209, 46210, 46211, 46212, 46213, 46214, 46216, 46217, 46218, 46219, 46220, 46221, 46222, 46251, 46252

RHSA: 2011:0301