VulnerabilityModified
CVE-2009-0521
Untrusted search path vulnerability in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 on Linux allows local users to obtain sensitive information or gain privileges via a crafted library in a directory contained in the RPATH.
MEDIUM 4.6EPSS 1.05%
Does this matter?
Lower severity and a low EPSS score (1.05%). Track it; it rarely justifies an emergency change on its own.
Description
Untrusted search path vulnerability in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 on Linux allows local users to obtain sensitive information or gain privileges via a crafted library in a directory contained in the RPATH.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.05% probability · 62th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- adobe/flash player for linux
- Source
- cve@mitre.org
References
- http://isc.sans.org/diary.html?storyid=5929Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2009-0332.htmlThird Party Advisory
- http://secunia.com/advisories/34012Broken Link
- http://secunia.com/advisories/34226Broken Link
- http://security.gentoo.org/glsa/glsa-200903-23.xmlThird Party Advisory
- http://www.adobe.com/support/security/bulletins/apsb09-01.htmlPatch, Vendor Advisory
- http://www.vupen.com/english/advisories/2009/0513Broken Link, Patch, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=487144Issue Tracking, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48904Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6160Third Party Advisory
- http://isc.sans.org/diary.html?storyid=5929Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2009-0332.htmlThird Party Advisory
- http://secunia.com/advisories/34012Broken Link
- http://secunia.com/advisories/34226Broken Link
- http://security.gentoo.org/glsa/glsa-200903-23.xmlThird Party Advisory
- http://www.adobe.com/support/security/bulletins/apsb09-01.htmlPatch, Vendor Advisory
- http://www.vupen.com/english/advisories/2009/0513Broken Link, Patch, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=487144Issue Tracking, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48904Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6160Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.