CVE-2019-7090
published 2019-05-24CVE-2019-7090: Flash Player Desktop Runtime versions 32.0.0.114 and earlier, Flash Player for Google Chrome versions 32.0.0.114 and earlier, and Flash Player for Microsoft…
PriorityP431medium6.5CVSS 3.0
AVNACLPRNUIRSUCHINAN
EPSS
4.79%
90.9th percentile
Flash Player Desktop Runtime versions 32.0.0.114 and earlier, Flash Player for Google Chrome versions 32.0.0.114 and earlier, and Flash Player for Microsoft Edge and Internet Explorer 11 versions 32.0.0.114 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | <= 32.0.0.114 | — |
| adobe | flash_player_desktop_runtime | <= 32.0.0.114 | — |
| adobe | flash_player_desktop_runtime | — | — |
| adobe | flash_player_for_google_chrome | — | — |
| adobe | flash_player_for_microsoft_edge_and_internet_explorer_11 | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-49vj-5fcp-ch84: Flash Player Desktop Runtime versions 32
ghsa_unreviewed·2022-05-24
CVE-2019-7090 [MEDIUM] CWE-125 GHSA-49vj-5fcp-ch84: Flash Player Desktop Runtime versions 32
Flash Player Desktop Runtime versions 32.0.0.114 and earlier, Flash Player for Google Chrome versions 32.0.0.114 and earlier, and Flash Player for Microsoft Edge and Internet Explorer 11 versions 32.0.0.114 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
Red Hat
flash-plugin: Information Disclosure vulnerability (APSB19-06)
vendor_redhat·2019-02-12·CVSS 6.5
CVE-2019-7090 [MEDIUM] flash-plugin: Information Disclosure vulnerability (APSB19-06)
flash-plugin: Information Disclosure vulnerability (APSB19-06)
Flash Player Desktop Runtime versions 32.0.0.114 and earlier, Flash Player for Google Chrome versions 32.0.0.114 and earlier, and Flash Player for Microsoft Edge and Internet Explorer 11 versions 32.0.0.114 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
No detection rules found.
No public exploits indexed.
Qualys
February 2019 Patch Tuesday – 74 Vulns, 20 Critical, Exchange 0-day, Adobe Vulns
blogs_qualys·2019-02-12·CVSS 8.8
[HIGH] February 2019 Patch Tuesday – 74 Vulns, 20 Critical, Exchange 0-day, Adobe Vulns
This month’s Patch Tuesday is very large, with 74 vulns being addressed of which 20 are labeled as critical. Fifteen of these critical vulns are in the Scripting Engine and browsers, with the remainder being GDI+, SharePoint, and DHCP. Microsoft also issued an Advisory for an Exchange 0-day, along with a patch for one of the two reported vulns. Adobe also released updates for Acrobat/Reader, Flash, Coldfusion, and Creative Cloud.
## Workstation Patches
Browser, Scripting Engine, and GDI+ patches should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. This includes multi-user servers that are used as remote desktops for users.
## Exchange
In late January, a 0-day exploit was announced for Microsoft Exchange.
Qualys
February 2019 Patch Tuesday - 74 Vulns, 20 Critical, Exchange 0-day, Adobe Vulns | Qualys
blogs_qualys·2019-02-12·CVSS 8.8
[HIGH] February 2019 Patch Tuesday - 74 Vulns, 20 Critical, Exchange 0-day, Adobe Vulns | Qualys
This month’s Patch Tuesday is very large, with 74 vulns being addressed of which 20 are labeled as critical. Fifteen of these critical vulns are in the Scripting Engine and browsers, with the remainder being GDI+, SharePoint, and DHCP. Microsoft also issued an Advisory for an Exchange 0-day, along with a patch for one of the two reported vulns. Adobe also released updates for Acrobat/Reader, Flash, Coldfusion, and Creative Cloud.
### Workstation Patches
Browser, Scripting Engine, and GDI+ patches should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. This includes multi-user servers that are used as remote desktops for users.
### Exchange
In late January, a 0-day exploit was announced for Microsoft Exchange
Bugzilla
CVE-2023-7090 sudo: Improper handling of ipa_hostname leads to privilege mismanagement
bugzilla·2023-12-23·CVSS 8.8
CVE-2023-7090 [HIGH] CVE-2023-7090 sudo: Improper handling of ipa_hostname leads to privilege mismanagement
CVE-2023-7090 sudo: Improper handling of ipa_hostname leads to privilege mismanagement
A flaw was found in sudo in the handling of ipa_hostname, where ipa_hostname from /etc/sssd/sssd.conf was not propagated in sudo. Therefore, it leads to privilege mismanagement vulnerability in applications, where client hosts retain privileges even after retracting them.
Upstream Patch:
https://github.com/sudo-project/sudo/commit/e99082e05b9f0dd0e0f47fa1d2e1b9d922ea8c4c
https://www.sudo.ws/repos/sudo/rev/b4f31dbe3109
Upstream release:
https://www.sudo.ws/releases/legacy/#1.8.28
Red Hat Advisory:
https://access.redhat.com/errata/RHBA-2019:3598
References:
https://sudo.ws/pipermail/sudo-workers/2019-August/001248.html
https://sudo.ws/pipermail/sudo-workers/2019-August/001249.html
Bugzilla
CVE-2019-7090 flash-plugin: Information Disclosure vulnerability (APSB19-06)
bugzilla·2019-02-12·CVSS 6.5
CVE-2019-7090 [MEDIUM] CVE-2019-7090 flash-plugin: Information Disclosure vulnerability (APSB19-06)
CVE-2019-7090 flash-plugin: Information Disclosure vulnerability (APSB19-06)
Adobe Security Bulletin APSB19-06 for Adobe Flash Player describes a flaw that can possibly lead to information disclosure when Flash Player is used to play a specially crafted SWF file:
Out-of-bounds read -- CVE-2019-7090
External References:
https://helpx.adobe.com/security/products/flash-player/apsb19-06.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:0348 https://access.redhat.com/errata/RHSA-2019:0348
2019-05-24
Published