CVE-2006-5330
Summary
| CVE | CVE-2006-5330 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-10-17 21:07:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | CRLF injection vulnerability in Adobe Flash Player plugin 9.0.16 and earlier for Windows, 7.0.63 and earlier for Linux, 7.x before 7.0 r67 for Solaris, and before 9.0.28.0 for Mac OS X, allows remote attackers to modify HTTP headers of client requests and conduct HTTP Request Splitting attacks via CRLF sequences in arguments to the ActionScript functions (1) XML.addRequestHeader and (2) XML.contentType. NOTE: the flexibility of the attack varies depending on the type of web browser being used. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Adobe | Flash Player | All | All | linux | All |
| Application | Adobe | Flash Player | All | All | solaris | All |
| Application | Adobe | Flash Player | All | All | windows | All |
| Application | Adobe | Flash Player | All | All | mac_os_x | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Adobe Flash Player Plugin HTTP Header Injection Weakness | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Adobe - Security Advisories : Update available for HTTP header injection vulnerabilities in Adobe Flash Player | af854a3a-2127-422b-91ae-364da2661108 | www.adobe.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| APPLE-SA-2007-03-13 Mac OS X v10.4.9 and Security Update 2007-003 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| SecurityTracker.com Archives - Adobe Flash Player Plugin Lets Remote Users Injection Arbitrary HTTP Header Data | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| www.osvdb.org/29863 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| Rapid7 Security Advisory R7-0026: HTTP Header Injection Vulnerabilities in the Flash Player Plugin | af854a3a-2127-422b-91ae-364da2661108 | www.rapid7.com | |
| US-CERT Technical Cyber Security Alert TA07-072A -- Apple Updates for Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Sun Solaris update for Adobe Flash Player - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Mac OS X Security Update Fixes Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| SecurityReason - HTTP Header Injection Vulnerabilities in the Flash Player Plugin | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| About the security content of Mac OS X 10.4.9 and Security Update 2007-003 | af854a3a-2127-422b-91ae-364da2661108 | docs.info.apple.com | |
| Red Hat update for flash-plugin - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| #102932: Security Vulnerability in Adobe Flash Player May Allow Unauthorized Header Injection into HTTP Requests | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Adobe Flash Player CRLF Injection Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| SuSE Security announcements: [suse-security-announce] SUSE Security Announcement: flash-player CRLF injection (SUSE-SA:2006:077) | af854a3a-2127-422b-91ae-364da2661108 | lists.suse.com | |
| Adobe - Security Advisories : HTTP header injection vulnerabilities in Adobe Flash Player | af854a3a-2127-422b-91ae-364da2661108 | www.adobe.com | |
| SUSE update for flash-player - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.