RETIRED: Adobe Flash Player Plugin Multiple HTTP Response Splitting Vulnerabilities
BID:20593
Info
RETIRED: Adobe Flash Player Plugin Multiple HTTP Response Splitting Vulnerabilities
| Bugtraq ID: | 20593 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 17 2006 12:00AM |
| Updated: | Oct 18 2006 10:29PM |
| Credit: | Marc Bevand of Rapid7 is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Macromedia Flash Player Plugin for WIndows 9.0.16 Macromedia Flash Player Plugin for Linux 7.0.63 |
| Not Vulnerable: |
Macromedia Flash Player plugin BETA version for Windows 9.0.18d60 |
Discussion
RETIRED: Adobe Flash Player Plugin Multiple HTTP Response Splitting Vulnerabilities
The Adobe Flash Player Plugin is prone to multiple HTTP response-splitting vulnerabilities because the application fails to properly sanitize user-supplied input.
A remote attacker may exploit these vulnerabilities to influence or misrepresent how web content is served, cached, or interpreted. This could aid in various attacks that attempt to entice client users into a false sense of trust.
Adobe Flash Player Plugin version 9.0.16 for Windows and version 7.0.63 for Linux are vulnerable; other versions may also be affected.
This BID has been retired.
The Adobe Flash Player Plugin is prone to multiple HTTP response-splitting vulnerabilities because the application fails to properly sanitize user-supplied input.
A remote attacker may exploit these vulnerabilities to influence or misrepresent how web content is served, cached, or interpreted. This could aid in various attacks that attempt to entice client users into a false sense of trust.
Adobe Flash Player Plugin version 9.0.16 for Windows and version 7.0.63 for Linux are vulnerable; other versions may also be affected.
This BID has been retired.
Exploit / POC
RETIRED: Adobe Flash Player Plugin Multiple HTTP Response Splitting Vulnerabilities
Currently we are not aware of any exploits for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
RETIRED: Adobe Flash Player Plugin Multiple HTTP Response Splitting Vulnerabilities
Solution:
The vendor has released Flash Player plugin BETA version 9.0.18d60 (for Windows) to address these issues; please contact the vendor for details.
This BID has been retired as it is a duplicate of an existing BID.
Solution:
The vendor has released Flash Player plugin BETA version 9.0.18d60 (for Windows) to address these issues; please contact the vendor for details.
This BID has been retired as it is a duplicate of an existing BID.
References
RETIRED: Adobe Flash Player Plugin Multiple HTTP Response Splitting Vulnerabilities
References:
References: