Adobe Flash Player SWF File Handling Remote Code Execution Vulnerability
BID:24856
Info
Adobe Flash Player SWF File Handling Remote Code Execution Vulnerability
| Bugtraq ID: | 24856 |
| Class: | Design Error |
| CVE: |
CVE-2007-3456 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 10 2007 12:00AM |
| Updated: | Mar 19 2015 08:26AM |
| Credit: | The vendor credits Stefano DiPaola, Elia Florio and Giorgio Fedon with the discovery of this vulnerability. |
| Vulnerable: |
Turbolinux wizpy 0 Turbolinux FUJI 0 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SP1 Sun Solaris 10_x86 Sun Solaris 10_sparc S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. openSUSE 10.2 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 10.1 S.u.S.E. Linux Desktop 1.0 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc S.u.S.E. Linux 10.0 x86-64 S.u.S.E. Linux 10.0 x86 S.u.S.E. Linux 10.0 ppc RedHat Enterprise Linux Extras 4 RedHat Enterprise Linux Extras 3 Red Hat Enterprise Linux Supplementary 5 server Red Hat Enterprise Linux Desktop Supplementary 5 client Nintendo Nintendo Wii 0 Macromedia Flash 8.0.24 .0 Macromedia Flash 8.0.22 .0 Macromedia Flash 7.0.63 .0 Macromedia Flash 7.0.61 .0 Macromedia Flash 7.0.60 .0 Macromedia Flash 7.0.25 .0 Macromedia Flash 7.0.19 .0 Macromedia Flash 7.0 r19 Macromedia Flash 8.0.33.0 Macromedia Flash 8.0 Macromedia Flash 7.0.68.0 Macromedia Flash 7.0.66.0 Gentoo Linux Foresight Linux Foresight Linux 1.1 Apple Mac OS X Server 10.4.10 Apple Mac OS X Server 10.4.9 Apple Mac OS X Server 10.4.8 Apple Mac OS X Server 10.4.7 Apple Mac OS X Server 10.4.6 Apple Mac OS X Server 10.4.5 Apple Mac OS X Server 10.4.4 Apple Mac OS X Server 10.4.3 Apple Mac OS X Server 10.4.2 Apple Mac OS X Server 10.4.1 Apple Mac OS X Server 10.4 Apple Mac OS X Server 10.3.9 Apple Mac OS X Server 10.3.8 Apple Mac OS X Server 10.3.7 Apple Mac OS X Server 10.3.6 Apple Mac OS X Server 10.3.5 Apple Mac OS X Server 10.3.4 Apple Mac OS X Server 10.3.3 Apple Mac OS X Server 10.3.2 Apple Mac OS X Server 10.3.1 Apple Mac OS X Server 10.3 Apple Mac OS X 10.4.10 Apple Mac OS X 10.4.9 Apple Mac OS X 10.4.8 Apple Mac OS X 10.4.7 Apple Mac OS X 10.4.6 Apple Mac OS X 10.4.5 Apple Mac OS X 10.4.4 Apple Mac OS X 10.4.3 Apple Mac OS X 10.4.2 Apple Mac OS X 10.4.1 Apple Mac OS X 10.4 Apple Mac OS X 10.3.9 Apple Mac OS X 10.3.8 Apple Mac OS X 10.3.7 Apple Mac OS X 10.3.6 Apple Mac OS X 10.3.5 Apple Mac OS X 10.3.4 Apple Mac OS X 10.3.3 Apple Mac OS X 10.3.2 Apple Mac OS X 10.3.1 Apple Mac OS X 10.3 Adobe Flash Player Plugin 9.0.31 .0 Adobe Flash Player Plugin 9.0.28 .0 Adobe Flash Player Plugin 9.0.20 .0 Adobe Flash Player Plugin 9.0.16 Adobe Flash Player Plugin 8.0 Adobe Flash Player Plugin 7.0.63 Adobe Flash Player Plugin 7.0.25 Adobe Flash Player Plugin 9.0.18d60 Adobe Flash Player 9.0.45.0 Adobe Flash Player 9.0.31.0 Adobe Flash Player 9.0.28.0 Adobe Flash Player 8.0.34.0 Adobe Flash Player 7.0.69.0 |
| Not Vulnerable: |
Sun Solaris 9_x86 Sun Solaris 9_sparc Sun Solaris 8_x86 Sun Solaris 8_sparc Apple Mac OS X Server 10.4.11 Apple Mac OS X 10.4.11 Adobe Flash Player 9.0.47.0 |
Discussion
Adobe Flash Player SWF File Handling Remote Code Execution Vulnerability
Adobe Flash Player is prone to a remote code-execution vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue by tricking an unsuspecting victim into opening a malicious file.
A successful exploit will result in the execution of arbitrary attacker-supplied code in the context of the victim running the vulnerable application.
Adobe Flash Player 9.0.45.0 and earlier, 8.0.34.0 and earlier, and 7.0.69.0 and earlier are affected.
Adobe Flash Player is prone to a remote code-execution vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue by tricking an unsuspecting victim into opening a malicious file.
A successful exploit will result in the execution of arbitrary attacker-supplied code in the context of the victim running the vulnerable application.
Adobe Flash Player 9.0.45.0 and earlier, 8.0.34.0 and earlier, and 7.0.69.0 and earlier are affected.
Exploit / POC
Adobe Flash Player SWF File Handling Remote Code Execution Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
Adobe Flash Player SWF File Handling Remote Code Execution Vulnerability
Solution:
The vendor has released updates to resolve this issue.
Please see the references for more information.
Sun Solaris 10_x86
Apple Mac OS X 10.4.10
Apple Mac OS X 10.4.2
Apple Mac OS X 10.4.3
Apple Mac OS X 10.4.4
Apple Mac OS X 10.4.5
Apple Mac OS X 10.4.7
Apple Mac OS X 10.4.8
Apple Mac OS X 10.4.9
Solution:
The vendor has released updates to resolve this issue.
Please see the references for more information.
Sun Solaris 10_x86
-
Sun Sun Patch Id: 125333-02
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -125333-02-1
Apple Mac OS X 10.4.10
-
Apple Mac OS X 10.4.11 Combo Update (Intel)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16036&cat= 1&platform=osx&method=sa/MacOSXUpdCombo10.4.11Intel.dmg -
Apple Mac OS X 10.4.11 Combo Update (PPC)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16051&cat= 1&platform=osx&method=sa/MacOSXUpdCombo10.4.11PPC.dmg
Apple Mac OS X 10.4.2
-
Apple Mac OS X 10.4.11 Combo Update (Intel)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16036&cat= 1&platform=osx&method=sa/MacOSXUpdCombo10.4.11Intel.dmg -
Apple Mac OS X 10.4.11 Combo Update (PPC)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16051&cat= 1&platform=osx&method=sa/MacOSXUpdCombo10.4.11PPC.dmg
Apple Mac OS X 10.4.3
-
Apple Mac OS X 10.4.11 Combo Update (Intel)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16036&cat= 1&platform=osx&method=sa/MacOSXUpdCombo10.4.11Intel.dmg -
Apple Mac OS X 10.4.11 Combo Update (PPC)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16051&cat= 1&platform=osx&method=sa/MacOSXUpdCombo10.4.11PPC.dmg
Apple Mac OS X 10.4.4
-
Apple Mac OS X 10.4.11 Combo Update (Intel)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16036&cat= 1&platform=osx&method=sa/MacOSXUpdCombo10.4.11Intel.dmg -
Apple Mac OS X 10.4.11 Combo Update (PPC)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16051&cat= 1&platform=osx&method=sa/MacOSXUpdCombo10.4.11PPC.dmg
Apple Mac OS X 10.4.5
-
Apple Mac OS X 10.4.11 Combo Update (Intel)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16036&cat= 1&platform=osx&method=sa/MacOSXUpdCombo10.4.11Intel.dmg -
Apple Mac OS X 10.4.11 Combo Update (PPC)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16051&cat= 1&platform=osx&method=sa/MacOSXUpdCombo10.4.11PPC.dmg
Apple Mac OS X 10.4.7
-
Apple Mac OS X 10.4.11 Combo Update (Intel)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16036&cat= 1&platform=osx&method=sa/MacOSXUpdCombo10.4.11Intel.dmg -
Apple Mac OS X 10.4.11 Combo Update (PPC)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16051&cat= 1&platform=osx&method=sa/MacOSXUpdCombo10.4.11PPC.dmg
Apple Mac OS X 10.4.8
-
Apple Mac OS X 10.4.11 Combo Update (Intel)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16036&cat= 1&platform=osx&method=sa/MacOSXUpdCombo10.4.11Intel.dmg -
Apple Mac OS X 10.4.11 Combo Update (PPC)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16051&cat= 1&platform=osx&method=sa/MacOSXUpdCombo10.4.11PPC.dmg
Apple Mac OS X 10.4.9
-
Apple Mac OS X 10.4.11 Combo Update (Intel)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16036&cat= 1&platform=osx&method=sa/MacOSXUpdCombo10.4.11Intel.dmg -
Apple Mac OS X 10.4.11 Combo Update (PPC)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16051&cat= 1&platform=osx&method=sa/MacOSXUpdCombo10.4.11PPC.dmg
References
Adobe Flash Player SWF File Handling Remote Code Execution Vulnerability
References:
References:
- Adobe Homepage (Adobe)
- Minded Security Labs: Advisory #MSA01110707 - Flash Player/Plugin Video file par (Minded Security)
- Sun Alert ID: 103167 Security Vulnerabilities in Adobe Flash Player May Allow Un (Sun Microsystems)
- Wii's Internet Channel affected to Flash FLV parser vulnerability ( Juha-Matti Laurio
) - Executing Our Code/Flv vuln (http://www.wiili.org/)
- Flash Player update available to address security vulnerabilities (Adobe)
- RHSA-2007:0696-2 flash-plugin security update (Red Hat)
- Vulnerability Note VU#730785 Adobe Flash Player fails to properly sanitize input (US-CERT)