Adobe ActionScript SecurityErrorEvent Security Bypass Vulnerability
BID:25260
Info
Adobe ActionScript SecurityErrorEvent Security Bypass Vulnerability
| Bugtraq ID: | 25260 |
| Class: | Design Error |
| CVE: |
CVE-2007-4324 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 09 2007 12:00AM |
| Updated: | Feb 09 2009 11:48PM |
| Credit: | David Neu is credited with the discovering this vulnerability. The exploit code was developed by fukami of SektionEins. |
| Vulnerable: |
Turbolinux wizpy 0 Turbolinux FUJI 0 SuSE Suse Linux Enterprise Desktop 10 SP2 SuSE Suse Linux Enterprise Desktop 10 SP1 Sun Solaris 10_x86 Sun Solaris 10_sparc Sun Solaris 10.0_x86 Sun Solaris 10.0 Sun OpenSolaris build snv_96 Sun OpenSolaris build snv_95 Sun OpenSolaris build snv_92 Sun OpenSolaris build snv_91 Sun OpenSolaris build snv_90 Sun OpenSolaris build snv_89 Sun OpenSolaris build snv_88 Sun OpenSolaris build snv_87 Sun OpenSolaris build snv_85 Sun OpenSolaris build snv_103 Sun OpenSolaris build snv_102 Sun OpenSolaris build snv_101 Sun OpenSolaris build snv_100 S.u.S.E. openSUSE 11.0 S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Novell Linux Desktop 9 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.1 Redhat Enterprise Linux Supplementary 5 server Redhat Enterprise Linux Extras 4.5.z Redhat Enterprise Linux Extras 4 Redhat Enterprise Linux Extras 3 Redhat Enterprise Linux Desktop Supplementary 5 client Nortel Networks Self-Service Peri Workstation 0 Nortel Networks Self-Service Peri Application 0 Nortel Networks Self-Service MPS 1000 0 Nortel Networks Self-Service - CCSS7 0 Nortel Networks Peri Workstation 0 Nortel Networks Peri Application 0 Nortel Networks Media Processing Svr 1000 Rel 3.0 Gentoo Linux Adobe Flex 2.0 Adobe Flash Player 9.0.124 .0 Adobe Flash Player 9.0.48.0 Adobe Flash Player 9.0.47.0 Adobe Flash Player 9.0.45.0 Adobe Flash Player 9.0.31.0 Adobe Flash Player 9.0.28.0 Adobe Flash Player 9.0.115.0 Adobe Flash Player 9 Adobe Flash Player 8.0.35.0 Adobe Flash Player 8.0.34.0 Adobe Flash Player 7.0.70.0 Adobe Flash Player 7.0.69.0 Adobe Flash Player 7 Adobe Flash CS3 Professional 0 Adobe ActionScript 3 |
| Not Vulnerable: |
Sun OpenSolaris build snv_104 Adobe Flash Player 10.0.12 .36 |
Discussion
Adobe ActionScript SecurityErrorEvent Security Bypass Vulnerability
Adobe ActionScript is prone to a security-bypass vulnerability because the application allows Flash movies compiled by ActionScript to connect to arbitrary TCP ports on a host running a vulnerable version of Flash.
Successfully exploiting this issue allows an attacker to bypass the application's sandbox security model and scan other hosts that are connected to the computer running the vulnerable application.
Adobe ActionScript is prone to a security-bypass vulnerability because the application allows Flash movies compiled by ActionScript to connect to arbitrary TCP ports on a host running a vulnerable version of Flash.
Successfully exploiting this issue allows an attacker to bypass the application's sandbox security model and scan other hosts that are connected to the computer running the vulnerable application.
Exploit / POC
Adobe ActionScript SecurityErrorEvent Security Bypass Vulnerability
An exploit is available at the following site:
http://scan.flashsec.org/
An exploit is available at the following site:
http://scan.flashsec.org/
Solution / Fix
Adobe ActionScript SecurityErrorEvent Security Bypass Vulnerability
Solution:
Adobe has released updates to address these issues. Please see the references for more information.
Adobe Flash Player 9.0.31.0
Adobe Flash Player 8.0.34.0
Adobe Flash Player 8.0.35.0
Adobe Flash Player 9.0.48.0
Adobe Flash Player 7
Adobe Flash Player 9
Adobe Flash Player 7.0.69.0
Adobe Flash Player 9.0.28.0
Adobe Flash Player 9.0.115.0
Adobe Flash Player 9.0.45.0
Turbolinux FUJI 0
Adobe Flash Player 7.0.70.0
Adobe Flash Player 9.0.47.0
Adobe Flash Player 9.0.124 .0
Solution:
Adobe has released updates to address these issues. Please see the references for more information.
Adobe Flash Player 9.0.31.0
-
Adobe install_flash_player_9_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_9_linux.tar.gz -
Adobe install_flash_player_10_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_10_linux.tar.gz
Adobe Flash Player 8.0.34.0
-
Adobe install_flash_player_9_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_9_linux.tar.gz -
Adobe install_flash_player_10_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_10_linux.tar.gz
Adobe Flash Player 8.0.35.0
-
Adobe install_flash_player_10_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_10_linux.tar.gz
Adobe Flash Player 9.0.48.0
-
Adobe install_flash_player_9_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_9_linux.tar.gz -
Adobe install_flash_player_10_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_10_linux.tar.gz
Adobe Flash Player 7
-
Adobe install_flash_player_10_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_10_linux.tar.gz
Adobe Flash Player 9
-
Adobe install_flash_player_10_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_10_linux.tar.gz
Adobe Flash Player 7.0.69.0
-
Adobe install_flash_player_9_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_9_linux.tar.gz -
Adobe install_flash_player_10_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_10_linux.tar.gz
Adobe Flash Player 9.0.28.0
-
Adobe install_flash_player_9_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_9_linux.tar.gz -
Adobe install_flash_player_10_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_10_linux.tar.gz
Adobe Flash Player 9.0.115.0
-
Adobe install_flash_player_10_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_10_linux.tar.gz
Adobe Flash Player 9.0.45.0
-
Adobe install_flash_player_9_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_9_linux.tar.gz -
Adobe install_flash_player_10_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_10_linux.tar.gz
Turbolinux FUJI 0
-
Turbolinux flash-player-9.0.115.0-1.src.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/11/u pdates/SRPMS/flash-player-9.0.115.0-1.src.rpm
Adobe Flash Player 7.0.70.0
-
Adobe install_flash_player_10_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_10_linux.tar.gz
Adobe Flash Player 9.0.47.0
-
Adobe install_flash_player_9_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_9_linux.tar.gz -
Adobe install_flash_player_10_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_10_linux.tar.gz
Adobe Flash Player 9.0.124 .0
-
Adobe install_flash_player_10_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_10_linux.tar.gz
References
Adobe ActionScript SecurityErrorEvent Security Bypass Vulnerability
References:
References:
- Adobe Homepage (Adobe)
- Design flaw in AS3 socket handling allows port probing ([email protected])
- Nortel Response to Sun Alert 248586 - Multiple Security Vulnerabilities in t (Nortel Networks)
- APSB07-20 Flash Player update available to address security vulnerabilities (Adobe)
- APSB08-18 Flash Player update available to address security vulnerabilities (Adobe)
- Multiple Security Vulnerabilities in the Flash Player Plugin for Solaris (Sun)
- Multiple Security Vulnerabilities in the Flash Player Plugin for Solaris (Sun 24 (Avaya)
- Nortel Response to Sun Alert 238305 - Multiple Security Vulnerabilities in Flash (Nortel Networks)
- RHSA-2007:1126-8 - flash-plugin security update (Red Hat)
- Solution 238305: Multiple Security Vulnerabilities in Flash Player for Solaris (Sun Microsystems)