Retired: Adobe Flash Player Multiple Security Vulnerabilities
BID:26929
Info
Retired: Adobe Flash Player Multiple Security Vulnerabilities
| Bugtraq ID: | 26929 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 18 2007 12:00AM |
| Updated: | Dec 21 2007 04:01PM |
| Credit: | Aaaron Portnoy of TippingPoint DVLabs, Toshiharu Sugiyama of UBsecure Inc, Rich Canning of the Google Security Team, Adam Barth of Standford University Jesse Michael and Thomas Biege of SUSE are credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Redhat Enterprise Linux Supplementary 5 server Redhat Enterprise Linux Extras 4.5.z Redhat Enterprise Linux Extras 4 Redhat Enterprise Linux Extras 3 Redhat Enterprise Linux Desktop Supplementary 5 client Adobe Flash Player 9.0.48.0 Adobe Flash Player 9.0.47.0 Adobe Flash Player 9.0.45.0 Adobe Flash Player 9.0.31.0 Adobe Flash Player 9.0.28.0 Adobe Flash Player 8.0.34.0 Adobe Flash Player 7.0.69.0 |
| Not Vulnerable: |
Adobe Flash Player 9.0.115.0 |
Discussion
Retired: Adobe Flash Player Multiple Security Vulnerabilities
Adobe Flash Player is prone to multiple security vulnerabilities.
The following individual records have been created to document these vulnerabilities:
26960 Adobe Flash Player ActiveX Control 'navigateToURL' API Cross Domain Scripting Vulnerability
26951 Adobe Flash Player JPG Header Remote Heap Based Buffer Overflow Vulnerability
26949 Adobe Flash Player 'asfunction' Cross Site Scripting Vulnerability
26965 Adobe Flash Player Unspecified Privilege-Escalation Vulnerability
26969 Adobe Flash Player HTTP Response Splitting Vulnerability
26966 Adobe Flash Player Policy File Cross Domain Security Bypass Vulnerability
These issues affect Adobe Flash Player 9.0.48.0, 8.0.35.0, 7.0.70.0 and prior versions.
Adobe Flash Player is prone to multiple security vulnerabilities.
The following individual records have been created to document these vulnerabilities:
26960 Adobe Flash Player ActiveX Control 'navigateToURL' API Cross Domain Scripting Vulnerability
26951 Adobe Flash Player JPG Header Remote Heap Based Buffer Overflow Vulnerability
26949 Adobe Flash Player 'asfunction' Cross Site Scripting Vulnerability
26965 Adobe Flash Player Unspecified Privilege-Escalation Vulnerability
26969 Adobe Flash Player HTTP Response Splitting Vulnerability
26966 Adobe Flash Player Policy File Cross Domain Security Bypass Vulnerability
These issues affect Adobe Flash Player 9.0.48.0, 8.0.35.0, 7.0.70.0 and prior versions.
Exploit / POC
Retired: Adobe Flash Player Multiple Security Vulnerabilities
An attacker can exploit some of these issues by enticing an unsuspecting victim to follow a malicious URI or entice a victim to open a malicious SWF file.
An attacker can exploit some of these issues by enticing an unsuspecting victim to follow a malicious URI or entice a victim to open a malicious SWF file.
Solution / Fix
Retired: Adobe Flash Player Multiple Security Vulnerabilities
Solution:
The vendor released an advisory and updates to address these issues. Please see the references for more information.
Adobe Flash Player 9.0.31.0
Adobe Flash Player 8.0.34.0
Adobe Flash Player 9.0.45.0
Adobe Flash Player 7.0.69.0
Adobe Flash Player 9.0.28.0
Adobe Flash Player 9.0.48.0
Adobe Flash Player 9.0.47.0
Solution:
The vendor released an advisory and updates to address these issues. Please see the references for more information.
Adobe Flash Player 9.0.31.0
-
Adobe install_flash_player_9_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_9_linux.tar.gz -
Adobe install_flash_player.exe
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player.exe
Adobe Flash Player 8.0.34.0
-
Adobe install_flash_player_9_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_9_linux.tar.gz -
Adobe install_flash_player.exe
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player.exe
Adobe Flash Player 9.0.45.0
-
Adobe install_flash_player_9_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_9_linux.tar.gz -
Adobe install_flash_player.exe
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player.exe
Adobe Flash Player 7.0.69.0
-
Adobe install_flash_player_9_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_9_linux.tar.gz -
Adobe install_flash_player.exe
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player.exe
Adobe Flash Player 9.0.28.0
-
Adobe install_flash_player_9_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_9_linux.tar.gz -
Adobe install_flash_player.exe
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player.exe
Adobe Flash Player 9.0.48.0
-
Adobe install_flash_player_9_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_9_linux.tar.gz -
Adobe install_flash_player.exe
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player.exe
Adobe Flash Player 9.0.47.0
-
Adobe install_flash_player_9_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_9_linux.tar.gz -
Adobe install_flash_player.exe
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player.exe
References
Retired: Adobe Flash Player Multiple Security Vulnerabilities
References:
References: