Adobe Flash Player DNS Rebinding Vulnerability
BID:26930
Info
Adobe Flash Player DNS Rebinding Vulnerability
| Bugtraq ID: | 26930 |
| Class: | Design Error |
| CVE: |
CVE-2007-5275 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 18 2007 12:00AM |
| Updated: | Mar 19 2015 09:35AM |
| Credit: | Dan Boneh, Adam Barth, Andrew Bortz, Collin Jackson, and Weidong Shao of Stanford University are credited with the discovery of this vulnerability. |
| Vulnerable: |
Turbolinux wizpy 0 Turbolinux FUJI 0 SuSE SUSE Linux Enterprise Desktop 10 SP1 SuSE openSUSE 10.3 Sun Solaris 10_x86 Sun Solaris 10_sparc Sun OpenSolaris build snv_88 S.u.S.E. openSUSE 10.2 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.1 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc RedHat Enterprise Linux Extras 4.5.z RedHat Enterprise Linux Extras 4 RedHat Enterprise Linux Extras 3 Red Hat Enterprise Linux Supplementary 5 server Red Hat Enterprise Linux Desktop Supplementary 5 client Nortel Networks Self-Service Peri Workstation 0 Nortel Networks Self-Service Peri Application 0 Nortel Networks Self-Service - CCSS7 0 Nortel Networks Media Processing Svr 1000 Rel 3.0 Gentoo Linux Apple Mac OS X Server 10.5.2 Apple Mac OS X Server 10.5.1 Apple Mac OS X Server 10.4.11 Apple Mac OS X Server 10.5 Apple Mac OS X 10.5.2 Apple Mac OS X 10.5.1 Apple Mac OS X 10.4.11 Apple Mac OS X 10.0 Apple Mac OS X 10.5 Adobe Flex 3.0 Adobe Flash Professional 8 Adobe Flash Player 9.0.48.0 Adobe Flash Player 9.0.47.0 Adobe Flash Player 9.0.45.0 Adobe Flash Player 9.0.31.0 Adobe Flash Player 9.0.28.0 Adobe Flash Player 9.0.115.0 Adobe Flash Player 8.0.34.0 Adobe Flash Player 7.0.69.0 Adobe Flash CS3 Professional 0 Adobe Flash Basic 8 Adobe AIR 1.0 |
| Not Vulnerable: |
Adobe Flash Professional 8 8.0.42.0 Adobe Flash Player 9.0.124 .0 Adobe Flash Basic 8.0.42.0 Adobe AIR 1.01 |
Discussion
Adobe Flash Player DNS Rebinding Vulnerability
Adobe Flash Player is prone to a DNS rebinding vulnerability that allows remote attackers to establish arbitrary TCP sessions.
An attacker can exploit this issue by enticing an unsuspecting victim to view a malicious SWF file.
Successfully exploiting this issue allows the attacker to bypass the application's same-origin policy and set up connections to services on arbitrary computers. This may lead to other attacks.
Adobe Flash Player is prone to a DNS rebinding vulnerability that allows remote attackers to establish arbitrary TCP sessions.
An attacker can exploit this issue by enticing an unsuspecting victim to view a malicious SWF file.
Successfully exploiting this issue allows the attacker to bypass the application's same-origin policy and set up connections to services on arbitrary computers. This may lead to other attacks.
Exploit / POC
Adobe Flash Player DNS Rebinding Vulnerability
A researcher has developed a proof of concept but it is not publicly available.
A researcher has developed a proof of concept but it is not publicly available.
Solution / Fix
References
Adobe Flash Player DNS Rebinding Vulnerability
References:
References:
- Adobe Homepage (Adobe)
- Install Adobe Flash Player (Adobe)
- Protecting Browsers from DNS Rebinding Attacks (Adam Barth)
- APSB07-20 Flash Player update available to address security vulnerabilities (Adobe)
- APSB08-11 Flash Player update available to address security vulnerabilities (Adobe)
- Nortel Response to Sun Alert 238305 - Multiple Security Vulnerabilities in Flash (Nortel Networks)
- RHSA-2007:1126-8 - flash-plugin security update (Red Hat)
- RHSA-2008:0221-3: Critical: flash-plugin security update (Red Hat)
- Solution 238305: Multiple Security Vulnerabilities in Flash Player for Solaris (Sun Microsystems)