Adobe Flash Player Unspecified Privilege-Escalation Vulnerability
BID:26965
Info
Adobe Flash Player Unspecified Privilege-Escalation Vulnerability
| Bugtraq ID: | 26965 |
| Class: | Access Validation Error |
| CVE: |
CVE-2007-6246 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 18 2007 12:00AM |
| Updated: | Mar 19 2015 09:11AM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Turbolinux wizpy 0 Turbolinux FUJI 0 SuSE SUSE Linux Enterprise Desktop 10 SP1 SuSE openSUSE 10.3 Sun Solaris 10_x86 Sun Solaris 10_sparc Sun OpenSolaris build snv_88 S.u.S.E. openSUSE 10.2 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.1 RedHat Enterprise Linux Extras 4.5.z RedHat Enterprise Linux Extras 4 RedHat Enterprise Linux Extras 3 Red Hat Enterprise Linux Supplementary 5 server Red Hat Enterprise Linux Desktop Supplementary 5 client Nortel Networks Self-Service Peri Workstation 0 Nortel Networks Self-Service Peri Application 0 Nortel Networks Self-Service MPS 1000 0 Nortel Networks Self-Service Media Processing Server 0 Nortel Networks Self-Service - CCSS7 0 Nortel Networks Self-Service 0 Gentoo Linux Adobe Flash Player 9.0.48.0 Adobe Flash Player 9.0.47.0 Adobe Flash Player 9.0.45.0 Adobe Flash Player 9.0.31.0 Adobe Flash Player 9.0.28.0 Adobe Flash Player 8.0.34.0 Adobe Flash Player 7.0.69.0 |
| Not Vulnerable: |
Adobe Flash Player 9.0.115.0 |
Discussion
Adobe Flash Player Unspecified Privilege-Escalation Vulnerability
Adobe Flash Player is prone to a vulnerability that allows attackers to gain elevated privileges on affected computers.
Very few technical details are currently available. We will update this BID as more information emerges.
NOTE: This issue occurs only when the application is running on a Linux operating system.
Versions prior to Adobe Flash Player 9.0.115.0 are vulnerable.
This issue was previously covered by BID 26929 (Adobe Flash Player Multiple Security Vulnerabilities).
Adobe Flash Player is prone to a vulnerability that allows attackers to gain elevated privileges on affected computers.
Very few technical details are currently available. We will update this BID as more information emerges.
NOTE: This issue occurs only when the application is running on a Linux operating system.
Versions prior to Adobe Flash Player 9.0.115.0 are vulnerable.
This issue was previously covered by BID 26929 (Adobe Flash Player Multiple Security Vulnerabilities).
Exploit / POC
Adobe Flash Player Unspecified Privilege-Escalation Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Adobe Flash Player Unspecified Privilege-Escalation Vulnerability
Solution:
The vendor released an advisory and a fix to address this issue. Please see the references for more information.
Adobe Flash Player 7.0.69.0
Adobe Flash Player 9.0.28.0
Adobe Flash Player 9.0.31.0
Adobe Flash Player 8.0.34.0
Adobe Flash Player 9.0.45.0
Turbolinux FUJI 0
Adobe Flash Player 9.0.47.0
Adobe Flash Player 9.0.48.0
Solution:
The vendor released an advisory and a fix to address this issue. Please see the references for more information.
Adobe Flash Player 7.0.69.0
-
Adobe install_flash_player_9_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_9_linux.tar.gz
Adobe Flash Player 9.0.28.0
-
Adobe install_flash_player_9_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_9_linux.tar.gz
Adobe Flash Player 9.0.31.0
-
Adobe install_flash_player_9_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_9_linux.tar.gz
Adobe Flash Player 8.0.34.0
-
Adobe install_flash_player_9_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_9_linux.tar.gz
Adobe Flash Player 9.0.45.0
-
Adobe install_flash_player_9_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_9_linux.tar.gz
Turbolinux FUJI 0
-
Turbolinux flash-player-9.0.115.0-1.src.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/11/u pdates/SRPMS/flash-player-9.0.115.0-1.src.rpm
Adobe Flash Player 9.0.47.0
-
Adobe install_flash_player_9_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_9_linux.tar.gz
Adobe Flash Player 9.0.48.0
-
Adobe install_flash_player_9_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_9_linux.tar.gz
References
Adobe Flash Player Unspecified Privilege-Escalation Vulnerability
References:
References:
- Adobe Flash Homepage (Adobe)
- APSB07-20 Flash Player update available to address security vulnerabilities (Adobe)
- Nortel Response to Sun Alert 238305 - Multiple Security Vulnerabilities in Flash (Nortel Networks)
- RHSA-2007:1126-8 - flash-plugin security update (Red Hat)
- Solution 238305: Multiple Security Vulnerabilities in Flash Player for Solaris (Sun Microsystems)