Adobe Flash Player Policy File Cross Domain Security Bypass Vulnerability
BID:26966
Info
Adobe Flash Player Policy File Cross Domain Security Bypass Vulnerability
| Bugtraq ID: | 26966 |
| Class: | Origin Validation Error |
| CVE: |
CVE-2007-6243 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 18 2007 12:00AM |
| Updated: | May 12 2015 07:49PM |
| Credit: | Toshiharu Sugiyama of UBsecure, Inc. and JPCERT/CC are credited with the discovery of this vulnerability. |
| Vulnerable: |
Turbolinux wizpy 0 Turbolinux FUJI 0 SuSE Suse Linux Enterprise Desktop 10 SP2 SuSE Suse Linux Enterprise Desktop 10 SP1 SuSE Linux 10.1 x86-64 SuSE Linux 10.1 x86 SuSE Linux 10.1 ppc Sun Solaris 10_x86 Sun Solaris 10_sparc Sun OpenSolaris build snv_96 Sun OpenSolaris build snv_95 Sun OpenSolaris build snv_92 Sun OpenSolaris build snv_91 Sun OpenSolaris build snv_90 Sun OpenSolaris build snv_89 Sun OpenSolaris build snv_88 Sun OpenSolaris build snv_87 Sun OpenSolaris build snv_85 Sun OpenSolaris build snv_103 Sun OpenSolaris build snv_102 Sun OpenSolaris build snv_101 Sun OpenSolaris build snv_100 S.u.S.E. openSUSE 11.0 S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.1 Redhat Enterprise Linux Supplementary 5 server Redhat Enterprise Linux Extras 4.6.z Redhat Enterprise Linux Extras 4.5.z Redhat Enterprise Linux Extras 4 Redhat Enterprise Linux Extras 3 Redhat Enterprise Linux Desktop Supplementary 5 client Nortel Networks Self-Service Peri Workstation 0 Nortel Networks Self-Service Peri Application 0 Nortel Networks Self-Service MPS 1000 0 Nortel Networks Self-Service - CCSS7 0 Nortel Networks Media Processing Svr 1000 Rel 3.0 Gentoo Linux Adobe Flex 3.0 Adobe Flash Professional 8 Adobe Flash Player 9.0.124 .0 Adobe Flash Player 9.0.48.0 Adobe Flash Player 9.0.47.0 Adobe Flash Player 9.0.45.0 Adobe Flash Player 9.0.31.0 Adobe Flash Player 9.0.28.0 Adobe Flash Player 9.0.115.0 Adobe Flash Player 8.0.35.0 Adobe Flash Player 8.0.34.0 Adobe Flash Player 7.0.70.0 Adobe Flash Player 7.0.69.0 Adobe Flash CS3 Professional 0 Adobe Flash Basic 8 Adobe AIR 1.0 |
| Not Vulnerable: |
Sun OpenSolaris build snv_104 Adobe Flash Professional 8 8.0.42.0 Adobe Flash Player 10.0.12 .36 Adobe Flash Basic 8.0.42.0 Adobe AIR 1.01 |
Discussion
Adobe Flash Player Policy File Cross Domain Security Bypass Vulnerability
The Adobe Flash Player is prone to a cross-domain security-bypass vulnerability.
An attacker can exploit this issue to connect to arbitrary hosts on affected computers. This may allow the application to perform generic TCP requests to determine what services are running on the affected computer.
NOTE: This issue was previously disclosed in BID 26929 (Adobe Flash Player Multiple Security Vulnerabilities), but has been assigned its own record because of new technical details.
The Adobe Flash Player is prone to a cross-domain security-bypass vulnerability.
An attacker can exploit this issue to connect to arbitrary hosts on affected computers. This may allow the application to perform generic TCP requests to determine what services are running on the affected computer.
NOTE: This issue was previously disclosed in BID 26929 (Adobe Flash Player Multiple Security Vulnerabilities), but has been assigned its own record because of new technical details.
Exploit / POC
Solution / Fix
Adobe Flash Player Policy File Cross Domain Security Bypass Vulnerability
Solution:
Adobe has released updates to address this issue.
NOTE: Flash Player 9.0.115.0 was previously released to fix this issue. According to the new Adobe security advisory (APSB08-11), this version is still vulnerable. Customers should install Flash Player 9.0.124.0. Please see the references for more information.
Adobe Flash Player 9.0.31.0
Adobe Flash Player 8.0.34.0
Adobe Flash Player 8.0.35.0
Adobe Flash Player 9.0.48.0
Adobe Flash Player 7.0.69.0
Adobe Flash Player 9.0.28.0
Adobe Flash Player 9.0.115.0
Adobe Flash Player 9.0.45.0
Adobe Flash Player 7.0.70.0
Adobe Flash Player 9.0.47.0
Adobe Flash Player 9.0.124 .0
Solution:
Adobe has released updates to address this issue.
NOTE: Flash Player 9.0.115.0 was previously released to fix this issue. According to the new Adobe security advisory (APSB08-11), this version is still vulnerable. Customers should install Flash Player 9.0.124.0. Please see the references for more information.
Adobe Flash Player 9.0.31.0
-
Adobe install_flash_player_10_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_10_linux.tar.gz
Adobe Flash Player 8.0.34.0
-
Adobe install_flash_player_10_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_10_linux.tar.gz
Adobe Flash Player 8.0.35.0
-
Adobe install_flash_player_10_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_10_linux.tar.gz
Adobe Flash Player 9.0.48.0
-
Adobe install_flash_player_10_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_10_linux.tar.gz
Adobe Flash Player 7.0.69.0
-
Adobe install_flash_player_10_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_10_linux.tar.gz
Adobe Flash Player 9.0.28.0
-
Adobe install_flash_player_10_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_10_linux.tar.gz
Adobe Flash Player 9.0.115.0
-
Adobe install_flash_player_10_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_10_linux.tar.gz
Adobe Flash Player 9.0.45.0
-
Adobe install_flash_player_10_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_10_linux.tar.gz
Adobe Flash Player 7.0.70.0
-
Adobe install_flash_player_10_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_10_linux.tar.gz
Adobe Flash Player 9.0.47.0
-
Adobe install_flash_player_10_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_10_linux.tar.gz
Adobe Flash Player 9.0.124 .0
-
Adobe install_flash_player_10_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_10_linux.tar.gz
References
Adobe Flash Player Policy File Cross Domain Security Bypass Vulnerability
References:
References:
- Adobe Flash Homepage (Adobe)
- Install Adobe Flash Player (Adobe)
- Security changes in Flash Player 9 (Deneb Meketa)
- VU#935737 - Adobe Flash Player may load arbitrary, malformed cross-domain policy (US-CERT)
- Nortel Response to Sun Alert 248586 - Multiple Security Vulnerabilities in t (Nortel Networks)
- APSB07-20 Flash Player update available to address security vulnerabilities (Adobe)
- APSB08-11 Flash Player update available to address security vulnerabilities (Adobe)
- APSB08-18 Flash Player update available to address security vulnerabilities (Adobe)
- Multiple Security Vulnerabilities in the Flash Player Plugin for Solaris (Sun)
- Multiple Security Vulnerabilities in the Flash Player Plugin for Solaris (Sun 24 (Avaya)
- Nortel Response to Sun Alert 238305 - Multiple Security Vulnerabilities in Flash (Nortel Networks)
- RHSA-2007:1126-8 - flash-plugin security update (Red Hat)
- RHSA-2008:0221-3: Critical: flash-plugin security update (Red Hat)
- Solution 238305: Multiple Security Vulnerabilities in Flash Player for Solaris (Sun Microsystems)