Adobe Flash Player HTTP Response Splitting Vulnerability
BID:26969
Info
Adobe Flash Player HTTP Response Splitting Vulnerability
| Bugtraq ID: | 26969 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-6245 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 20 2007 12:00AM |
| Updated: | Mar 19 2015 08:16AM |
| Credit: | Toshiharu Sugiyama of UBsecure Inc. is credited with discovering this vulnerability. |
| Vulnerable: |
Turbolinux wizpy 0 Turbolinux FUJI 0 SuSE SUSE Linux Enterprise Desktop 10 SP1 SuSE openSUSE 10.3 Sun Solaris 10_x86 Sun Solaris 10_sparc Sun OpenSolaris build snv_88 S.u.S.E. openSUSE 10.2 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.1 RedHat Enterprise Linux Extras 4.5.z RedHat Enterprise Linux Extras 4 RedHat Enterprise Linux Extras 3 Red Hat Enterprise Linux Supplementary 5 server Red Hat Enterprise Linux Desktop Supplementary 5 client Nortel Networks Self-Service Peri Workstation 0 Nortel Networks Self-Service Peri Application 0 Nortel Networks Self-Service - CCSS7 0 Nortel Networks Media Processing Svr 1000 Rel 3.0 Gentoo Linux Adobe Flash Player 9.0.48.0 Adobe Flash Player 9.0.47.0 Adobe Flash Player 9.0.45.0 Adobe Flash Player 9.0.31.0 Adobe Flash Player 9.0.28.0 Adobe Flash Player 8.0.35.0 Adobe Flash Player 8.0.34.0 Adobe Flash Player 7.0.70.0 Adobe Flash Player 7.0.69.0 |
| Not Vulnerable: | |
Discussion
Adobe Flash Player HTTP Response Splitting Vulnerability
Adobe Flash Player is prone to an HTTP response-splitting vulnerability because it fails to adequately sanitize user-supplied input.
A remote attacker can exploit this vulnerability to influence or misrepresent how web content is served, cached, or interpreted. This could aid in various attacks that try to entice client users into a false sense of trust.
This issue affects Adobe Flash Player 9.0.48.0, 8.0.35.0, and 7.0.70.0 and prior versions.
NOTE: This issue was previously disclosed in BID 26929 (Adobe Flash Player Multiple Security Vulnerabilities).
Adobe Flash Player is prone to an HTTP response-splitting vulnerability because it fails to adequately sanitize user-supplied input.
A remote attacker can exploit this vulnerability to influence or misrepresent how web content is served, cached, or interpreted. This could aid in various attacks that try to entice client users into a false sense of trust.
This issue affects Adobe Flash Player 9.0.48.0, 8.0.35.0, and 7.0.70.0 and prior versions.
NOTE: This issue was previously disclosed in BID 26929 (Adobe Flash Player Multiple Security Vulnerabilities).
Exploit / POC
Adobe Flash Player HTTP Response Splitting Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
Adobe Flash Player HTTP Response Splitting Vulnerability
Solution:
The vendor released an advisory and updates to address this issue. Please see the references for more information.
Adobe Flash Player 7.0.69.0
Adobe Flash Player 9.0.28.0
Adobe Flash Player 9.0.31.0
Adobe Flash Player 8.0.34.0
Adobe Flash Player 9.0.45.0
Turbolinux FUJI 0
Adobe Flash Player 9.0.47.0
Adobe Flash Player 9.0.48.0
Solution:
The vendor released an advisory and updates to address this issue. Please see the references for more information.
Adobe Flash Player 7.0.69.0
-
Adobe install_flash_player_9_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_9_linux.tar.gz -
Adobe install_flash_player.exe
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player.exe
Adobe Flash Player 9.0.28.0
-
Adobe install_flash_player_9_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_9_linux.tar.gz -
Adobe install_flash_player.exe
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player.exe
Adobe Flash Player 9.0.31.0
-
Adobe install_flash_player_9_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_9_linux.tar.gz -
Adobe install_flash_player.exe
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player.exe
Adobe Flash Player 8.0.34.0
-
Adobe install_flash_player_9_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_9_linux.tar.gz -
Adobe install_flash_player.exe
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player.exe
Adobe Flash Player 9.0.45.0
-
Adobe install_flash_player_9_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_9_linux.tar.gz -
Adobe install_flash_player.exe
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player.exe
Turbolinux FUJI 0
-
Turbolinux flash-player-9.0.115.0-1.src.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/11/u pdates/SRPMS/flash-player-9.0.115.0-1.src.rpm
Adobe Flash Player 9.0.47.0
-
Adobe install_flash_player_9_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_9_linux.tar.gz -
Adobe install_flash_player.exe
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player.exe
Adobe Flash Player 9.0.48.0
-
Adobe install_flash_player_9_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_9_linux.tar.gz -
Adobe install_flash_player.exe
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player.exe
References
Adobe Flash Player HTTP Response Splitting Vulnerability
References:
References:
- Adobe Flash Homepage (Adobe)
- APSB07-20 Flash Player update available to address security vulnerabilities (Adobe)
- Nortel Response to Sun Alert 238305 - Multiple Security Vulnerabilities in Flash (Nortel Networks)
- RHSA-2007:1126-8 - flash-plugin security update (Red Hat)
- Solution 238305: Multiple Security Vulnerabilities in Flash Player for Solaris (Sun Microsystems)