Adobe Flash Player Arbitrary Cross Domain HTTP Request Headers Security Vulnerability
BID:28696
Info
Adobe Flash Player Arbitrary Cross Domain HTTP Request Headers Security Vulnerability
| Bugtraq ID: | 28696 |
| Class: | Design Error |
| CVE: |
CVE-2008-1654 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 02 2008 12:00AM |
| Updated: | Mar 19 2015 09:05AM |
| Credit: | Tom Gallagher |
| Vulnerable: |
Turbolinux wizpy 0 Turbolinux FUJI 0 SuSE SUSE Linux Enterprise Desktop 10 SP1 SuSE openSUSE 10.3 Sun Solaris 10_x86 Sun Solaris 10_sparc Sun OpenSolaris build snv_88 S.u.S.E. openSUSE 10.2 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc RedHat Enterprise Linux Extras 4 RedHat Enterprise Linux Extras 3 Red Hat Enterprise Linux Supplementary 5 server Red Hat Enterprise Linux Desktop Supplementary 5 client Nortel Networks Self-Service Peri Workstation 0 Nortel Networks Self-Service Peri Application 0 Nortel Networks Self-Service MPS 1000 0 Nortel Networks Self-Service Media Processing Server 0 Nortel Networks Self-Service - CCSS7 0 Nortel Networks Self-Service 0 Gentoo Linux Apple Mac OS X Server 10.5.2 Apple Mac OS X Server 10.5.1 Apple Mac OS X Server 10.4.11 Apple Mac OS X Server 10.5 Apple Mac OS X 10.5.2 Apple Mac OS X 10.5.1 Apple Mac OS X 10.4.11 Apple Mac OS X 10.5 Adobe Flex 3.0 Adobe Flash Professional 8 Adobe Flash Player 9.0.48.0 Adobe Flash Player 9.0.47.0 Adobe Flash Player 9.0.45.0 Adobe Flash Player 9.0.31.0 Adobe Flash Player 9.0.28.0 Adobe Flash Player 9.0.115.0 Adobe Flash Player 9 Adobe Flash Player 8.0.35.0 Adobe Flash Player 8.0.34.0 Adobe Flash CS3 Professional 0 Adobe Flash Basic 8 Adobe AIR 1.0 |
| Not Vulnerable: |
Adobe Flash Professional 8 8.0.42.0 Adobe Flash Player 9.0.124 .0 Adobe Flash Basic 8.0.42.0 Adobe AIR 1.01 |
Discussion
Exploit / POC
Adobe Flash Player Arbitrary Cross Domain HTTP Request Headers Security Vulnerability
Attackers can exploit this issues using by using standard functions provided by ActionScript in SWF files.
Attackers can exploit this issues using by using standard functions provided by ActionScript in SWF files.
Solution / Fix
Adobe Flash Player Arbitrary Cross Domain HTTP Request Headers Security Vulnerability
Solution:
The vendor released Flash Player 9.0.124.0 to address this issue. Please see the references for more information.
Apple Mac OS X Server 10.5
Apple Mac OS X 10.5
Apple Mac OS X Server 10.4.11
Apple Mac OS X 10.4.11
Apple Mac OS X 10.5.1
Apple Mac OS X Server 10.5.1
Apple Mac OS X 10.5.2
Apple Mac OS X Server 10.5.2
Solution:
The vendor released Flash Player 9.0.124.0 to address this issue. Please see the references for more information.
Apple Mac OS X Server 10.5
-
Apple Security Update 2008-003 Server (PPC)
http://www.apple.com/support/downloads/securityupdate2008003serverppc. html -
Apple Security Update 2008-003 Server (Universal)
http://www.apple.com/support/downloads/securityupdate2008003serveruniv ersal.html
Apple Mac OS X 10.5
-
Apple Security Update 2008-003 (Intel)
http://www.apple.com/support/downloads/securityupdate2008003intel.html -
Apple Security Update 2008-003 (PPC)
http://www.apple.com/support/downloads/securityupdate2008003ppc.html
Apple Mac OS X Server 10.4.11
-
Apple Security Update 2008-003 Server (PPC)
http://www.apple.com/support/downloads/securityupdate2008003serverppc. html -
Apple Security Update 2008-003 Server (Universal)
http://www.apple.com/support/downloads/securityupdate2008003serveruniv ersal.html
Apple Mac OS X 10.4.11
-
Apple Security Update 2008-003 (Intel)
http://www.apple.com/support/downloads/securityupdate2008003intel.html -
Apple Security Update 2008-003 (PPC)
http://www.apple.com/support/downloads/securityupdate2008003ppc.html
Apple Mac OS X 10.5.1
-
Apple Security Update 2008-003 (Intel)
http://www.apple.com/support/downloads/securityupdate2008003intel.html -
Apple Security Update 2008-003 (PPC)
http://www.apple.com/support/downloads/securityupdate2008003ppc.html
Apple Mac OS X Server 10.5.1
-
Apple Security Update 2008-003 Server (PPC)
http://www.apple.com/support/downloads/securityupdate2008003serverppc. html -
Apple Security Update 2008-003 Server (Universal)
http://www.apple.com/support/downloads/securityupdate2008003serveruniv ersal.html
Apple Mac OS X 10.5.2
-
Apple Security Update 2008-003 (Intel)
http://www.apple.com/support/downloads/securityupdate2008003intel.html -
Apple Security Update 2008-003 (PPC)
http://www.apple.com/support/downloads/securityupdate2008003ppc.html
Apple Mac OS X Server 10.5.2
-
Apple Security Update 2008-003 Server (PPC)
http://www.apple.com/support/downloads/securityupdate2008003serverppc. html -
Apple Security Update 2008-003 Server (Universal)
http://www.apple.com/support/downloads/securityupdate2008003serveruniv ersal.html
References
Adobe Flash Player Arbitrary Cross Domain HTTP Request Headers Security Vulnerability
References:
References:
- Adobe Flash Homepage (Adobe)
- Adobe Homepage (Adobe)
- Install Adobe Flash Player (Adobe)
- TechNote: Arbitrary headers are not sent from Flash Player to a remote domain (Adobe)
- APSB08-11 Flash Player update available to address security vulnerabilities (Adobe)
- Nortel Response to Sun Alert 238305 - Multiple Security Vulnerabilities in Flash (Nortel Networks)
- RHSA-2008:0221-3: Critical: flash-plugin security update (Red Hat)
- Solution 238305: Multiple Security Vulnerabilities in Flash Player for Solaris (Sun Microsystems)