Retired: Adobe Flash Player SWF File Remote Code Execution Vulnerability
BID:29386
Info
Retired: Adobe Flash Player SWF File Remote Code Execution Vulnerability
| Bugtraq ID: | 29386 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 27 2008 12:00AM |
| Updated: | May 28 2008 07:53PM |
| Credit: | Symantec |
| Vulnerable: |
Adobe Flash Player 9.0.124 .0 Adobe Flash Player 9.0.115.0 |
| Not Vulnerable: | |
Discussion
Retired: Adobe Flash Player SWF File Remote Code Execution Vulnerability
Adobe Flash Player is prone to a remote code-execution vulnerability.
An attacker may exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
Adobe Flash Player 9.0.115.0 and 9.0.124.0 are vulnerable; other versions may also be affected.
NOTE: Further research indicates that this vulnerability is the same issue described in BID 28695 (Adobe Flash Player Multimedia File Remote Buffer Overflow Vulnerability), so this BID is being retired.
Adobe Flash Player is prone to a remote code-execution vulnerability.
An attacker may exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
Adobe Flash Player 9.0.115.0 and 9.0.124.0 are vulnerable; other versions may also be affected.
NOTE: Further research indicates that this vulnerability is the same issue described in BID 28695 (Adobe Flash Player Multimedia File Remote Buffer Overflow Vulnerability), so this BID is being retired.
Exploit / POC
Retired: Adobe Flash Player SWF File Remote Code Execution Vulnerability
Symantec has observed that this issue is being actively exploited in the wild.
UPDATE: Continued investigation reveals that this issue is fairly widespread. Malicious code is being injected into other third-party domains (approximately 20,000 web pages), most likely through SQL-injection attacks. The code then redirects users to sites hosting malicious Flash files exploiting this issue.
Symantec has observed that this issue is being actively exploited in the wild.
UPDATE: Continued investigation reveals that this issue is fairly widespread. Malicious code is being injected into other third-party domains (approximately 20,000 web pages), most likely through SQL-injection attacks. The code then redirects users to sites hosting malicious Flash files exploiting this issue.
Solution / Fix
Retired: Adobe Flash Player SWF File Remote Code Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Retired: Adobe Flash Player SWF File Remote Code Execution Vulnerability
References:
References:
- Adobe Flash Homepage (Adobe)
- Adobe Homepage (Adobe)
- Malware Attack Exploiting Flash Zero Day Vulnerability (Dancho Danchev)
- Potential Flash Player issue (Adobe)
- VU#395473 - Adobe Flash player code execution vulnerability (US-CERT)