Adobe Flash Player Clipboard Security Weakness
BID:31117
Info
Adobe Flash Player Clipboard Security Weakness
| Bugtraq ID: | 31117 |
| Class: | Design Error |
| CVE: |
CVE-2008-3873 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 18 2008 12:00AM |
| Updated: | Mar 10 2009 11:56PM |
| Credit: | Reported by the vendor |
| Vulnerable: |
SuSE Suse Linux Enterprise Desktop 10 SP2 SuSE Suse Linux Enterprise Desktop 10 SP1 Sun Solaris 10_x86 Sun Solaris 10_sparc Sun OpenSolaris build snv_96 Sun OpenSolaris build snv_95 Sun OpenSolaris build snv_92 Sun OpenSolaris build snv_91 Sun OpenSolaris build snv_90 Sun OpenSolaris build snv_89 Sun OpenSolaris build snv_88 Sun OpenSolaris build snv_87 Sun OpenSolaris build snv_85 Sun OpenSolaris build snv_103 Sun OpenSolaris build snv_102 Sun OpenSolaris build snv_101 Sun OpenSolaris build snv_100 S.u.S.E. openSUSE 11.0 S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 S.u.S.E. Novell Linux Desktop 9 Redhat Enterprise Linux Supplementary 5 server Redhat Enterprise Linux Extras 4 Redhat Enterprise Linux Extras 3 Redhat Enterprise Linux Desktop Supplementary 5 client Nortel Networks Self-Service Peri Workstation 0 Nortel Networks Self-Service Peri Application 0 Nortel Networks Self-Service MPS 1000 0 Nortel Networks Self-Service - CCSS7 0 Gentoo Linux Adobe Flash Player 9.0.124 .0 Adobe Flash Player 9.0.48.0 Adobe Flash Player 9.0.47.0 Adobe Flash Player 9.0.45.0 Adobe Flash Player 9.0.31.0 Adobe Flash Player 9.0.28.0 Adobe Flash Player 9.0.115.0 Adobe Flash Player 9 Adobe Flash Player 8.0.35.0 Adobe Flash Player 8.0.34.0 |
| Not Vulnerable: |
Sun OpenSolaris build snv_104 Adobe Flash Player 10.0.12 .36 Adobe Flash Player 10 |
Discussion
Adobe Flash Player Clipboard Security Weakness
Adobe Flash Player is prone to a security weakness that may allow attackers to inject arbitrary content into a user's clipboard.
Attackers can exploit this issue to overwrite content that is contained in a victim's clipboard. As a result, attacker-supplied URIs can persist in the victim's clipboard.
Adobe Flash Player is prone to a security weakness that may allow attackers to inject arbitrary content into a user's clipboard.
Attackers can exploit this issue to overwrite content that is contained in a victim's clipboard. As a result, attacker-supplied URIs can persist in the victim's clipboard.
Exploit / POC
Adobe Flash Player Clipboard Security Weakness
Reports indicate that this issue is being exploited in the wild.
Reports indicate that this issue is being exploited in the wild.
Solution / Fix
Adobe Flash Player Clipboard Security Weakness
Solution:
Adobe released an advisory. Adobe Flash Player 10 will address this issue by changing the way the player interacts with the clipboard. Please see the references for more information.
Adobe Flash Player 9.0.31.0
Adobe Flash Player 8.0.34.0
Adobe Flash Player 8.0.35.0
Adobe Flash Player 9.0.48.0
Adobe Flash Player 9
Adobe Flash Player 9.0.28.0
Adobe Flash Player 9.0.115.0
Adobe Flash Player 9.0.45.0
Adobe Flash Player 9.0.47.0
Adobe Flash Player 9.0.124 .0
Solution:
Adobe released an advisory. Adobe Flash Player 10 will address this issue by changing the way the player interacts with the clipboard. Please see the references for more information.
Adobe Flash Player 9.0.31.0
-
Adobe install_flash_player_10_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_10_linux.tar.gz
Adobe Flash Player 8.0.34.0
-
Adobe install_flash_player_10_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_10_linux.tar.gz
Adobe Flash Player 8.0.35.0
-
Adobe install_flash_player_10_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_10_linux.tar.gz
Adobe Flash Player 9.0.48.0
-
Adobe install_flash_player_10_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_10_linux.tar.gz
Adobe Flash Player 9
-
Adobe install_flash_player_10_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_10_linux.tar.gz
Adobe Flash Player 9.0.28.0
-
Adobe install_flash_player_10_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_10_linux.tar.gz
Adobe Flash Player 9.0.115.0
-
Adobe install_flash_player_10_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_10_linux.tar.gz
Adobe Flash Player 9.0.45.0
-
Adobe install_flash_player_10_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_10_linux.tar.gz
Adobe Flash Player 9.0.47.0
-
Adobe install_flash_player_10_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_10_linux.tar.gz
Adobe Flash Player 9.0.124 .0
-
Adobe install_flash_player_10_linux.tar.gz
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash _player_10_linux.tar.gz
References
Adobe Flash Player Clipboard Security Weakness
References:
References:
- Adobe Flash ads launching clipboard hijack attack (Ryan Naraine)
- Adobe Homepage (Adobe)
- Can Adobe mitigate �??clipboard hijack�?? issue? (Ryan Naraine)
- Nortel Response to Sun Alert 248586 - Multiple Security Vulnerabilities in t (Nortel Networks)
- Adobe Clipboard Attack (Adobe)
- APSB08-18 Flash Player update available to address security vulnerabilities (Adobe)
- Clipboard attack update (Adobe)
- Multiple Security Vulnerabilities in the Flash Player Plugin for Solaris (Sun)
- Multiple Security Vulnerabilities in the Flash Player Plugin for Solaris (Sun 24 (Avaya)
- Setting data on the system Clipboard requires user interaction (Adobe)