RETIRED: Adobe Flash Player Same-Origin Policy Bypass Vulnerability
BID:37013
Info
RETIRED: Adobe Flash Player Same-Origin Policy Bypass Vulnerability
| Bugtraq ID: | 37013 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 12 2009 12:00AM |
| Updated: | Nov 17 2009 02:26PM |
| Credit: | Mike Bailey |
| Vulnerable: |
Adobe Flash Player Plugin 9.0.31 .0 Adobe Flash Player Plugin 9.0.28 .0 Adobe Flash Player Plugin 9.0.20 .0 Adobe Flash Player Plugin 9.0.16 Adobe Flash Player Plugin 8.0 Adobe Flash Player Plugin 7.0.63 Adobe Flash Player Plugin 7.0.25 Adobe Flash Player Plugin 9.0.45.0 Adobe Flash Player Plugin 9.0.18d60 Adobe Flash Player Plugin 9.0.124.0 Adobe Flash Player Plugin 9.0.124.0 Adobe Flash Player Plugin 9.0.112.0 Adobe Flash Player Plugin 10.0.12.10 Adobe Flash Player 10.0.32 18 Adobe Flash Player 10.0.22 .87 Adobe Flash Player 10.0.15 .3 Adobe Flash Player 10.0.12 .36 Adobe Flash Player 10.0.12 .35 Adobe Flash Player 9.0.246 0 Adobe Flash Player 9.0.152 .0 Adobe Flash Player 9.0.151 .0 Adobe Flash Player 9.0.124 .0 Adobe Flash Player 9.0.48.0 Adobe Flash Player 9.0.47.0 Adobe Flash Player 9.0.45.0 Adobe Flash Player 9.0.31.0 Adobe Flash Player 9.0.28.0 Adobe Flash Player 9.0.246.0 Adobe Flash Player 9.0.159.0 Adobe Flash Player 9.0.115.0 Adobe Flash Player 9 Adobe Flash Player 8.0.35.0 Adobe Flash Player 8.0.34.0 Adobe Flash Player 7.0.70.0 Adobe Flash Player 7.0.69.0 Adobe Flash Player 7 Adobe Flash Player 10.0.32.18 Adobe Flash Player 10 |
| Not Vulnerable: | |
Discussion
RETIRED: Adobe Flash Player Same-Origin Policy Bypass Vulnerability
Adobe Flash Player is prone to a vulnerability that lets attackers bypass the same-origin policy.
Attackers can exploit this issue to access resources from another origin in the context of another domain. This can facilitate cross-site request-forgery attacks.
NOTE: The BID is being retired because the vendor states that the described behavior is not considered a vulnerability and is in line with the design and documentation.
Adobe Flash Player is prone to a vulnerability that lets attackers bypass the same-origin policy.
Attackers can exploit this issue to access resources from another origin in the context of another domain. This can facilitate cross-site request-forgery attacks.
NOTE: The BID is being retired because the vendor states that the described behavior is not considered a vulnerability and is in line with the design and documentation.
Exploit / POC
RETIRED: Adobe Flash Player Same-Origin Policy Bypass Vulnerability
Attackers can exploit this issue by enticing an unsuspecting user into interacting with a malicious site.
Attackers can exploit this issue by enticing an unsuspecting user into interacting with a malicious site.
Solution / Fix
RETIRED: Adobe Flash Player Same-Origin Policy Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
RETIRED: Adobe Flash Player Same-Origin Policy Bypass Vulnerability
References:
References:
- Adobe Homepage (Adobe)
- Flash content and the same-origin policy (Adobe)
- Flash Origin Policy Issues (Mike Bailey)