Adobe Flash Player and AIR CVE-2012-4168 Cross Domain Information Disclosure Vulnerability
BID:56197
Info
Adobe Flash Player and AIR CVE-2012-4168 Cross Domain Information Disclosure Vulnerability
| Bugtraq ID: | 56197 |
| Class: | Origin Validation Error |
| CVE: |
CVE-2012-4168 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 21 2012 12:00AM |
| Updated: | Mar 12 2014 01:03PM |
| Credit: | Opera Software ASA |
| Vulnerable: |
Red Hat Enterprise Linux Supplementary 5 server Red Hat Enterprise Linux Desktop Supplementary 5 client HP Systems Insight Manager 7.0 HP Systems Insight Manager 6.3 HP Systems Insight Manager 6.2 HP Systems Insight Manager 6.1 HP Systems Insight Manager 6.0.0.96 HP Systems Insight Manager 6.0 Gentoo Linux Adobe Flash Player for Android 11.1.102.59 Adobe Flash Player 11.2.202.235 Adobe Flash Player 11.2.202.233 Adobe Flash Player 11.2.202.229 Adobe Flash Player 11.2.202.228 Adobe Flash Player 11.2.202.223 Adobe Flash Player 11.1.115.8 Adobe Flash Player 11.1.115.7 Adobe Flash Player 11.1.115.6 Adobe Flash Player 11.1.112.61 Adobe Flash Player 11.1.111.9 Adobe Flash Player 11.1.111.8 Adobe Flash Player 11.1.111.7 Adobe Flash Player 11.1.111.6 Adobe Flash Player 11.1.111.5 Adobe Flash Player 11.1.102.63 Adobe Flash Player 11.1.102.62 Adobe Flash Player 11.1.102.55 Adobe Flash Player 11.1.102.228 Adobe Flash Player 11.0.1.152 |
| Not Vulnerable: | |
Discussion
Adobe Flash Player and AIR CVE-2012-4168 Cross Domain Information Disclosure Vulnerability
Adobe Flash Player and AIR are prone to a cross-domain information-disclosure vulnerability.
An attacker can exploit this issue to bypass the same-origin policy and gain access to sensitive information.
NOTE: This issue was previously covered in BID 55136 (Adobe Flash Player and AIR APSB12-19 Multiple Remote Vulnerabilities) but has been assigned its own record for better documentation.
Adobe Flash Player and AIR are prone to a cross-domain information-disclosure vulnerability.
An attacker can exploit this issue to bypass the same-origin policy and gain access to sensitive information.
NOTE: This issue was previously covered in BID 55136 (Adobe Flash Player and AIR APSB12-19 Multiple Remote Vulnerabilities) but has been assigned its own record for better documentation.
Exploit / POC
Adobe Flash Player and AIR CVE-2012-4168 Cross Domain Information Disclosure Vulnerability
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Adobe Flash Player and AIR CVE-2012-4168 Cross Domain Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Adobe Flash Player and AIR CVE-2012-4168 Cross Domain Information Disclosure Vulnerability
References:
References:
- Adobe AIR homepage (Adobe)
- Adobe Flash Homepage (Adobe)