Adobe Flash Player CVE-2014-0503 Same Origin Security Bypass Vulnerability
BID:66122
Info
Adobe Flash Player CVE-2014-0503 Same Origin Security Bypass Vulnerability
| Bugtraq ID: | 66122 |
| Class: | Origin Validation Error |
| CVE: |
CVE-2014-0503 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 11 2014 12:00AM |
| Updated: | Mar 19 2015 08:30AM |
| Credit: | Masato Kinugawa |
| Vulnerable: |
SuSE Suse Linux Enterprise Desktop 11 SP3 S.u.S.E. openSUSE 12.3 S.u.S.E. openSUSE 11.4 Redhat Enterprise Linux Workstation Supplementary 6 Redhat Enterprise Linux Supplementary 5 server Redhat Enterprise Linux Server Supplementary 6 Redhat Enterprise Linux Desktop Supplementary 6 Redhat Enterprise Linux Desktop Supplementary 5 client Google Chrome 33.0.1750.92 Google Chrome 33.0.1750.90 Google Chrome 33.0.1750.89 Google Chrome 33.0.1750.85 Google Chrome 33.0.1750.82 Google Chrome 33.0.1750.80 Google Chrome 33.0.1750.79 Google Chrome 33.0.1750.76 Google Chrome 33.0.1750.74 Google Chrome 33.0.1750.71 Google Chrome 33.0.1750.7 Google Chrome 33.0.1750.68 Google Chrome 33.0.1750.66 Google Chrome 33.0.1750.64 Google Chrome 33.0.1750.62 Google Chrome 33.0.1750.60 Google Chrome 33.0.1750.59 Google Chrome 33.0.1750.57 Google Chrome 33.0.1750.55 Google Chrome 33.0.1750.53 Google Chrome 33.0.1750.51 Google Chrome 33.0.1750.5 Google Chrome 33.0.1750.48 Google Chrome 33.0.1750.46 Google Chrome 33.0.1750.44 Google Chrome 33.0.1750.42 Google Chrome 33.0.1750.40 Google Chrome 33.0.1750.39 Google Chrome 33.0.1750.37 Google Chrome 33.0.1750.35 Google Chrome 33.0.1750.31 Google Chrome 33.0.1750.3 Google Chrome 33.0.1750.28 Google Chrome 33.0.1750.26 Google Chrome 33.0.1750.24 Google Chrome 33.0.1750.22 Google Chrome 33.0.1750.20 Google Chrome 33.0.1750.19 Google Chrome 33.0.1750.16 Google Chrome 33.0.1750.146 Google Chrome 33.0.1750.144 Google Chrome 33.0.1750.14 Google Chrome 33.0.1750.135 Google Chrome 33.0.1750.132 Google Chrome 33.0.1750.13 Google Chrome 33.0.1750.125 Google Chrome 33.0.1750.124 Google Chrome 33.0.1750.117 Google Chrome 33.0.1750.116 Google Chrome 33.0.1750.113 Google Chrome 33.0.1750.111 Google Chrome 33.0.1750.11 Google Chrome 33.0.1750.108 Google Chrome 33.0.1750.106 Google Chrome 33.0.1750.10 Google Chrome 33.0.1750.0 Gentoo Linux Adobe Flash Player for Windows 8.1 12.0.0.38 Adobe Flash Player for Windows 8.0 12.0.0.38 Adobe Flash Player for Windows 12.0 70 Adobe Flash Player for Windows 11.7.700 169 Adobe Flash Player for Windows 12.0.0.44 Adobe Flash Player for Windows 12.0.0.43 Adobe Flash Player for Windows 12.0.0.41 Adobe Flash Player for Windows 11.9.900.170 Adobe Flash Player for Windows 11.7.700.269 Adobe Flash Player for Windows 11.6.602.180 Adobe Flash Player for Macintosh 12.0 70 Adobe Flash Player for Macintosh 12.0.0.44 Adobe Flash Player for Macintosh 12.0.0.41 Adobe Flash Player for Macintosh 12.0.0.38 Adobe Flash Player for Macintosh 11.9.900.170 Adobe Flash Player for Macintosh 11.7.700.269 Adobe Flash Player for Chrome 12.0 70 Adobe Flash Player for Chrome 11.7.700 202 Adobe Flash Player for Chrome 11.7.700 169 Adobe Flash Player for Chrome 12.0.0.44 Adobe Flash Player for Chrome 12.0.0.41 Adobe Flash Player for Chrome 11.6.602.180 Adobe Flash Player for Chrome 11.6.602.171 Adobe Flash Player for Chrome 11.5.31.5 Adobe Flash Player for Chrome 11.5.31.137 Adobe Flash Player for Chrome 11.4.402.287 Adobe Flash Player for Chrome 11.4.402.265 Adobe Flash Player for Chrome 11.3.31.331 Adobe Flash Player for Chrome 11.3.31.230 Adobe Flash Player for Chrome 11.3.31.110 Adobe Flash Player for Chrome 11.3.300.271 |
| Not Vulnerable: |
Google Chrome 33.0.1750.149 Adobe Flash Player for Windows 12.0 77 Adobe Flash Player for Windows 11.7.700 272 Adobe Flash Player for Macintosh 12.0 77 Adobe Flash Player for Macintosh 11.7.700 272 Adobe Flash Player for Chrome 12.0 77 |
Discussion
Adobe Flash Player CVE-2014-0503 Same Origin Security Bypass Vulnerability
Adobe Flash Player is prone to an unspecified security-bypass vulnerability.
An attacker can exploit this issue to bypass certain same-origin policy restrictions, which may aid in further attacks.
Adobe Flash Player is prone to an unspecified security-bypass vulnerability.
An attacker can exploit this issue to bypass certain same-origin policy restrictions, which may aid in further attacks.
Exploit / POC
Adobe Flash Player CVE-2014-0503 Same Origin Security Bypass Vulnerability
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Adobe Flash Player CVE-2014-0503 Same Origin Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Adobe Flash Player CVE-2014-0503 Same Origin Security Bypass Vulnerability
References:
References: