Skip to main content

Adobe Flash Player Multiple Vulnerabilities

Last Update Date: 28 Jan 2011 Release Date: 10 Apr 2008 4463 Views

RISK: Medium Risk

Multiple vulnerabilities have been identified in Adobe Flash Player, which could be exploited by remote attackers to bypass security restrictions, gain knowledge of sensitive information or take complete control of an affected system.

1. Due to a buffer overflow error in the processing of "Declare Function (V7)" tags, which could be exploited by attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page.

2. Due to an integer overflow error when processing malformed SWF files, which could be exploited by attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page.

3. Due to an unspecified error when handling specially crafted Flash files, which could be exploited to conduct DNS rebinding attacks.

4. Due to an error when interpreting cross-domain policy files, which could be exploited to conduct privilege escalation attacks against web servers hosting Flash content and cross-domain policy files.

5. Due to an error when processing HTTP headers, which could be exploited to bypass cross-domain policy restrictions.

6. Due to input validation errors in various APIs, which could be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser in the security context of an affected Web site.


Impact

  • Cross-Site Scripting
  • Remote Code Execution
  • Security Restriction Bypass

System / Technologies affected

  • Adobe Flash Player 9.x

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link