Home→Descriptions→SA26027
| Secunia ID | |
| CVE-ID | |
| Release Date |
11 Jul 2007 |
| Last Change |
16 Jul 2007 |
| Criticality | |
| Solution Status |
Vendor Patch |
| Software |
Adobe Flash CS3 |
| Where | |
| Impact |
System accessThis covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user. Exposure of sensitive informationVulnerabilities where documents or credentials are leaked or can be revealed either locally or from remote. |
| Description |
Some vulnerabilities have been reported in Adobe Flash Player, which can be exploited by malicious people to gain knowledge of sensitive information or compromise a user's system. 1) A boundary error when processing FLV files can be exploited to cause a buffer overflow via an FLV file with a specially crafted DataObject section. Successful exploitation allows execution of arbitrary code when a user e.g. visits a malicious website. The vulnerability affects versions 9.0.45.0 and prior. 2) An error within the interaction of Flash Player and certain browsers can be exploited to leak key presses to a Flash Player applet. The vulnerability affects versions 7.0.69.0 and prior on Linux and Solaris. It does not affect Flash Player 9. A bug has also been reported in the validation of the HTTP Referer in versions 8.0.34.0 and prior, which may aid in e.g. CSRF (Cross-Site Request Forgery) attacks. |
| Solution |
Apply updates. Flash Player 9.0.45.0 and earlier (update to version 9.0.47.0): Flash Player 9.0.45.0 and earlier - network distribution (update to version 9.0.47.0): Flash CS3 Professional (update to version 9.0.47.0): Flash Professional 8, Flash Basic (update to version 8.0.35.0): Flex 2.0 (update to version 9.0.47.0): Flash Player version 7.0.70.0 for Linux and Solaris reportedly fixes vulnerability #2 for Opera and Konqueror browsers. |
| Reported by |
1) Stefano Di Paola and Giorgio Fedon, Minded Security. |
| Original Advisory |
Adobe: Minded Security: |