Vulnerability details :
 
Macromedia Flash Player swf Processing Multiple Unspecified Code Execution 
 
     Fiche

Fiche créée le 2006-03-15 01:58:26, dernière mise à jour le 2010-11-04 19:16:14

Flash Player contains a flaw that may allow a malicious user to execute arbitrary code. The issue is triggered when the victim loads a malicious SWF file. It is possible that the flaw may allow an attacker to take control of the affected system resulting in a loss of confidentiality, integrity, and/or availability.



 
Macromedia, Inc.    8.0.22.0  Affected
Macromedia, Inc.    7.0.61 .0  Affected
Macromedia, Inc.    7.0.60 .0  Affected
Macromedia, Inc.    7.0.19 .0  Affected
Macromedia, Inc.    7.0 r19  Affected
Macromedia, Inc.    6.0.79 .0  Affected
Macromedia, Inc.    6.0.65 .0  Affected
Macromedia, Inc.    6.0.47 .0  Affected
Macromedia, Inc.    6.0.40 .0  Affected
Macromedia, Inc.    6.0.29 .0  Affected
Macromedia, Inc.    6.0  Affected
 
Attack Type :  Denial of Service
 saturation flood, crash, lock up, forced reboot.
 Découvert le 2006-03-15 02:02:36
 
Disclosure :  OSVDB Verified
 Confirmé le 2006-03-15 02:02:36
 
Disclosure :  Vendor Verified
 
Impact :  Loss of Integrity
 Assurance that data is unaltered by unauthorized persons. Examples: XSS, arbitrary command execution, most overflows, most format strings, SQL injection, unauthorized file modification/deletion/creation, remote file inclusion, etc.
 
Location :  Remote / Network Access
 If network access if required and exploit can be done remotely.
 
Solution :  Upgrade

 Upgrade to version 8.0.24.0 or 7.0.63.0 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
 Solution découverte le 1970-01-01 07:00:00
 
 
External refs :
OSVDB  23908
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
 
 
 
 

 

 


Free consultation (search)
 
  Fill one or some of the fields below :
   
Vendor
 
Title
 
Vulnerability ref.
 
 
   
 
   
Individual alerts
 
You determine with one profile dynamic and assisted, all your material and software equipment.
We shall inform you then automatically, as soon as a notification of security will concern one or several elements of it profile.
Every notification is definite, consists of numerous information to determine risk and to protect itself from it.
 
Login:
Pass:
 
Free online subscription
© Power4Security.com - BMS Ltd UK 2007-2008 - powered by Power4Website.com