PT-2008-5644 · Adobe · Flash Player

Published

2008-10-17

·

Updated

2018-10-30

·

CVE-2008-4401

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Adobe Flash Player versions 9.0.124.0 and earlier
Description: The issue concerns ActionScript in Adobe Flash Player, which does not require user interaction for certain operations in the FileReference upload and download APIs. This allows remote attackers to create a browse dialog box via an SWF file, potentially having other unspecified impacts. The FileReference.browse operation in the FileReference upload API and the FileReference.download operation in the FileReference download API are specifically affected.
Recommendations: For Adobe Flash Player versions 9.0.124.0 and earlier, consider disabling the FileReference upload and download APIs until a patch is available. Restrict access to SWF files to minimize the risk of exploitation. Avoid using the FileReference.browse and FileReference.download operations in the affected APIs until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-4401
RHSA-2008:0945
RHSA-2008:0980

Affected Products

Flash Player