The System.setClipboard method in ActionScript in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to populate the clipboard with a URL that is difficult to delete and does not require user interaction to populate the clipboard, as exploited in the wild in August 2008.
References
Configurations
History
21 Nov 2024, 00:50
Type | Values Removed | Values Added |
---|---|---|
References | () http://blogs.adobe.com/psirt/2008/08/clipboard_attack.html - | |
References | () http://blogs.zdnet.com/security/?p=1733 - | |
References | () http://blogs.zdnet.com/security/?p=1759 - | |
References | () http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html - | |
References | () http://secunia.com/advisories/32448 - | |
References | () http://secunia.com/advisories/32702 - | |
References | () http://secunia.com/advisories/32759 - | |
References | () http://secunia.com/advisories/33390 - | |
References | () http://secunia.com/advisories/34226 - | |
References | () http://security.gentoo.org/glsa/glsa-200903-23.xml - | |
References | () http://securitytracker.com/id?1020724 - | |
References | () http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1 - | |
References | () http://support.avaya.com/elmodocs2/security/ASA-2008-440.htm - | |
References | () http://support.avaya.com/elmodocs2/security/ASA-2009-020.htm - | |
References | () http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=834256&poid= - | |
References | () http://www.adobe.com/devnet/flashplayer/articles/fplayer10_security_changes.html - | |
References | () http://www.adobe.com/support/security/bulletins/apsb08-18.html - | |
References | () http://www.redhat.com/support/errata/RHSA-2008-0945.html - | |
References | () http://www.redhat.com/support/errata/RHSA-2008-0980.html - | |
References | () http://www.securityfocus.com/bid/31117 - | |
References | () http://www.vupen.com/english/advisories/2008/2838 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/44584 - |
Information
Published : 2008-08-29 17:41
Updated : 2024-11-21 00:50
NVD link : CVE-2008-3873
Mitre link : CVE-2008-3873
CVE.ORG link : CVE-2008-3873
JSON object : View
Products Affected
adobe
- flash_player
CWE