CVE-2008-4401

ActionScript in Adobe Flash Player 9.0.124.0 and earlier does not require user interaction in conjunction with (1) the FileReference.browse operation in the FileReference upload API or (2) the FileReference.download operation in the FileReference download API, which allows remote attackers to create a browse dialog box, and possibly have unspecified other impact, via an SWF file.
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html
http://secunia.com/advisories/32270 Patch Vendor Advisory
http://secunia.com/advisories/32448
http://secunia.com/advisories/32702
http://secunia.com/advisories/32759
http://secunia.com/advisories/33390
http://secunia.com/advisories/34226
http://security.gentoo.org/glsa/glsa-200903-23.xml
http://securitytracker.com/id?1021061
http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1
http://support.avaya.com/elmodocs2/security/ASA-2008-440.htm
http://support.avaya.com/elmodocs2/security/ASA-2009-020.htm
http://www.adobe.com/devnet/flashplayer/articles/fplayer10_security_changes.html
http://www.adobe.com/support/security/bulletins/apsb08-18.html Patch Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2008-0945.html
http://www.redhat.com/support/errata/RHSA-2008-0980.html
http://www.vupen.com/english/advisories/2008/2838
https://exchange.xforce.ibmcloud.com/vulnerabilities/45913
http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html
http://secunia.com/advisories/32270 Patch Vendor Advisory
http://secunia.com/advisories/32448
http://secunia.com/advisories/32702
http://secunia.com/advisories/32759
http://secunia.com/advisories/33390
http://secunia.com/advisories/34226
http://security.gentoo.org/glsa/glsa-200903-23.xml
http://securitytracker.com/id?1021061
http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1
http://support.avaya.com/elmodocs2/security/ASA-2008-440.htm
http://support.avaya.com/elmodocs2/security/ASA-2009-020.htm
http://www.adobe.com/devnet/flashplayer/articles/fplayer10_security_changes.html
http://www.adobe.com/support/security/bulletins/apsb08-18.html Patch Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2008-0945.html
http://www.redhat.com/support/errata/RHSA-2008-0980.html
http://www.vupen.com/english/advisories/2008/2838
https://exchange.xforce.ibmcloud.com/vulnerabilities/45913
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:7.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:7.0.25:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:7.0.63:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:7.0.69.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:7.0.70.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:7.0_r67:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:7.1:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:7.1.1:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:7.2:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:8.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:8.0.24.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:8.0.34.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:8.0.35.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:8.0.39.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.112.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.114.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:flash_player:9.0.115.0:*:*:*:*:*:*:*

History

21 Nov 2024, 00:51

Type Values Removed Values Added
References () http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html - () http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html -
References () http://secunia.com/advisories/32270 - Patch, Vendor Advisory () http://secunia.com/advisories/32270 - Patch, Vendor Advisory
References () http://secunia.com/advisories/32448 - () http://secunia.com/advisories/32448 -
References () http://secunia.com/advisories/32702 - () http://secunia.com/advisories/32702 -
References () http://secunia.com/advisories/32759 - () http://secunia.com/advisories/32759 -
References () http://secunia.com/advisories/33390 - () http://secunia.com/advisories/33390 -
References () http://secunia.com/advisories/34226 - () http://secunia.com/advisories/34226 -
References () http://security.gentoo.org/glsa/glsa-200903-23.xml - () http://security.gentoo.org/glsa/glsa-200903-23.xml -
References () http://securitytracker.com/id?1021061 - () http://securitytracker.com/id?1021061 -
References () http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1 - () http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1 -
References () http://support.avaya.com/elmodocs2/security/ASA-2008-440.htm - () http://support.avaya.com/elmodocs2/security/ASA-2008-440.htm -
References () http://support.avaya.com/elmodocs2/security/ASA-2009-020.htm - () http://support.avaya.com/elmodocs2/security/ASA-2009-020.htm -
References () http://www.adobe.com/devnet/flashplayer/articles/fplayer10_security_changes.html - () http://www.adobe.com/devnet/flashplayer/articles/fplayer10_security_changes.html -
References () http://www.adobe.com/support/security/bulletins/apsb08-18.html - Patch, Vendor Advisory () http://www.adobe.com/support/security/bulletins/apsb08-18.html - Patch, Vendor Advisory
References () http://www.redhat.com/support/errata/RHSA-2008-0945.html - () http://www.redhat.com/support/errata/RHSA-2008-0945.html -
References () http://www.redhat.com/support/errata/RHSA-2008-0980.html - () http://www.redhat.com/support/errata/RHSA-2008-0980.html -
References () http://www.vupen.com/english/advisories/2008/2838 - () http://www.vupen.com/english/advisories/2008/2838 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/45913 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/45913 -

Information

Published : 2008-10-17 19:31

Updated : 2024-11-21 00:51


NVD link : CVE-2008-4401

Mitre link : CVE-2008-4401

CVE.ORG link : CVE-2008-4401


JSON object : View

Products Affected

adobe

  • flash_player
CWE
CWE-264

Permissions, Privileges, and Access Controls