Secunia Advisory SA38547

Adobe Flash Player Domain Sandbox Bypass Vulnerability
Secunia Advisory SA38547
Release Date 2010-02-12
   
Popularity 925 views

Criticality level Moderately criticalModerately critical
Impact Security Bypass
Where From remote
Authentication level Available in Customer Area
   
Report reliability Available in Customer Area
Solution Status Vendor Patch
   
Systems affected Available in Customer Area
Approve distribution Available in Customer Area
Remediation status Secunia CSI, Secunia PSI
Automated scanning Secunia CSI, Secunia PSI
   
Software:Adobe AIR 1.x
Adobe Flash CS3
Adobe Flash CS4
Adobe Flash Player 10.x
Adobe Flex 3.x

Secunia CVSS Score Available in Customer Area
CVE Reference(s) CVE-2010-0186 CVSS available in Customer Area
CVE-2010-0187 CVSS available in Customer Area
  

Description
A vulnerability has been reported in Adobe Flash Player, which can be exploited by malicious people to bypass certain security restrictions.

The vulnerability is caused due to an unspecified error while enforcing cross-domain restrictions. This can be exploited to bypass domain sandbox limitations and perform unauthorized cross-domain requests.

NOTE: An error causing a potential DoS (Denial of Service) has also been reported.

Solution
Update to a fixed version.
Further details available in Customer Area

Provided and/or discovered by
The vendor credits Michael Yong Park.

Changelog
Further details available in Customer Area

Original Advisory
http://www.adobe.com/support/security/bulletins/apsb10-06.html

Other references
Further details available in Customer Area

Technical Analysis
Further details available in Customer Area

Alternate/detailed remediation
Further details available in Customer Area

Deep Links
Links available in Customer Area


Discuss this advisory
A new thread in our forum is automatically created for each posted Secunia Advisory. Activate the thread by commenting/discussing below.
Subject: Adobe Flash Player Domain Sandbox Bypass Vulnerability
 
No posts yet

-

You must be logged in to post a comment.



footer
© 2002-2010 Secunia ApS • Weidekampsgade 14A, Copenhagen, Denmark • +45 7020 5144 • info@secunia.com
Terms & Conditions and CopyrightReport vulnerability
CVE logo OTA logo First logo