FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2007-3457

This CVE name corresponds to:

Entered Topic
2007-07-18 linux-flashplugin -- critical vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2007-3457
Phase Assigned(20070626)

Description

Adobe Flash Player 8.0.34.0 and earlier insufficiently validates HTTP Referer headers, which might allow remote attackers to conduct a CSRF attack via a crafted SWF file.

References

Source Reference
CONFIRM http://www.adobe.com/support/security/bulletins/apsb07-12.html
GENTOO GLSA-200708-01
SUNALERT 103167
SUNALERT 201506
SUSE SUSE-SA:2007:046
CERT TA07-192A
CERT-VN VU#138457
VUPEN ADV-2007-2497
VUPEN ADV-2007-4190
OSVDB 38049
SECTRACK 1018359
SECUNIA 26027
SECUNIA 26118
SECUNIA 26357
SECUNIA 28068
XF flashplayer-swf-httpreferer-csrf(35338)