FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2007-6243

This CVE name corresponds to:

Entered Topic
2008-01-03 linux-flashplugin -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2007-6243
Phase Assigned(20071205)

Description

Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0 does not sufficiently restrict the interpretation and usage of cross-domain policy files, which makes it easier for remote attackers to conduct cross-domain and cross-site scripting (XSS) attacks.

References

Source Reference
MISC http://www.adobe.com/devnet/flashplayer/articles/fplayer9_security.html
MISC http://jvn.jp/jp/JVN%2345675516/index.html
CONFIRM http://www.adobe.com/support/security/bulletins/apsb07-20.html
CONFIRM http://www.adobe.com/support/security/bulletins/apsb08-11.html
APPLE APPLE-SA-2008-05-28
GENTOO GLSA-200801-07
GENTOO GLSA-200804-21
REDHAT RHSA-2008:0221
SUNALERT 238305
SUSE SUSE-SA:2007:069
SUSE SUSE-SA:2008:022
CERT TA07-355A
CERT TA08-100A
CERT TA08-150A
CERT-VN VU#935737
BID 26929
BID 26966
FRSIRT ADV-2007-4258
FRSIRT ADV-2008-1697
FRSIRT ADV-2008-1724
SECTRACK 1019116
SECUNIA 28161
SECUNIA 28570
SECUNIA 28213
SECUNIA 29763
SECUNIA 29865
SECUNIA 30430
SECUNIA 30507
XF adobe-unspecified-security-bypass(39129)