FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2007-6243

This CVE name corresponds to:

Entered Topic
2008-10-17 linux-flashplugin -- multiple vulnerabilities
2008-01-03 linux-flashplugin -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2007-6243
Phase Assigned(20071205)

Description

Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0 does not sufficiently restrict the interpretation and usage of cross-domain policy files, which makes it easier for remote attackers to conduct cross-domain and cross-site scripting (XSS) attacks.

References

Source Reference
MISC http://www.adobe.com/devnet/flashplayer/articles/fplayer9_security.html
CONFIRM http://www.adobe.com/support/security/bulletins/apsb07-20.html
CONFIRM http://www.adobe.com/support/security/bulletins/apsb08-11.html
CONFIRM http://support.avaya.com/elmodocs2/security/ASA-2008-440.htm
CONFIRM http://support.avaya.com/elmodocs2/security/ASA-2009-020.htm
CONFIRM http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=834256&poid=
APPLE APPLE-SA-2008-05-28
GENTOO GLSA-200801-07
GENTOO GLSA-200804-21
REDHAT RHSA-2008:0221
REDHAT RHSA-2008:0945
REDHAT RHSA-2008:0980
SUNALERT 238305
SUNALERT 248586
SUSE SUSE-SA:2007:069
SUSE SUSE-SA:2008:022
SUSE SUSE-SR:2008:025
CERT TA07-355A
CERT TA08-100A
CERT TA08-150A
CERT-VN VU#935737
JVN JVN#45675516
BID 26929
BID 26966
OVAL oval:org.mitre.oval:def:11069
VUPEN ADV-2007-4258
VUPEN ADV-2008-1697
VUPEN ADV-2008-1724
SECTRACK 1019116
SECUNIA 28161
SECUNIA 28570
SECUNIA 28213
SECUNIA 29763
SECUNIA 29865
SECUNIA 30430
SECUNIA 30507
SECUNIA 32448
SECUNIA 32759
SECUNIA 32702
SECUNIA 33390
XF adobe-unspecified-security-bypass(39129)