FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2008-1834

This CVE name corresponds to:

Entered Topic
2008-05-07 swfdec -- exposure of sensitive information

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2008-1834
Phase Assigned(20080416)

Description

swfdec_load_object.c in Swfdec before 0.6.4 does not properly restrict local file access from untrusted sandboxes, which allows remote attackers to read arbitrary files via a crafted Flash file.

References

Source Reference
MLIST [Swfdec] 20080409 Swfdec 0.6.4 released
CONFIRM http://gitweb.freedesktop.org/?p=swfdec/swfdec.git;a=commit;h=326ee4ff631ecc11605f1251e1923a94561a3823
BID 28881
SECUNIA 29915
XF swfdec-swfdecloadobject-info-disclosure(41887)