Vulnerabilities > CVE-2008-1201 - Unspecified vulnerability in Adobe Flash Basic/Professional
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Multiple unspecified vulnerabilities in FLA file parsing in Adobe Flash CS3 Professional, Flash Professional 8, and Flash Basic 8 on Windows allow user-assisted remote attackers to execute arbitrary code via a crafted .FLA file.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
Seebug
bulletinFamily | exploit |
description | BUGTRAQ ID: 28349 CVE(CAN) ID: CVE-2008-1201 Adobe Flash CS3 Professional软件是用于为数码、Web和移动平台创建丰富的交互式内容的最高级创作环境。 Adobe Flash CS3 Professional处理畸形格式的.FLA文件时存在漏洞,攻击者可能利用此漏洞提升权限。 如果用户受骗使用Flash CS3 Professional打开了畸形的.FLA文件的话,就可能导致执行任意指令。 FLA是Flash Professional和Flash Basic的私有文件格式,Flash Player和浏览器都无法解释FLA文件,因此无法远程利用这个漏洞。 Adobe Flash Professional 8 Adobe Flash CS3 Professional 9.0 Adobe Flash Basic 8 Adobe ----- 目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载: <a href=http://www.adobe.com target=_blank>http://www.adobe.com</a> |
id | SSV:3067 |
last seen | 2017-11-19 |
modified | 2008-03-21 |
published | 2008-03-21 |
reporter | Root |
title | Adobe Flash CS3 Professional FLA文件处理代码执行漏洞 |
References
- http://ruder.cdut.net/blogview.asp?logID=241
- http://ruder.cdut.net/blogview.asp?logID=241
- http://secunia.com/advisories/29455
- http://secunia.com/advisories/29455
- http://www.adobe.com/support/security/advisories/apsa08-03.html
- http://www.adobe.com/support/security/advisories/apsa08-03.html
- http://www.fortiguardcenter.com/advisory/FGA-2008-07.html
- http://www.fortiguardcenter.com/advisory/FGA-2008-07.html
- http://www.securityfocus.com/bid/28349
- http://www.securityfocus.com/bid/28349
- http://www.securitytracker.com/id?1019681
- http://www.securitytracker.com/id?1019681
- http://www.vupen.com/english/advisories/2008/0948/references
- http://www.vupen.com/english/advisories/2008/0948/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41327
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41327