|
|
|
Vulnerability Note VU#758769Adobe Flash Player asfunction protocol may enable cross-site scriptingOverviewThe Adobe Flash player asfunction protocol could allow an attacker to conduct cross-site scripting attacks on websites that host vulnerable Flash files.I. DescriptionThe Adobe Flash Player is a player for the Flash media format and enables frame-based animations and multimedia to be viewed within a web browser. ActionScript is a scripting language that is used to develop software and multimedia files that are processed by the Adobe Flash Player. The asfunction protocol enables HTTP hyperlinks in Flash files to launch a ActionScript functions.Per Adobe Security Bulletin APSB07-20:
Note that vulnerable versions of the Flash Player may be distributed with various operating systems. II. ImpactA remote, unauthenticated attacker may be able to launch cross-site scripting attacks against sites that host vulnerable Flash files.III. SolutionUpdate Flash PlayerAdobe has released an update to address this issue. Adobe Security Bulletin APSB07-20 contains more information about obtaining fixed software. Adobe Dreamweaver users may need to manually update their Flash player to obtain updates. See the Protocol Solutions Network Security Blog Adobe/Macromedia/Dreamweaver vulnerability posting for more information.
References
Adobe credits Rich Cannings of the Google Security Team for reporting this issue. This document was written by Ryan Giobbi.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||