|
|
Info |
Last Modified |
| about 1 year ago |
|
|
|
|
|
Description |
Flash Player 9.0.45.0 and earlier allow an attacker to manipulate HTTP referrer headers by way of ActionScript. This allows an attacker to spoof the origin of a request and bypass common filters to prevent CSRF. An attacker could leverage this for to issue a CSRF from outside of the target's domain.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Information Disclosure,
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Unknown
Disclosure:
OSVDB Verified
|
|
Solution |
Upgrade to Adobe Flash Player version 9.0.47.0 (Windows) or version 9.0.48.0 (Linux), as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
|
|
Products |
|
Flash Player
 |
9.0.45.0 |
|
|
|
|
|
|
Credit |
- Daiki Fukumori - Secure Sky Technology, Inc.
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|