flash-plugin: information leaks and hardening bypass fixed in APSB15-23
Published Sep 22, 2015
4.3
MEDIUMCVSS 2.0
EPSS 3.34%
Description
Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API. NOTE: this issue exists because of an incomplete fix for CVE-2014-4671 and CVE-2014-5333.
Affected products
No data.
Configuration 1
- ≤ 11.2.202.508
Running on/with
- n/a
Configuration 2
Configuration 3
- ≤ 13.0.0.289
- 14.0.0.125
- 14.0.0.145
- 14.0.0.176
- 14.0.0.179
- 15.0.0.152
- 15.0.0.167
- 15.0.0.189
- 15.0.0.223
- 15.0.0.239
- 15.0.0.246
- 16.0.0.235
- 16.0.0.257
- 16.0.0.287
- 16.0.0.296
- 17.0.0.134
- 17.0.0.169
- 17.0.0.188
- 17.0.0.190
- 17.0.0.191
- 18.0.0.160
- 18.0.0.194
- 18.0.0.203
- 18.0.0.209
- 18.0.0.232
No data.
Red Hat Enterprise Linux 5 Supplementary
flash-plugin-0:11.2.202.521-1.el5
Fixed · RHSA-2015:1814
Red Hat Enterprise Linux 6 Supplementary
flash-plugin-0:11.2.202.521-1.el6_7
Fixed · RHSA-2015:1814
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 Supplementary | flash-plugin-0:11.2.202.521-1.el5 | Fixed | RHSA-2015:1814 |
| Red Hat Enterprise Linux 6 Supplementary | flash-plugin-0:11.2.202.521-1.el6_7 | Fixed | RHSA-2015:1814 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (17)
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00022.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00023.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00024.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00018.html vendor-advisoryx_refsource_SUSE
- http://rhn.redhat.com/errata/RHSA-2015-1814.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/76803 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id/1033629 vdb-entryx_refsource_SECTRACK
- https://access.redhat.com/security/cve/CVE-2015-5571 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1265121 Issue Tracking
- https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04939841 x_refsource_CONFIRM
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05356388 x_refsource_CONFIRM
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680 x_refsource_CONFIRM
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722 x_refsource_CONFIRM
- https://helpx.adobe.com/security/products/flash-player/apsb15-23.html x_refsource_CONFIRMPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2015-5571
- https://security.gentoo.org/glsa/201509-07 vendor-advisoryx_refsource_GENTOO
- https://www.cve.org/CVERecord?id=CVE-2015-5571
Change history (0)
No recorded changes yet.