漏洞信息详情
Adobe Flash Player Plugin HTTP报头跨站脚本请求伪造漏洞
- CNNVD编号:CNNVD-200610-243
- 危害等级: 中危
- CVE编号:
CVE-2006-5330
- 漏洞类型:
跨站脚本
- 发布时间:
2006-10-17
- 威胁类型:
远程
- 更新时间:
2006-10-18
- 厂 商:
adobe - 漏洞来源:
Marc Bevand is cre… -
漏洞简介
针对Windows的Adobe Flash Player plugin 9.0.16以及针对Linux的7.0.63版本以及更早的版本,其包含CRLF注入漏洞,远程攻击者可以通过ActionScript函数(1)XML.addRequestHeader和(2)XML.contentType的自变量中的CRLF序列来修改客户端请求的HTTP报头和执行HTTP请求拆分攻击。
漏洞公告
目前厂商已经发布了升级补丁以修复此安全问题,补丁获取链接:
Sun Solaris 10.0
Sun 125332-01
http://sunsolve.sun.com/search/document.do?assetkey=1-21-125332-01-1
Sun Solaris 10.0_x86
Sun 125333-01
http://sunsolve.sun.com/search/document.do?assetkey=1-21-125333-01-1
Apple Mac OS X Server 10.4.8
Apple Mac OS X v10.4.9
http://www.apple.com/support/downloads/
Apple Mac OS X 10.4.8
Apple Mac OS X v10.4.9
http://www.apple.com/support/downloads/
Adobe Flash Player Plugin 7.0.25
SuSE flash-player-7.0.69.0-1.1.i586.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/flash-player-7.0 .69.0-1.1.i586.rpm
SuSE flash-player-7.0.69.0-1.1.i586.rpm
SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/i586/flash-player-7.0. 69.0-1.1.i586.rpm
Adobe Flash Player Plugin 7.0.63
SuSE flash-player-7.0.69.0-1.1.i586.rpm
openSUSE 10.2:
ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/flash-player-7.0.69.0 -1.1.i586.rpm
SuSE flash-player-7.0.69.0-1.2.i586.rpm
SUSE LINUX 10.1:
ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/flash-player-7.0.69.0 -1.2.i586.rpm
参考网址
来源: TA07-072A
名称: TA07-072A
链接:http://www.us-cert.gov/cas/techalerts/TA07-072A.html
来源: XF
名称: flashplayer-multiple-xsrf(29634)
链接:http://xforce.iss.net/xforce/xfdb/29634
来源: BID
名称: 20592
链接:http://www.securityfocus.com/bid/20592
来源: BUGTRAQ
名称: 20061017 Rapid7 Advisory R7-0026: HTTP Header Injection Vulnerabilities in the Flash Player Plugin
链接:http://www.securityfocus.com/archive/1/archive/1/448997/100/0/threaded
来源: REDHAT
名称: RHSA-2007:0009
链接:http://www.redhat.com/support/errata/RHSA-2007-0009.html
来源: MISC
链接:http://www.rapid7.com/advisories/R7-0026.jsp
来源: OSVDB
名称: 29863
来源: VUPEN
名称: ADV-2007-1999
链接:http://www.frsirt.com/english/advisories/2007/1999
来源: VUPEN
名称: ADV-2007-0930
链接:http://www.frsirt.com/english/advisories/2007/0930
来源: VUPEN
名称: ADV-2006-4094
链接:http://www.frsirt.com/english/advisories/2006/4094
来源: www.adobe.com
链接:http://www.adobe.com/support/security/bulletins/apsb06-18.html
来源: www.adobe.com
链接:http://www.adobe.com/support/security/advisories/apsa06-01.html
来源: SUNALERT
名称: 102932
链接:http://sunsolve.sun.com/search/document.do?assetkey=1-26-102932-1
来源: SECTRACK
名称: 1017078
链接:http://securitytracker.com/id?1017078
来源: SREASON
名称: 1737
链接:http://securityreason.com/securityalert/1737
来源: SECUNIA
名称: 25467
链接:http://secunia.com/advisories/25467
来源: SECUNIA
名称: 24479
链接:http://secunia.com/advisories/24479
来源: SECUNIA
名称: 23581
链接:http://secunia.com/advisories/23581
来源: SECUNIA
名称: 23324
链接:http://secunia.com/advisories/23324
来源: SECUNIA
名称: 22467
链接:http://secunia.com/advisories/22467
来源: SUSE
名称: SUSE-SA:2006:077
链接:http://lists.suse.com/archive/suse-security-announce/2006-Dec/0006.html
来源: APPLE
名称: APPLE-SA-2007-03-13
链接:http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html
来源: docs.info.apple.com