Upstream information
Description
The Adobe Macromedia Flash 9 plug-in allows remote attackers to cause a victim machine to establish TCP sessions with arbitrary hosts via a Flash (SWF) movie, related to lack of pinning of a hostname to a single IP address after receiving an allow-access-from element in a cross-domain-policy XML document, and the availability of a Flash Socket class that does not use the browser's DNS pins, aka DNS rebinding attacks, a different issue than CVE-2002-1467 and CVE-2007-4324.NVD CVSS v2 Base Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:P/A:N)
Novell/SUSE information
Novell Bugzilla entry: 332480, 376639 SUSE Security Advisories:- SUSE-SA:2007:069, published Fri, 21 Dec 2007 15:00:00 +0000
- SUSE-SA:2008:022, published Fri, 11 Apr 2008 10:00:00 +0000
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE LINUX 10.1 |
| |
| openSUSE 10.2 openSUSE 10.3 |
| |
| SUSE LINUX 10.1 |
| |
| openSUSE 10.2 openSUSE 10.3 |
| |
| SUSE Linux Enterprise Desktop 10 SP1 for AMD64 and Intel EM64T SUSE Linux Enterprise Desktop 10 SP1 for x86 |
| Builds ZYPP Patch Nr: 5159 |
| SUSE Linux Enterprise Desktop 10 SP1 for AMD64 and Intel EM64T SUSE Linux Enterprise Desktop 10 SP1 for x86 |
| Builds YOU Patch Nr: 12036 ZYPP Patch Nr: 4856 |
| Novell Linux Desktop 9 for x86 Novell Linux Desktop 9 for x86_64 |
| Builds YOU Patch Nr: 12036 ZYPP Patch Nr: 4856 |
| Novell Linux Desktop 9 for x86 Novell Linux Desktop 9 for x86_64 |
| Builds YOU Patch Nr: 12136 |
| Novell Linux Desktop 9 for x86 Novell Linux Desktop 9 for x86_64 |
| Builds YOU Patch Nr: 12051 |
