CVE-2007-4324
published 2007-08-14CVE-2007-4324: ActionScript 3 (AS3) in Adobe Flash Player 9.0.47.0, and other versions and other 9.0.124.0 and earlier versions, allows remote attackers to bypass the…
PriorityP428medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
7.93%
94.1th percentile
ActionScript 3 (AS3) in Adobe Flash Player 9.0.47.0, and other versions and other 9.0.124.0 and earlier versions, allows remote attackers to bypass the Security Sandbox Model, obtain sensitive information, and port scan arbitrary hosts via a Flash (SWF) movie that specifies a connection to make, then uses timing discrepancies from the SecurityErrorEvent error to determine whether a port is open or not. NOTE: 9.0.115.0 introduces support for a workaround, but does not fix the vulnerability.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | <= 9.0.114.0 | — |
| adobe | shockwave_player | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pwqr-x6x9-wjxj: The Adobe Macromedia Flash 9 plug-in allows remote attackers to cause a victim machine to establish TCP sessions with arbitrary hosts via a Flash (SWF
ghsa_unreviewed·2022-05-01·CVSS 5.0
CVE-2007-5275 [MEDIUM] CWE-20 GHSA-pwqr-x6x9-wjxj: The Adobe Macromedia Flash 9 plug-in allows remote attackers to cause a victim machine to establish TCP sessions with arbitrary hosts via a Flash (SWF
The Adobe Macromedia Flash 9 plug-in allows remote attackers to cause a victim machine to establish TCP sessions with arbitrary hosts via a Flash (SWF) movie, related to lack of pinning of a hostname to a single IP address after receiving an allow-access-from element in a cross-domain-policy XML document, and the availability of a Flash Socket class that does not use the browser's DNS pins, aka DNS rebinding attacks, a different issue than CVE-2002-1467 and CVE-2007-4324.
GHSA
GHSA-fvv5-4452-jhc8: ActionScript 3 (AS3) in Adobe Flash Player 9
ghsa_unreviewed·2022-05-01
CVE-2007-4324 [MEDIUM] GHSA-fvv5-4452-jhc8: ActionScript 3 (AS3) in Adobe Flash Player 9
ActionScript 3 (AS3) in Adobe Flash Player 9.0.47.0, and other versions and other 9.0.124.0 and earlier versions, allows remote attackers to bypass the Security Sandbox Model, obtain sensitive information, and port scan arbitrary hosts via a Flash (SWF) movie that specifies a connection to make, then uses timing discrepancies from the SecurityErrorEvent error to determine whether a port is open or not. NOTE: 9.0.115.0 introduces support for a workaround, but does not fix the vulnerability.
Red Hat
Flash plugin DNS rebinding
vendor_redhat·2007-10-08·CVSS 5.0
CVE-2007-5275 [MEDIUM] Flash plugin DNS rebinding
Flash plugin DNS rebinding
The Adobe Macromedia Flash 9 plug-in allows remote attackers to cause a victim machine to establish TCP sessions with arbitrary hosts via a Flash (SWF) movie, related to lack of pinning of a hostname to a single IP address after receiving an allow-access-from element in a cross-domain-policy XML document, and the availability of a Flash Socket class that does not use the browser's DNS pins, aka DNS rebinding attacks, a different issue than CVE-2002-1467 and CVE-2007-4324.
Red Hat
Flash movie can determine whether a TCP port is open
vendor_redhat·2007-08-09·CVSS 5.0
CVE-2007-4324 [MEDIUM] Flash movie can determine whether a TCP port is open
Flash movie can determine whether a TCP port is open
ActionScript 3 (AS3) in Adobe Flash Player 9.0.47.0, and other versions and other 9.0.124.0 and earlier versions, allows remote attackers to bypass the Security Sandbox Model, obtain sensitive information, and port scan arbitrary hosts via a Flash (SWF) movie that specifies a connection to make, then uses timing discrepancies from the SecurityErrorEvent error to determine whether a port is open or not. NOTE: 9.0.115.0 introduces support for a workaround, but does not fix the vulnerability.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-5275 Flash plugin DNS rebinding
bugzilla·2007-11-05·CVSS 5.0
CVE-2007-5275 [MEDIUM] CVE-2007-5275 Flash plugin DNS rebinding
CVE-2007-5275 Flash plugin DNS rebinding
Common Vulnerabilities and Exposures assigned an identifier CVE-2007-5275 to the following vulnerability:
The Adobe Macromedia Flash 9 plug-in allows remote attackers to cause a victim machine to establish TCP sessions with arbitrary hosts via a Flash (SWF) movie, related to lack of pinning of a hostname to a single IP address after receiving an allow-access-from element in a cross-domain-policy XML document, and the availability of a Flash Socket class that does not use the browser's DNS pins, aka DNS rebinding attacks, a different issue than CVE-2002-1467 and CVE-2007-4324.
References:
http://crypto.stanford.edu/dns/dns-rebinding.pdf
Discussion:
Issue was addressed in supported products by:
https://rhn.redhat.com/errata/RHSA-2007-1126.html
Bugzilla
CVE-2007-4324 Flash movie can determine whether a TCP port is open
bugzilla·2007-08-15·CVSS 5.0
CVE-2007-4324 [MEDIUM] CVE-2007-4324 Flash movie can determine whether a TCP port is open
CVE-2007-4324 Flash movie can determine whether a TCP port is open
Common Vulnerabilities and Exposures assigned an identifier CVE-2007-4324
to the following vulnerability:
ActionScript 3 (AS3) in Adobe Flash Player 9.0.47.0 allows remote attackers to bypass the Security Sandbox Model, obtain sensitive information, and port scan arbitrary hosts via a Flash (SWF) movie that specifies a connection to make, then using timing discrepancies from the SecurityErrorEvent error to determine whether a host is open or not.
References:
http://www.securityfocus.com/archive/1/archive/1/475961/100/0/threaded
Discussion:
Issue was addressed in supported products by:
https://rhn.redhat.com/errata/RHSA-2007-1126.html
http://kb.adobe.com/selfservice/viewContent.do?externalId=kb402956&sliceId=2http://lists.opensuse.org/opensuse-security-announce/2007-12/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.htmlhttp://scan.flashsec.org/http://secunia.com/advisories/28157http://secunia.com/advisories/28161http://secunia.com/advisories/28213http://secunia.com/advisories/28570http://secunia.com/advisories/30507http://secunia.com/advisories/32270http://secunia.com/advisories/32448http://secunia.com/advisories/32702http://secunia.com/advisories/32759http://secunia.com/advisories/33390http://securityreason.com/securityalert/2995http://securitytracker.com/id?1019116http://sunsolve.sun.com/search/document.do?assetkey=1-26-238305-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1http://support.avaya.com/elmodocs2/security/ASA-2008-440.htmhttp://support.avaya.com/elmodocs2/security/ASA-2009-020.htmhttp://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=834256&poid=http://www.adobe.com/devnet/flashplayer/articles/fplayer10_security_changes.htmlhttp://www.adobe.com/support/security/bulletins/apsb07-20.htmlhttp://www.adobe.com/support/security/bulletins/apsb08-18.htmlhttp://www.gentoo.org/security/en/glsa/glsa-200801-07.xmlhttp://www.redhat.com/support/errata/RHSA-2007-1126.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0945.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0980.htmlhttp://www.securityfocus.com/archive/1/475961/100/0/threadedhttp://www.securityfocus.com/bid/25260http://www.us-cert.gov/cas/techalerts/TA07-355A.htmlhttp://www.vupen.com/english/advisories/2007/4258http://www.vupen.com/english/advisories/2008/1724/referenceshttp://www.vupen.com/english/advisories/2008/2838https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11874http://kb.adobe.com/selfservice/viewContent.do?externalId=kb402956&sliceId=2http://lists.opensuse.org/opensuse-security-announce/2007-12/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.htmlhttp://scan.flashsec.org/http://secunia.com/advisories/28157http://secunia.com/advisories/28161http://secunia.com/advisories/28213http://secunia.com/advisories/28570http://secunia.com/advisories/30507http://secunia.com/advisories/32270http://secunia.com/advisories/32448http://secunia.com/advisories/32702http://secunia.com/advisories/32759http://secunia.com/advisories/33390http://securityreason.com/securityalert/2995http://securitytracker.com/id?1019116http://sunsolve.sun.com/search/document.do?assetkey=1-26-238305-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1http://support.avaya.com/elmodocs2/security/ASA-2008-440.htmhttp://support.avaya.com/elmodocs2/security/ASA-2009-020.htmhttp://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=834256&poid=http://www.adobe.com/devnet/flashplayer/articles/fplayer10_security_changes.htmlhttp://www.adobe.com/support/security/bulletins/apsb07-20.htmlhttp://www.adobe.com/support/security/bulletins/apsb08-18.htmlhttp://www.gentoo.org/security/en/glsa/glsa-200801-07.xmlhttp://www.redhat.com/support/errata/RHSA-2007-1126.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0945.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0980.htmlhttp://www.securityfocus.com/archive/1/475961/100/0/threadedhttp://www.securityfocus.com/bid/25260http://www.us-cert.gov/cas/techalerts/TA07-355A.htmlhttp://www.vupen.com/english/advisories/2007/4258http://www.vupen.com/english/advisories/2008/1724/referenceshttp://www.vupen.com/english/advisories/2008/2838https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11874
2007-08-14
Published