CVE-2009-0521Sensitive Information Exposure in Adobe Flash Player FOR Linux

Severity
4.6MEDIUMNVD
EPSS
0.2%
top 51.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 26
Latest updateMay 2

Description

Untrusted search path vulnerability in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 on Linux allows local users to obtain sensitive information or gain privileges via a crafted library in a directory contained in the RPATH.

CVSS vector

AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4

Affected Packages1 packages

NVDadobe/flash_player10.0.15.3+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-h35j-98vm-989g: Untrusted search path vulnerability in Adobe Flash Player 92022-05-02
CVEList
CVE-2009-0521: Untrusted search path vulnerability in Adobe Flash Player 92009-02-26

📋Vendor Advisories

1
Red Hat
flash-plugin: Linux-specific information disclosure (privilege escalation)2009-02-24

💬Community

1
Bugzilla
CVE-2009-0521 flash-plugin: Linux-specific information disclosure (privilege escalation)2009-02-24
CVE-2009-0521 — Sensitive Information Exposure in Adobe | cvebase