CVE-2014-4671
published 2014-07-09CVE-2014-4671: Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.202.394 on Linux, Adobe AIR before 14.0.0.137 on Android…
PriorityP337medium4.3CVSS 2.0
AVNACMAuNCPINAN
EXPLOIT
EPSS
23.02%
97.5th percentile
Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.202.394 on Linux, Adobe AIR before 14.0.0.137 on Android, Adobe AIR SDK before 14.0.0.137, and Adobe AIR SDK & Compiler before 14.0.0.137 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API.
Affected
78 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_air | <= 14.0.0.110 | — |
| adobe | adobe_air | <= 14.0.0.137 | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air_sdk | <= 14.0.0.110 | — |
| adobe | adobe_air_sdk | <= 14.0.0.137 | — |
| adobe | adobe_air_sdk | — | — |
| adobe | adobe_air_sdk | — | — |
| adobe | adobe_air_sdk | — | — |
| adobe | air | <= 18.0.0.199 | — |
| adobe | air | <= 18.0.0.143 | — |
| adobe | air_sdk | <= 18.0.0.199 | — |
| adobe | air_sdk_compiler | <= 18.0.0.180 | — |
| adobe | flash_player | <= 11.2.202.378 | — |
| adobe | flash_player | <= 13.0.0.223 | — |
| adobe | flash_player | <= 11.2.202.508 | — |
| adobe | flash_player | <= 13.0.0.289 | — |
| adobe | flash_player | <= 13.0.0.231 | — |
| adobe | flash_player | <= 11.2.202.394 | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv4.3MEDIUM
vendor_redhat4.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
flash-plugin: information leaks and hardening bypass fixed in APSB15-23
vendor_redhat·2015-09-21·CVSS 4.3
CVE-2015-5571 [MEDIUM] flash-plugin: information leaks and hardening bypass fixed in APSB15-23
flash-plugin: information leaks and hardening bypass fixed in APSB15-23
Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API. NOTE: this issue exists because of an incomplete fix for CVE-2014-4671 and CVE-2014-5333.
Red Hat
flash-plugin: multiple code execution or security bypass flaws (APSB14-18)
vendor_redhat·2014-08-12·CVSS 4.3
CVE-2014-5333 [MEDIUM] flash-plugin: multiple code execution or security bypass flaws (APSB14-18)
flash-plugin: multiple code execution or security bypass flaws (APSB14-18)
Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before 14.0.0.178, and Adobe AIR SDK & Compiler before 14.0.0.178 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API, in conjunction with a manipulation involving a '$' (dollar sign) or '(' (open parenthesis) character. NOTE: this issue exists because of an incomplet
Red Hat
flash-plugin: vulnerable JSONP callback APIs issue (APSB14-17)
vendor_redhat·2014-07-08·CVSS 4.3
CVE-2014-4671 [MEDIUM] flash-plugin: vulnerable JSONP callback APIs issue (APSB14-17)
flash-plugin: vulnerable JSONP callback APIs issue (APSB14-17)
Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.202.394 on Linux, Adobe AIR before 14.0.0.137 on Android, Adobe AIR SDK before 14.0.0.137, and Adobe AIR SDK & Compiler before 14.0.0.137 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API.
A flaw was found that would lead to Cross-Site Request Forgery (CSRF) attacks.
GHSA
GHSA-9rw6-x6f2-42c3: Adobe Flash Player before 18
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2015-5571 [MEDIUM] CWE-200 GHSA-9rw6-x6f2-42c3: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API. NOTE: this issue exists because of an incomplete fix for CVE-2014-4671 and CVE-2014-5333.
GHSA
GHSA-p4f6-prp8-fmgf: Adobe Flash Player before 13
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2014-5333 [MEDIUM] CWE-352 GHSA-p4f6-prp8-fmgf: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before 14.0.0.178, and Adobe AIR SDK & Compiler before 14.0.0.178 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API, in conjunction with a manipulation involving a '$' (dollar sign) or '(' (open parenthesis) character. NOTE: this issue exists because of an incomplete fix for CVE-2014-4671.
GHSA
Rosetta-Flash JSONP Vulnerability in hapi
ghsa·2020-08-31
CVE-2014-4671 [MEDIUM] CWE-352 Rosetta-Flash JSONP Vulnerability in hapi
Rosetta-Flash JSONP Vulnerability in hapi
This description taken from the pull request provided by Patrick Kettner.
Versions 6.1.0 and earlier of hapi are vulnerable to a rosetta-flash attack, which can be used by attackers to send data across domains and break the browser same-origin-policy.
## Recommendation
- Update hapi to version 6.1.1 or later.
Alternatively, a solution previously implemented by Google, Facebook, and Github is to prepend callbacks with an empty inline comment. This will cause the flash parser to break on invalid inputs and prevent the issue, and how the issue has been resolved internally in hapi.
OSV
Rosetta-Flash JSONP Vulnerability in hapi
osv·2020-08-31
CVE-2014-4671 [MEDIUM] Rosetta-Flash JSONP Vulnerability in hapi
Rosetta-Flash JSONP Vulnerability in hapi
This description taken from the pull request provided by Patrick Kettner.
Versions 6.1.0 and earlier of hapi are vulnerable to a rosetta-flash attack, which can be used by attackers to send data across domains and break the browser same-origin-policy.
## Recommendation
- Update hapi to version 6.1.1 or later.
Alternatively, a solution previously implemented by Google, Facebook, and Github is to prepend callbacks with an empty inline comment. This will cause the flash parser to break on invalid inputs and prevent the issue, and how the issue has been resolved internally in hapi.
OSV
CVE-2015-5571: Adobe Flash Player before 18
osv·2015-09-22·CVSS 4.3
CVE-2015-5571 [MEDIUM] CVE-2015-5571: Adobe Flash Player before 18
Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API. NOTE: this issue exists because of an incomplete fix for CVE-2014-4671 and CVE-2014-5333.
OSV
CVE-2014-5333: Adobe Flash Player before 13
osv·2014-08-19·CVSS 4.3
CVE-2014-5333 [MEDIUM] CVE-2014-5333: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before 14.0.0.178, and Adobe AIR SDK & Compiler before 14.0.0.178 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API, in conjunction with a manipulation involving a '$' (dollar sign) or '(' (open parenthesis) character. NOTE: this issue exists because of an incomplete fix for CVE-2014-4671.
OSV
CVE-2014-4671: Adobe Flash Player before 13
osv·2014-07-09·CVSS 4.3
CVE-2014-4671 [MEDIUM] CVE-2014-4671: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.202.394 on Linux, Adobe AIR before 14.0.0.137 on Android, Adobe AIR SDK before 14.0.0.137, and Adobe AIR SDK & Compiler before 14.0.0.137 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API.
Suricata
ET WEB_SERVER Adobe Flash Player Rosetta Flash compressed CWS in URI
suricata·2014-07-18
CVE-2014-4671 ET WEB_SERVER Adobe Flash Player Rosetta Flash compressed CWS in URI
ET WEB_SERVER Adobe Flash Player Rosetta Flash compressed CWS in URI
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SERVER Adobe Flash Player Rosetta Flash compressed CWS in URI"; flow:established,to_server; urilen:>70; http.uri; content:"callback=CWS"; nocase; pcre:"/^[a-z0-9\.\_]{5}hC[a-z0-9\.\_]{50}/Ri"; reference:url,miki.it/blog/2014/7/8/abusing-jsonp-with-rosetta-flash/; reference:cve,2014-4671; classtype:attempted-user; sid:2018740; rev:3; metadata:created_at 2014_07_18, cve CVE_2014_4671, signature_severity Minor, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2020_04_30;)
Suricata
ET WEB_CLIENT Adobe Flash Player Rosetta Flash compressed CWS
suricata·2014-07-09
CVE-2014-4671 ET WEB_CLIENT Adobe Flash Player Rosetta Flash compressed CWS
ET WEB_CLIENT Adobe Flash Player Rosetta Flash compressed CWS
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_CLIENT Adobe Flash Player Rosetta Flash compressed CWS"; flow:established,to_client; file.data; content:"callback=CWS"; nocase; fast_pattern; content:")).)+?data\s*?\=\s*?[\x22\x27][^\x22\x27]*[?&]callback=CWS[a-zA-Z0-9_\.\x0d\x0a]{50,}+[&\x22\x27]/Rsi"; reference:url,miki.it/blog/2014/7/8/abusing-jsonp-with-rosetta-flash/; reference:cve,2014-4671; classtype:attempted-user; sid:2018656; rev:5; metadata:affected_product Web_Browsers, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2014_07_09, cve CVE_2014_4671, deployment Perimeter, signature_severity Major, tag Web_Client_Attacks, updated_at 2024_04_07;)
Suricata
ET WEB_CLIENT Adobe Flash Player Rosetta Flash compressed ZWS
suricata·2014-07-09
CVE-2014-4671 ET WEB_CLIENT Adobe Flash Player Rosetta Flash compressed ZWS
ET WEB_CLIENT Adobe Flash Player Rosetta Flash compressed ZWS
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_CLIENT Adobe Flash Player Rosetta Flash compressed ZWS"; flow:established,to_client; file.data; content:"callback=ZWS"; nocase; fast_pattern; content:")).)+?data\s*?\=\s*?[\x22\x27][^\x22\x27]*[?&]callback=ZWS[a-zA-Z0-9_\.\x0d\x0a]{50,}+[&\x22\x27]/Rsi"; reference:url,miki.it/blog/2014/7/8/abusing-jsonp-with-rosetta-flash/; reference:cve,2014-4671; classtype:attempted-user; sid:2018658; rev:5; metadata:affected_product Web_Browsers, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2014_07_09, cve CVE_2014_4671, deployment Perimeter, signature_severity Major, tag Web_Client_Attacks, updated_at 2024_04_07;)
Suricata
ET WEB_CLIENT Adobe Flash Player Rosetta Flash compressed FWS
suricata·2014-07-09
CVE-2014-4671 ET WEB_CLIENT Adobe Flash Player Rosetta Flash compressed FWS
ET WEB_CLIENT Adobe Flash Player Rosetta Flash compressed FWS
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_CLIENT Adobe Flash Player Rosetta Flash compressed FWS"; flow:established,to_client; file.data; content:"callback=FWS"; nocase; fast_pattern; content:")).)+?data\s*?\=\s*?[\x22\x27][^\x22\x27]*[?&]callback=FWS[a-zA-Z0-9_\.\x0d\x0a]{50,}+[&\x22\x27]/Rsi"; reference:url,miki.it/blog/2014/7/8/abusing-jsonp-with-rosetta-flash/; reference:cve,2014-4671; classtype:attempted-user; sid:2018657; rev:5; metadata:affected_product Web_Browsers, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2014_07_09, cve CVE_2014_4671, deployment Perimeter, signature_severity Major, tag Web_Client_Attacks, updated_at 2024_04_07;)
Bugzilla
CVE-2014-0538 CVE-2014-0540 CVE-2014-0541 CVE-2014-0542 CVE-2014-0543 CVE-2014-0544 CVE-2014-0545 CVE-2014-5333 flash-plugin: multiple code execution or security bypass flaws (APSB14-18)
bugzilla·2014-08-12·CVSS 10.0
CVE-2014-0538 [CRITICAL] CVE-2014-0538 CVE-2014-0540 CVE-2014-0541 CVE-2014-0542 CVE-2014-0543 CVE-2014-0544 CVE-2014-0545 CVE-2014-5333 flash-plugin: multiple code execution or security bypass flaws (APSB14-18)
CVE-2014-0538 CVE-2014-0540 CVE-2014-0541 CVE-2014-0542 CVE-2014-0543 CVE-2014-0544 CVE-2014-0545 CVE-2014-5333 flash-plugin: multiple code execution or security bypass flaws (APSB14-18)
Adobe has released Flash Player 11.2.202.400 for Linux to correct the following flaws:
* These updates resolve memory leakage vulnerabilities that could be used to bypass memory address randomization (CVE-2014-0540, CVE-2014-0542, CVE-2014-0543, CVE-2014-0544, CVE-2014-0545).
* These updates resolve a security bypass vulnerability (CVE-2014-0541).
* These updates resolve a use-after-free vulnerability that could lead to code execution (CVE-2014-0538).
External References:
http://helpx.adobe.com/security/products/flash-player/apsb14-18.html
Discussion:
This issue has been addressed in following pro
Bugzilla
CVE-2014-1546 bugzilla: Cross Site Request Forgery issue with Bugzilla's JSONP endpoint
bugzilla·2014-07-25·CVSS 4.3
CVE-2014-1546 [MEDIUM] CVE-2014-1546 bugzilla: Cross Site Request Forgery issue with Bugzilla's JSONP endpoint
CVE-2014-1546 bugzilla: Cross Site Request Forgery issue with Bugzilla's JSONP endpoint
The upstream Bugzilla 4.0.14, 4.2.10, 4.4.5, 4.5.5 releases fix the following issue:
""
Adobe does not properly restrict the SWF file format,
which allows remote attackers to conduct cross-site
request forgery (CSRF) attacks against Bugzilla's JSONP
endpoint, possibly obtaining sensitive bug information,
via a crafted OBJECT element with SWF content satisfying
the character-set requirements of a callback API.
References: https://bugzilla.mozilla.org/show_bug.cgi?id=1036213
""
The 3.2.10 and 3.4.14 versions in EPEL 5 and 6 appear too old to be affected.
Reference:
http://www.bugzilla.org/security/4.0.13/
Discussion:
Created bugzilla tracking bugs for this issue:
Affects: fedora-all [bug 1123173]
Bugzilla
CVE-2014-4671 flash-plugin: vulnerable JSONP callback APIs issue (APSB14-17)
bugzilla·2014-07-09·CVSS 4.3
CVE-2014-4671 [MEDIUM] CVE-2014-4671 flash-plugin: vulnerable JSONP callback APIs issue (APSB14-17)
CVE-2014-4671 flash-plugin: vulnerable JSONP callback APIs issue (APSB14-17)
Adobe has released Flash Player 11.2.202.394 for Linux to correct the following flaws:
These updates include additional validation checks to ensure that Flash Player rejects malicious content from vulnerable JSONP callback APIs (CVE-2014-4671).
External References:
http://helpx.adobe.com/security/products/flash-player/apsb14-17.html
Discussion:
IssueDescription:
A flaw was found that would lead to Cross-Site Request Forgery (CSRF) attacks.
---
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2014:0860 https://rhn.redhat.com/errata/RHSA-2014-0860.html
---
Detailed write-up of the issue form its report
Bugzilla
[SECURITY] Add '/**/' before jsonrpc.cgi callback to avoid swf content type sniff vulnerability
bugzilla·2014-07-09
[CRITICAL] [SECURITY] Add '/**/' before jsonrpc.cgi callback to avoid swf content type sniff vulnerability
[SECURITY] Add '/**/' before jsonrpc.cgi callback to avoid swf content type sniff vulnerability
Created attachment 8452810
poc.html
User Agent: Mozilla/5.0 (X11; Linux i686 (x86_64)) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.1916.153 Safari/537.36
Steps to reproduce:
Hi,
I think you may already know about this vulnerability(no, take a look - miki.it/blog/2014/7/8/abusing-jsonp-with-rosetta-flash/)
this vulnerability allows the page jsonrpc.cgi as a swf file then resulting in http request in local webserver(bugzilla.mozilla.org). To patch that add '/**/' before the callback function.
Reproduce:
1. Log in bugzilla.
2. open poc.html(attached)
3. wait 10 seconds
4. you will be redirected to a page that contains the source code of 'bugzilla.mozilla.org'(was got via victim browse
http://helpx.adobe.com/security/products/flash-player/apsb14-17.htmlhttp://miki.it/blog/2014/7/8/abusing-jsonp-with-rosetta-flash/http://rhn.redhat.com/errata/RHSA-2014-0860.htmlhttp://secunia.com/advisories/59774http://secunia.com/advisories/59837http://security.gentoo.org/glsa/glsa-201407-02.xmlhttp://www.securityfocus.com/bid/68457http://www.securitytracker.com/id/1030533http://helpx.adobe.com/security/products/flash-player/apsb14-17.htmlhttp://miki.it/blog/2014/7/8/abusing-jsonp-with-rosetta-flash/http://rhn.redhat.com/errata/RHSA-2014-0860.htmlhttp://secunia.com/advisories/59774http://secunia.com/advisories/59837http://security.gentoo.org/glsa/glsa-201407-02.xmlhttp://www.securityfocus.com/bid/68457http://www.securitytracker.com/id/1030533
2014-07-09
Published