CVE Vulnerabilities

CVE-2008-1834

Published: Apr 16, 2008 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW

swfdec_load_object.c in Swfdec before 0.6.4 does not properly restrict local file access from untrusted sandboxes, which allows remote attackers to read arbitrary files via a crafted Flash file.

Affected Software

Name Vendor Start Version End Version
Swfdec Swfdec * 0.6.2 (including)
Swfdec Swfdec 0.4.0 (including) 0.4.0 (including)
Swfdec Swfdec 0.4.1 (including) 0.4.1 (including)
Swfdec Swfdec 0.4.2 (including) 0.4.2 (including)
Swfdec Swfdec 0.4.3 (including) 0.4.3 (including)
Swfdec Swfdec 0.4.4 (including) 0.4.4 (including)
Swfdec Swfdec 0.4.5 (including) 0.4.5 (including)
Swfdec Swfdec 0.5.0 (including) 0.5.0 (including)
Swfdec Swfdec 0.5.1 (including) 0.5.1 (including)
Swfdec Swfdec 0.5.2 (including) 0.5.2 (including)
Swfdec Swfdec 0.5.3 (including) 0.5.3 (including)
Swfdec Swfdec 0.5.4 (including) 0.5.4 (including)
Swfdec Swfdec 0.5.5 (including) 0.5.5 (including)
Swfdec Swfdec 0.5.90 (including) 0.5.90 (including)
Swfdec Swfdec 0.6.0 (including) 0.6.0 (including)
Swfdec0.5 Ubuntu gutsy *
Swfdec0.5 Ubuntu hardy *
Swfdec0.6 Ubuntu upstream *

References