Overview
A vulnerability in Adobe Flash Player may allow a remote attacker to bypass allowScriptAccess protection.
Description
Adobe Flash Player is a player for the Flash media format and enables frame-based animations with sound to be viewed within a web browser. According to Adobe: |
Impact
By convincing a victim to view a HTML document (web page, HTML email) containing specially crafted Adobe Flash SWF file, an attacker could access content in a different security domain than the one containing the attacker's document. |
Solution
Upgrade Flash Player |
Disable Adobe Flash Player in your web browser |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This issue was reported in Adobe Security bulletin APSB06-11.
This document was written by Jeff Gennari.
Other Information
CVE IDs: | CVE-2006-4640 |
Severity Metric: | 14.29 |
Date Public: | 2006-09-12 |
Date First Published: | 2006-09-20 |
Date Last Updated: | 2006-11-14 21:30 UTC |
Document Revision: | 23 |