Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2008-3873
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-3873

Description:
The System.setClipboard method in ActionScript in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to populate the clipboard with a URL that is difficult to delete and does not require user interaction to populate the clipboard, as exploited in the wild in August 2008.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/44584

SUSE
  http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html

SUNALERT
  http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1

ST
  1020724

SAID
  Secunia Advisory: SA33390
  Secunia Advisory: SA32759
  Secunia Advisory: SA32702
  Secunia Advisory: SA34226
  Secunia Advisory: SA32448

REDHAT
  http://www.redhat.com/support/errata/RHSA-2008-0980.html
  http://www.redhat.com/support/errata/RHSA-2008-0945.html

MISC
  http://blogs.zdnet.com/security/?p=1759
  http://blogs.zdnet.com/security/?p=1733

GENTOO
  http://security.gentoo.org/glsa/glsa-200903-23.xml

CONFIRM
  http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=834256&poid=
  http://support.avaya.com/elmodocs2/security/ASA-2009-020.htm
  http://support.avaya.com/elmodocs2/security/ASA-2008-440.htm
  http://www.adobe.com/support/security/bulletins/apsb08-18.html
  http://www.adobe.com/devnet/flashplayer/articles/fplayer10_security_changes.html
  http://blogs.adobe.com/psirt/2008/08/clipboard_attack.html

BID
  31117


Return to the previous page.