CVE-2007-5275

NameCVE-2007-5275
DescriptionThe Adobe Macromedia Flash 9 plug-in allows remote attackers to cause a victim machine to establish TCP sessions with arbitrary hosts via a Flash (SWF) movie, related to lack of pinning of a hostname to a single IP address after receiving an allow-access-from element in a cross-domain-policy XML document, and the availability of a Flash Socket class that does not use the browser's DNS pins, aka DNS rebinding attacks, a different issue than CVE-2002-1467 and CVE-2007-4324.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium (attack range: remote)
Debian Bugs449110

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
flashplugin-nonfree (PTS)wheezy/contrib1:3.2+wheezy1fixed
jessie/contrib1:3.6.1+deb8u1fixed
sid/contrib1:3.7fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
flashplugin-nonfreesource(unstable)9.0.115.0.1medium449110

Notes

[sarge] - flashplugin-nonfree <no-dsa> (Contrib not supported)
[etch] - flashplugin-nonfree <no-dsa> (Contrib not supported)

Search for package or bug name: Reporting problems