Vulnerability Description
Unspecified vulnerability in the Settings Manager in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87, and possibly other versions, allows remote attackers to trick a user into visiting an arbitrary URL via unknown vectors, related to "a potential Clickjacking issue variant."
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Air | 1.5 |
| Adobe | Flash Player | <= 10.0.12.36 |
| Adobe | Flash Player For Linux | <= 10.0.15.3 |
| Adobe | Flex | 3.0 |
| Microsoft | Windows | All versions |
References
- http://isc.sans.org/diary.html?storyid=5929
- http://lists.apple.com/archives/security-announce/2009/May/msg00002.html
- http://secunia.com/advisories/34226
- http://secunia.com/advisories/34293
- http://secunia.com/advisories/35074
- http://security.gentoo.org/glsa/glsa-200903-23.xml
- http://securitytracker.com/id?1021751
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-254909-1
- http://support.apple.com/kb/HT3549
- http://www.adobe.com/support/security/bulletins/apsb09-01.htmlPatchVendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2009/0513Patch
- http://www.vupen.com/english/advisories/2009/0743
- http://www.vupen.com/english/advisories/2009/1297
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48902
FAQ
What is CVE-2009-0114?
CVE-2009-0114 is a vulnerability with a CVSS score of 5.8 (MEDIUM). Unspecified vulnerability in the Settings Manager in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87, and possibly other versions, allows remote attackers to trick a user into visit...
How severe is CVE-2009-0114?
CVE-2009-0114 has been rated MEDIUM with a CVSS base score of 5.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-0114?
Check the references section above for vendor advisories and patch information. Affected products include: Adobe Air, Adobe Flash Player, Adobe Flash Player For Linux, Adobe Flex, Microsoft Windows.