[Japanese]
|
JVNDB-2012-000046
|
Flash Player issue in implementations of the Same Origin Policy
|
Flash Player contains an issue in implementations of the Same Origin Policy.
SoundMixer.computeSpectrum() method, included in Flash Player, contains an issue in implementations of the Same Origin Policy.
Mitsuaki Shiraishi of Symantec Japan, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
|
CVSS V2 Severity: Base Metrics 2.6 (Low) [IPA Score]
- Access Vector: Network
- Access Complexity: High
- Authentication: None
- Confidentiality Impact: Partial
- Integrity Impact: None
- Availability Impact: None
|
|
Adobe Systems, Inc.
- Adobe Flash Player 11.2.202.235 and earlier versions for Windows, Macintosh and Linux
- Adobe Flash Player 11.1.115.8 and earlier versions for Android 4.x
- Adobe Flash Player 11.1.111.9 and earlier versions for Android 3.x and 2.x
|
|
An attacker may obtain sound spectrum data that user playing in violation of the same-origin policy.
|
[Update the Software]
Update to the latest version according to the information provided by the developer.
|
Adobe Systems, Inc.
FUJITSU
|
- No Mapping(CWE-Other) [IPA Evaluation]
|
- CVE-2012-2038
|
- JVN : JVN#38163638
- National Vulnerability Database (NVD) : CVE-2012-2038
|
- [2012/06/11]
Web page was published
[2012/06/13]
Vendor Information : Content was added
|