CVE-2014-4671
flash-plugin: vulnerable JSONP callback APIs issue (APSB14-17)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.202.394 on Linux, Adobe AIR before 14.0.0.137 on Android, Adobe AIR SDK before 14.0.0.137, and Adobe AIR SDK & Compiler before 14.0.0.137 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API.
Adobe Flash Player anterior a 13.0.0.231 y 14.x anterior a 14.0.0.145 en Windows y OS X y anterior a 11.2.202.394 en Linux, Adobe AIR anterior a 14.0.0.137 en Android, Adobe AIR SDK anterior a 14.0.0.137 y Adobe AIR SDK & Compiler anterior a 14.0.0.137 no restringen debidamente el formatos de ficheros SWF, lo que permitte a atacantes remotos realizar ataques de CSRF contra Endpoints JSONP, y obtener información sensible, a través de un elemento OBJECT manipulado con contenido SWF que satisface los requisitos de la configuración de caracteres de una API de devolución de llamadas.
A flaw was found that would lead to Cross-Site Request Forgery (CSRF) attacks.
The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. Multiple flaws were found in the way flash-plugin displayed certain SWF content. An attacker could use these flaws to create a specially crafted SWF file that would cause flash-plugin to crash or, potentially, execute arbitrary code when the victim loaded a page containing the malicious SWF content.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-06-26 CVE Reserved
- 2014-07-09 CVE Published
- 2023-01-28 First Exploit
- 2024-08-06 CVE Updated
- 2025-05-04 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (14)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/59774 | Third Party Advisory | |
http://secunia.com/advisories/59837 | Third Party Advisory | |
http://www.securityfocus.com/bid/68457 | Vdb Entry | |
http://www.securitytracker.com/id/1030533 | Vdb Entry | |
https://github.com/mikispag/rosettaflash | ||
https://www.quaxio.com/jsonp_handcrafted_flash_files |
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/180652 | 2024-08-31 | |
https://github.com/cph/rabl-old | 2023-01-28 | |
http://miki.it/blog/2014/7/8/abusing-jsonp-with-rosetta-flash | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://helpx.adobe.com/security/products/flash-player/apsb14-17.html | 2015-09-22 | |
http://rhn.redhat.com/errata/RHSA-2014-0860.html | 2015-09-22 | |
http://security.gentoo.org/glsa/glsa-201407-02.xml | 2015-09-22 | |
https://access.redhat.com/security/cve/CVE-2014-4671 | 2014-07-09 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1117588 | 2014-07-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | <= 11.2.202.378 Search vendor "Adobe" for product "Flash Player" and version " <= 11.2.202.378" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.223 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.223" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.228 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.228" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.233 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.233" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.235 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.235" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.236 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.236" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.238 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.238" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.243 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.243" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.251 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.251" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.258 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.258" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.261 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.261" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.262 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.262" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.270 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.270" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.273 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.273" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.275 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.275" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.280 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.280" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.285 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.285" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.291 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.291" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.297 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.297" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.310 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.310" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.332 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.332" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.335 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.335" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.336 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.336" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.341 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.341" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.346 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.346" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.350 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.350" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.356 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.356" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 11.2.202.359 Search vendor "Adobe" for product "Flash Player" and version "11.2.202.359" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | <= 13.0.0.223 Search vendor "Adobe" for product "Flash Player" and version " <= 13.0.0.223" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | <= 13.0.0.223 Search vendor "Adobe" for product "Flash Player" and version " <= 13.0.0.223" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 13.0.0.182 Search vendor "Adobe" for product "Flash Player" and version "13.0.0.182" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 13.0.0.182 Search vendor "Adobe" for product "Flash Player" and version "13.0.0.182" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 13.0.0.201 Search vendor "Adobe" for product "Flash Player" and version "13.0.0.201" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 13.0.0.201 Search vendor "Adobe" for product "Flash Player" and version "13.0.0.201" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 13.0.0.206 Search vendor "Adobe" for product "Flash Player" and version "13.0.0.206" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 13.0.0.206 Search vendor "Adobe" for product "Flash Player" and version "13.0.0.206" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 13.0.0.214 Search vendor "Adobe" for product "Flash Player" and version "13.0.0.214" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 13.0.0.214 Search vendor "Adobe" for product "Flash Player" and version "13.0.0.214" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 14.0.0.125 Search vendor "Adobe" for product "Flash Player" and version "14.0.0.125" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | 14.0.0.125 Search vendor "Adobe" for product "Flash Player" and version "14.0.0.125" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Adobe Search vendor "Adobe" | Adobe Air Search vendor "Adobe" for product "Adobe Air" | <= 14.0.0.110 Search vendor "Adobe" for product "Adobe Air" and version " <= 14.0.0.110" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Adobe Air Search vendor "Adobe" for product "Adobe Air" | 13.0.0.83 Search vendor "Adobe" for product "Adobe Air" and version "13.0.0.83" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Adobe Air Search vendor "Adobe" for product "Adobe Air" | 13.0.0.111 Search vendor "Adobe" for product "Adobe Air" and version "13.0.0.111" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Adobe Air Sdk Search vendor "Adobe" for product "Adobe Air Sdk" | <= 14.0.0.110 Search vendor "Adobe" for product "Adobe Air Sdk" and version " <= 14.0.0.110" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Adobe Air Sdk Search vendor "Adobe" for product "Adobe Air Sdk" | 13.0.0.83 Search vendor "Adobe" for product "Adobe Air Sdk" and version "13.0.0.83" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Adobe Air Sdk Search vendor "Adobe" for product "Adobe Air Sdk" | 13.0.0.111 Search vendor "Adobe" for product "Adobe Air Sdk" and version "13.0.0.111" | - |
Affected
|