CVE-2007-3457

Publication date 11 July 2007

Last updated 17 July 2025


Ubuntu priority

Description

Adobe Flash Player 8.0.34.0 and earlier insufficiently validates HTTP Referer headers, which might allow remote attackers to conduct a CSRF attack via a crafted SWF file.

Status

Package Ubuntu Release Status
flashplugin-nonfree 9.10 karmic
Fixed 9.0.48.0.0ubuntu10
9.04 jaunty
Fixed 9.0.48.0.0ubuntu10
8.10 intrepid
Fixed 9.0.48.0.0ubuntu10
8.04 LTS hardy
Fixed 9.0.48.0.0ubuntu10
7.10 gutsy
Fixed 9.0.48.0.0ubuntu10
7.04 feisty
Fixed 9.0.48.0.0ubuntu1~7.04.1
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper Ignored end of life


Access our resources on patching vulnerabilities