CVE-2007-6637

Publication date 4 January 2008

Last updated 24 July 2024


Ubuntu priority

Description

Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player allow remote attackers to inject arbitrary web script or HTML via a crafted SWF file, related to "pre-generated SWF files" and Adobe Dreamweaver CS3 or Adobe Acrobat Connect. NOTE: the asfunction: vector is already covered by CVE-2007-6244.1.

Status

Package Ubuntu Release Status
flashplugin-nonfree 9.10 karmic
Fixed 10.0.32.18ubuntu1
9.04 jaunty
Fixed 10.0.32.18ubuntu0.9.04.1
8.10 intrepid
Fixed 10.0.32.18ubuntu0.8.10.1
8.04 LTS hardy
Fixed 9.0.246.0ubuntu1
7.10 gutsy Ignored end of life, was needed
7.04 feisty Ignored end of life, was needed
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper Ignored end of life