Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2008-4401

Published: 17 October 2008

ActionScript in Adobe Flash Player 9.0.124.0 and earlier does not require user interaction in conjunction with (1) the FileReference.browse operation in the FileReference upload API or (2) the FileReference.download operation in the FileReference download API, which allows remote attackers to create a browse dialog box, and possibly have unspecified other impact, via an SWF file.

Priority

Medium

Status

Package Release Status
flashplugin-nonfree
Launchpad, Ubuntu, Debian
dapper Ignored
(end of life)
gutsy Ignored
(end of life, was needed)
hardy
Released (9.0.246.0ubuntu1)
intrepid Not vulnerable
(10.0.12.36ubuntu1)
jaunty Not vulnerable
(10.0.12.36ubuntu1)
karmic Not vulnerable
(10.0.12.36ubuntu1)
upstream
Released (10.0.12.36)