CVE-2010-3636

Publication date 7 November 2010

Last updated 24 July 2024


Ubuntu priority

Description

Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1 on Android, does not properly handle unspecified encodings during the parsing of a cross-domain policy file, which allows remote web servers to bypass intended access restrictions via unknown vectors.

Status

Package Ubuntu Release Status
adobe-flashplugin 10.10 maverick
Fixed 10.1.102.64-1maverick1
10.04 LTS lucid
Fixed 10.1.102.64-1lucid1
9.10 karmic
Fixed 10.1.102.64-1karmic1
8.04 LTS hardy
Fixed 10.1.102.64-1
6.06 LTS dapper Not in release
flashplugin-nonfree 10.10 maverick
Fixed 10.1.102.64ubuntu0.10.10.1
10.04 LTS lucid
Fixed 10.1.102.64ubuntu0.10.04.1
9.10 karmic
Fixed 10.1.102.64ubuntu0.9.10.1
8.04 LTS hardy
Fixed 10.0.1.218+really9.0.289.0ubuntu1
6.06 LTS dapper Ignored end of life


Access our resources on patching vulnerabilities