First published: Wed Apr 09 2008(Updated: )
Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via an SWF file with a modified DeclareFunction2 Actionscript tag, which prevents an object from being instantiated properly.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe AIR | =1.0 | |
Adobe Flash Player | =basic-8 | |
Adobe Flash Player | =professional-8 | |
Adobe Flash Player | =professional-cs3 | |
Adobe Flash Player for Internet Explorer 11 | <=9.0.115.0 | |
Adobe Flash Player for Internet Explorer 11 | =7.0 | |
Adobe Flash Player for Internet Explorer 11 | =7.0.1 | |
Adobe Flash Player for Internet Explorer 11 | =7.0.25 | |
Adobe Flash Player for Internet Explorer 11 | =7.0.63 | |
Adobe Flash Player for Internet Explorer 11 | =7.0.69.0 | |
Adobe Flash Player for Internet Explorer 11 | =7.0.70.0 | |
Adobe Flash Player for Internet Explorer 11 | =7.0_r67 | |
Adobe Flash Player for Internet Explorer 11 | =7.1 | |
Adobe Flash Player for Internet Explorer 11 | =7.1.1 | |
Adobe Flash Player for Internet Explorer 11 | =7.2 | |
Adobe Flash Player for Internet Explorer 11 | =8 | |
Adobe Flash Player for Internet Explorer 11 | =8 | |
Adobe Flash Player for Internet Explorer 11 | =8.0 | |
Adobe Flash Player for Internet Explorer 11 | =8.0 | |
Adobe Flash Player for Internet Explorer 11 | =8.0 | |
Adobe Flash Player for Internet Explorer 11 | =8.0.24.0 | |
Adobe Flash Player for Internet Explorer 11 | =8.0.34.0 | |
Adobe Flash Player for Internet Explorer 11 | =8.0.35.0 | |
Adobe Flash Player for Internet Explorer 11 | =8.0.39.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.16 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.16 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.18d60 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.20 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.20.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.28 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.28.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.31 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.31.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.45.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.47.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.48.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.112.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.114.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.124.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.155.0 | |
Adobe Flex | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-6019 has been classified as a critical severity vulnerability due to its potential to allow remote code execution.
To fix CVE-2007-6019, update Adobe Flash Player to version 9.0.115.1 or later, or upgrade to the latest version of Adobe AIR.
CVE-2007-6019 affects Adobe Flash Player versions 9.0.115.0 and earlier, as well as versions 8.0.39.0 and earlier.
Exploiting CVE-2007-6019 could allow an attacker to execute arbitrary code, potentially compromising the user's system and sensitive data.
The best workaround for CVE-2007-6019 is to disable Adobe Flash Player until an update can be applied.