First published: Wed Feb 13 2008(Updated: )
Use-after-free vulnerability in the Edge server in Adobe Flash Media Server 2 before 2.0.5, and Connect Enterprise Server 6 before SP3, allows remote attackers to execute arbitrary code via an unspecified sequence of Real Time Message Protocol (RTMP) requests.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Connect Enterprise Server | <=6 | |
Adobe Flash Media Server 2 | <=2.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-6148 is considered a critical vulnerability as it allows remote attackers to execute arbitrary code.
To fix CVE-2007-6148, update Adobe Flash Media Server to version 2.0.5 or later and Adobe Connect Enterprise Server to SP3 or later.
CVE-2007-6148 affects Adobe Flash Media Server 2 versions up to and including 2.0.4 and Adobe Connect Enterprise Server 6 versions up to and including SP2.
Attackers can exploit CVE-2007-6148 to execute arbitrary code on affected systems through crafted RTMP requests.
CVE-2007-6148 poses a risk to any system still running the affected versions of Adobe Flash Media Server or Connect Enterprise Server that have not been updated.