CVE-2008-3872: Critical severity macromedia flash player vulnerability
Published Oct 6, 2008
·Updated
Adobe Flash Player 8.0.39.0 and earlier, and 9.x up to 9.0.115.0, allows remote attackers to bypass the allowScriptAccess parameter setting via a crafted SWF file with unspecified "Filter evasion" manipulations.
Affected Software
2 affected components
Adobe Flash Player>=8.0<=8.0.39.0
Adobe Flash Player>=9.0<=9.0.115.0
Event History
Oct 6, 2008
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-3872?
CVE-2008-3872 is considered to be a critical vulnerability due to its potential for exploitation via crafted SWF files.
2
How do I fix CVE-2008-3872?
To fix CVE-2008-3872, upgrade to Adobe Flash Player version 9.0.115.0 or later.
3
Which software versions are affected by CVE-2008-3872?
CVE-2008-3872 affects Adobe Flash Player 8.0.39.0 and earlier, as well as any 9.x versions up to 9.0.115.0.
4
Can CVE-2008-3872 allow remote attacks?
Yes, CVE-2008-3872 allows remote attackers to bypass security settings through specially crafted SWF files.
5
What parameters can be bypassed due to CVE-2008-3872?
CVE-2008-3872 allows attackers to bypass the allowScriptAccess parameter setting.