First published: Fri May 01 2009(Updated: )
Unspecified vulnerability in Adobe Flash Media Server (FMS) before 3.0.4 and 3.5.x before 3.5.2, as used in Flash Media Interactive Server and Flash Media Streaming Server, allows remote attackers to execute arbitrary remote procedures within an ActionScript file on the server via RPC requests.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Flash Media Server | =2.0.1 | |
Adobe Flash Media Server | =3.5 | |
Adobe Flash Media Server | =3.0.1 | |
Adobe Flash Media Server | =2.0.2 | |
Adobe Flash Media Server | =3.5.1 | |
Adobe Flash Media Server | =2.0.5 | |
Adobe Flash Media Server | =3.0.2 | |
Adobe Flash Media Server | =2.0.3 | |
Adobe Flash Media Server | =2.0.4 | |
Adobe Flash Media Server | <=3.0.3 | |
Adobe Flash Media Server | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1365 is considered a serious vulnerability as it allows remote attackers to execute arbitrary procedures on the server.
To fix CVE-2009-1365, upgrade to Adobe Flash Media Server version 3.0.4 or 3.5.2 or later.
CVE-2009-1365 affects Adobe Flash Media Server versions 2.0.1 through 3.0.3 and all 3.5.x versions prior to 3.5.2.
Yes, CVE-2009-1365 can be exploited remotely via RPC requests made to the vulnerable Flash Media Server.
CVE-2009-1365 is associated with remote code execution attacks through improperly handled ActionScript files.