First published: Thu Dec 10 2009(Updated: )
Unspecified vulnerability in the Flash Player ActiveX control in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 on Windows allows remote attackers to obtain the names of local files via unknown vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4820.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows | ||
Adobe AIR SDK | <=1.5.2 | |
Adobe AIR SDK | =1.0 | |
Adobe AIR SDK | =1.0.1 | |
Adobe AIR SDK | =1.1 | |
Adobe AIR SDK | =1.5.1 | |
Adobe Acrobat Reader | <=10.0.32.18 | |
Adobe Acrobat Reader | =7.0 | |
Adobe Acrobat Reader | =7.0.1 | |
Adobe Acrobat Reader | =7.0.25 | |
Adobe Acrobat Reader | =7.0.63 | |
Adobe Acrobat Reader | =7.0.69.0 | |
Adobe Acrobat Reader | =7.0.70.0 | |
Adobe Acrobat Reader | =7.1 | |
Adobe Acrobat Reader | =7.1.1 | |
Adobe Acrobat Reader | =7.2 | |
Adobe Acrobat Reader | =8 | |
Adobe Acrobat Reader | =8 | |
Adobe Acrobat Reader | =8.0 | |
Adobe Acrobat Reader | =8.0 | |
Adobe Acrobat Reader | =8.0 | |
Adobe Acrobat Reader | =8.0.24.0 | |
Adobe Acrobat Reader | =8.0.34.0 | |
Adobe Acrobat Reader | =8.0.35.0 | |
Adobe Acrobat Reader | =8.0.39.0 | |
Adobe Acrobat Reader | =9.0 | |
Adobe Acrobat Reader | =9.0.16 | |
Adobe Acrobat Reader | =9.0.18d60 | |
Adobe Acrobat Reader | =9.0.20 | |
Adobe Acrobat Reader | =9.0.20.0 | |
Adobe Acrobat Reader | =9.0.28 | |
Adobe Acrobat Reader | =9.0.28.0 | |
Adobe Acrobat Reader | =9.0.31 | |
Adobe Acrobat Reader | =9.0.31.0 | |
Adobe Acrobat Reader | =9.0.45.0 | |
Adobe Acrobat Reader | =9.0.47.0 | |
Adobe Acrobat Reader | =9.0.48.0 | |
Adobe Acrobat Reader | =9.0.112.0 | |
Adobe Acrobat Reader | =9.0.114.0 | |
Adobe Acrobat Reader | =9.0.115.0 | |
Adobe Acrobat Reader | =9.0.124.0 | |
Adobe Acrobat Reader | =9.0.155.0 | |
Adobe Acrobat Reader | =9.0.159.0 | |
Adobe Acrobat Reader | =9.125.0 | |
Adobe Acrobat Reader | =10.0.0.584 | |
Adobe Acrobat Reader | =10.0.12.10 | |
Adobe Acrobat Reader | =10.0.12.36 | |
Adobe Acrobat Reader | =10.0.22.87 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-3951 is rated as a critical vulnerability that allows remote attackers to access local file names.
To remediate CVE-2009-3951, upgrade to Adobe Flash Player version 10.0.42.34 or later, or Adobe AIR version 1.5.3 or later.
CVE-2009-3951 affects Adobe Flash Player versions prior to 10.0.42.34 and Adobe AIR versions prior to 1.5.3.
CVE-2009-3951 impacts systems running Adobe Flash Player and Adobe AIR with specific older versions on Windows.
Exploitation of CVE-2009-3951 can lead to information disclosure, allowing attackers to obtain local file names.