News & Events

2006 Press Releases

PDF Version

Vulnerabilities Discovered in Adobe Flash Player Plugin Allow Potential Attackers to Send Arbitrary HTTP Requests fromUsers' Browsers, Warns Vulnerability Management Company Rapid7

Rapid7 Reports Two Adobe Flash Vulnerabilities That Can Be Exploited with Specific Browser/Operating System Combinations and Potentially Used to Perform Cross-Site Request Forgery (CSRF) Attacks

Boston - October 17, 2006 - Two vulnerabilities found in Adobe Flash Player provide opportunity to attackers to send arbitrary HTTP requests from an unsuspecting user’s browser, reports Rapid7 LLC in a security advisory published today (see Rapid7 Advisory R7-0026: HTTP Header Injection Vulnerabilities in the Flash Player Plugin). These vulnerabilities could be used in concert with cross-site request forgery (CSRF) vulnerabilities to steal cookies or other private information. Adobe Flash Player version 9.0.16 for Windows and version 7.0.63 for Linux, as well as earlier versions, are affected.

The exploits can be carried out through the vulnerabilities when Flash is used with the following browser/operating system combinations:

  • Internet Explorer (IE) 6 Service Pack 2 (IE 6, Security Version 1) for Windows (with Flash 9.0.16)
  • Firefox 1.5.0.6 for Windows (with Flash 9.0.16)
  • Firefox 1.5.0.6 for Linux (with Flash 7.0.63)

The two vulnerabilities reported are as follows:

XML.addRequestHeader() Vulnerability

The addRequestHeader() method insufficiently secures itself, providing a way around a security restriction that does not permit developers to use addRequestHeader() to set headers such as Host, Referer or Content-Length. As a result, it is possible to inject arbitrary headers with HTTP requests. The Rapid7 security paper points out that this vulnerability is similar to other, previously-reported vulnerabilities in Adobe Flash 7 and 8.

XML.contentType Vulnerability

The XML.contentType attribute contains the same vulnerability found in the addRequestHeader() and it can be exploited in the same way because Adobe Flash does not check the validity of the attribute’s value before building the HTTP request.

According to Rapid7, Adobe was notified of the vulnerabilities but has not yet released a fix or upgrade to Adobe Flash Player. To protect from the risk of attack, Rapid7 offers four solutions in the interim:

  • Upgrade to the beta version (Flash Player 9.0.18d60 for Windows), which is fixed;
  • Only allow trusted Web sites to use Flash;
  • Use alternative Flash Plugins (GplFlash, Gnash); or
  • Uninstall Adobe Flash Player.

According to Adobe, there are 700 million Adobe Flash users worldwide (source: labs.adobe.com).

To protect its customers, Rapid7 has added data on these two vulnerabilities to security checks performed by NeXpose, its enterprise network vulnerability management solution.

About Rapid7 NeXpose

The award-winning Rapid7 NeXpose Unified Vulnerability Management (UVM) is an all-in-one security solution that scans networks, Web applications, databases, to locate threats, assess their risk to the environment, devise a remediation plan and implement the ticketing process. NeXpose incorporates an expert system to build a knowledge base of facts on the environment it explores and model potential targeted attacks to expose all existing threats. NeXpose provides robust reporting capabilities that ensure compliance with governmental regulations, corporate security configuration policies, and the PCI Data Security Standard. NeXpose is available as a "plug and play" appliance, downloadable software, or an On-Demand hosted solution.

About Rapid7

Rapid7 is the leading provider of unified vulnerability management, compliance, and penetration testing solutions, delivering actionable intelligence about an organization’s entire IT environment.  Rapid7 offers the only integrated threat management solution that enables organizations to implement and maintain best practices and optimize their network security, Web application security and database security strategies.

Recognized as the fastest growing vulnerability management company in the U.S. by Inc. Magazine, Rapid7 helps leading organizations such as Liz Claiborne, Southern Company, the United States Postal Service, the New York Times, Carnegie Mellon University and the National Nuclear Security Administration (NNSA) to mitigate risk and maintain compliance for regulations such as PCI, HIPAA, FISMA, SOX and NERC . Rapid7 also manages the Metasploit Project, the leading open-source penetration testing platform with the world’s largest database of public, tested exploits.  For more information, visit www.rapid7.com.

Awards
inc500 Award Logo inc500 Award Logo 2009 Redherring Winner Logo 2009 Best Prodcuts Logo 2009 Tomorrow Tech Logo 2009 GPE Awrads Logo Finalist Hot Companies 2009 Logo Rapid7 Star100 Revised Graphic Gartner POS Rating Graphic SC Award Nominee 2008 Nominee 2008 Global Exeellence SC Awards 2007 Finalist Hot Companies of 2007 Customer Trust Logo Hot Company 2006 Logo SC 2006 Awards Winner