受影响系统:
Microsoft Windows XP SP2
Microsoft Windows XP SP1
Microsoft Windows ME
Microsoft Windows 98se
Microsoft Windows 98
RedHat Linux WS 4
RedHat Linux WS 3
RedHat Linux ES 4
RedHat Linux ES 3
RedHat Linux AS 4
RedHat Linux AS 3
Macromedia Flash Player <= 8.0.22.0
Macromedia Breeze Meeting Add-In <= 5.1
Macromedia Shockwave Player <= 10.1.0.11
Macromedia Flash Debug Player <= 7.0.14.0
不受影响系统:
Macromedia Flash Player 8.0.24.0
Macromedia Flash Player 7.0.63.0
Macromedia Breeze Meeting Add-In 7.0.55.331 (Win)
Macromedia Breeze Meeting Add-In 7.0.55.118 (Mac)
Macromedia Shockwave Player 10.1.1
描述:
BUGTRAQ ID: 17106
CVE(CAN) ID: CVE-2006-0024
Macromedia Flash Player是一款非常流行的FLASH播放器。
Flash Player在处理畸形恶意SWF文件时存在缓冲区溢出漏洞,攻击者可能利用此漏洞在客户机器上执行任意指令。
如果攻击者诱骗用户使用Flash Player加载了恶意的SWF文件的话,就会完全控制受影响的系统。
<*来源:Microsoft
链接:http://www.macromedia.com/devnethttp://security.chinaitlab.com/security_zone/apsb06-03.html
http://www.microsoft.com/technethttp://security.chinaitlab.com/advisory/916208.mspx
http://www.us-cert.gov/cas/techalerts/TA06-075A.html
http://lwn.net/Alerts/175844/?format=printable
http://security.gentoo.org/glsa/glsa-200603-20.xml
http://www.microsoft.com/technethttp://security.chinaitlab.com/Bulletin/MS06-020.mspx?pf=true
http://www.us-cert.gov/cas/techalerts/TA06-129A.html
*>
建议:
临时解决方法:
如果您不能立刻安装补丁或者升级,建议您采取以下措施以降低威胁:
* 禁止在IE中运行Flash Player ActiveX控件
* 注销Flash Player ActiveX控件
* 使用“软件限制策略”限制对Macromedia Flash文件夹的访问
* 将Internet Explorer设置更改为在运行ActiveX控件之前进行提示,或者在Internet安全区域和本地Intranet安全区域中禁用ActiveX控件
* 将Internet和本地Intranet安全区域设置设为“高”,以便在这些区域中运行ActiveX控件之前进行提示
* 从系统中删除Flash Player
厂商补丁:
Macromedia
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:
http://www.macromedia.com/devnethttp://security.chinaitlab.com/security_zone/apsb06-03.html
Microsoft
Microsoft已经为此发布了一个安全公告(MS06-020)以及相应补丁:
MS06-020:Vulnerabilities in Macromedia Flash Player from Adobe Could Allow Remote Code Execution (913433)
链接:http://www.microsoft.com/technethttp://security.chinaitlab.com/Bulletin/MS06-020.mspx?pf=true
补丁下载:
http://www.microsoft.com/downloads/details.aspx?FamilyId=B2B8F9A8-4874-405A-9F0C-768B2631673A
RedHat
RedHat已经为此发布了一个安全公告(RHSA-2006:0268-01)以及相应补丁:
RHSA-2006:0268-01:Critical: flash-plugin security update
链接:http://lwn.net/Alerts/175844/?format=printable
Gentoo
Gentoo已经为此发布了一个安全公告(GLSA-200603-20)以及相应补丁:
GLSA-200603-20:Macromedia Flash Player: Arbitrary code execution
链接:http://security.gentoo.org/glsa/glsa-200603-20.xml
所有Macromedia Flash Player用户都应升级到最新版本:
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-www/netscape-flash-7.0.63"