CVE-2006-5330

Impact:
Moderate
Public Date:
2006-10-17
Bugzilla:
1618210: CVE-2006-5330 security flaw

The MITRE CVE dictionary describes this issue as:

CRLF injection vulnerability in Adobe Flash Player plugin 9.0.16 and earlier for Windows, 7.0.63 and earlier for Linux, 7.x before 7.0 r67 for Solaris, and before 9.0.28.0 for Mac OS X, allows remote attackers to modify HTTP headers of client requests and conduct HTTP Request Splitting attacks via CRLF sequences in arguments to the ActionScript functions (1) XML.addRequestHeader and (2) XML.contentType. NOTE: the flexibility of the attack varies depending on the type of web browser being used.

Find out more about CVE-2006-5330 from the MITRE CVE dictionary dictionary and NIST NVD.

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux AS version 3 Extras (flash-plugin) RHSA-2007:0009 2007-01-09
Red Hat Enterprise Linux AS version 4 Extras (flash-plugin) RHSA-2007:0009 2007-01-09

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.