Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows remote web servers to cause a denial of service (NULL pointer dereference and browser crash) by returning a different response when an HTTP request is sent a second time, as demonstrated by two responses that provide SWF files with different SWF version numbers.
References
Link Providers
http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751 cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00000.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html cve-icon cve-icon
http://secunia.com/advisories/32759 cve-icon cve-icon
http://secunia.com/advisories/40545 cve-icon cve-icon
http://secunia.com/advisories/43026 cve-icon cve-icon
http://security.gentoo.org/glsa/glsa-201101-09.xml cve-icon cve-icon
http://securityreason.com/securityalert/4401 cve-icon cve-icon
http://securitytracker.com/id?1024085 cve-icon cve-icon
http://securitytracker.com/id?1024086 cve-icon cve-icon
http://support.apple.com/kb/HT4435 cve-icon cve-icon
http://www.adobe.com/support/security/bulletins/apsb10-14.html cve-icon cve-icon
http://www.mochimedia.com/~matthew/flashcrash/ cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2010-0464.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2010-0470.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/496929/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/31537 cve-icon cve-icon
http://www.turbolinux.co.jp/security/2010/TLSA-2010-19j.txt cve-icon cve-icon
http://www.us-cert.gov/cas/techalerts/TA10-162A.html cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/1421 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/1432 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/1434 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/1453 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/1482 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/1522 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/1793 cve-icon cve-icon
http://www.vupen.com/english/advisories/2011/0192 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/45630 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2008-4546 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16302 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7187 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2008-4546 cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2008-10-14T15:00:00

Updated: 2024-08-07T10:17:10.087Z

Reserved: 2008-10-14T00:00:00

Link: CVE-2008-4546

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2008-10-14T15:28:16.723

Modified: 2024-11-21T00:51:56.650

Link: CVE-2008-4546

cve-icon Redhat

Severity : Low

Publid Date: 2008-10-02T00:00:00Z

Links: CVE-2008-4546 - Bugzilla