PublicDate: 2007-07-11 16:30:00 UTC Candidate: CVE-2007-3457 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3457 Description: Adobe Flash Player 8.0.34.0 and earlier insufficiently validates HTTP Referer headers, which might allow remote attackers to conduct a CSRF attack via a crafted SWF file. Ubuntu-Description: Notes: Priority: untriaged Discovered-by: Assigned-to: CVSS: Bugs: dapper_flashplugin-nonfree: ignored (reached end-of-life) edgy_flashplugin-nonfree: needed (reached end-of-life) feisty_flashplugin-nonfree: released (9.0.48.0.0ubuntu1~7.04.1) gutsy_flashplugin-nonfree: released (9.0.48.0.0ubuntu10) hardy_flashplugin-nonfree: released (9.0.48.0.0ubuntu10) intrepid_flashplugin-nonfree: released (9.0.48.0.0ubuntu10) jaunty_flashplugin-nonfree: released (9.0.48.0.0ubuntu10) karmic_flashplugin-nonfree: released (9.0.48.0.0ubuntu10) devel_flashplugin-nonfree: released (9.0.48.0.0ubuntu10) upstream_flashplugin-nonfree: needs-triage