VulnerabilityModified
CVE-2008-5109
The default configuration of Adobe Flash Media Server (FMS) 3.0 does not enable SWF Verification for (1) RTMPE and (2) RTMPTE sessions, which makes it easier for remote attackers to make copies of video content via stream-capture software.
MEDIUM 5.0EPSS 2.31%
Does this matter?
Lower severity and a low EPSS score (2.31%). Track it; it rarely justifies an emergency change on its own.
Description
The default configuration of Adobe Flash Media Server (FMS) 3.0 does not enable SWF Verification for (1) RTMPE and (2) RTMPTE sessions, which makes it easier for remote attackers to make copies of video content via stream-capture software.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.31% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-16
- Affected
- adobe/flash media server
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/32771Vendor Advisory
- http://www.adobe.com/support/security/advisories/apsa08-11.htmlPatch, Vendor Advisory
- http://www.osvdb.org/49952
- http://secunia.com/advisories/32771Vendor Advisory
- http://www.adobe.com/support/security/advisories/apsa08-11.htmlPatch, Vendor Advisory
- http://www.osvdb.org/49952
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.