Common Vulnerabilities and Exposures assigned an identifier CVE-2008-3873 to the following vulnerability: The System.setClipboard method in Adobe Flash Player allows remote attackers to populate the clipboard with a URL that is difficult to delete, as exploited in the wild in August 2008. References: http://blogs.zdnet.com/security/?p=1733 http://blogs.zdnet.com/security/?p=1759 http://blogs.adobe.com/psirt/2008/08/clipboard_attack.html http://www.securityfocus.com/bid/31117 http://securitytracker.com/id?1020724 Demo: http://raffon.net/research/flash/cb/test.html
This issue was addressed in: Red Hat Enterprise Linux Extras: http://rhn.redhat.com/errata/RHSA-2008-0945.html http://rhn.redhat.com/errata/RHSA-2008-0980.html