Accessibility

Security Bulletin

MPSB05-11 Administrator Interface Denial of Service Vulnerability in Flash Media Server

Originally posted: December 15, 2005

Summary

This bulletin addresses a publicly reported security issue with Flash Media Server.

Affected Software Versions

  • Flash Media Server 2.0
  • Flash Media Server 1.5

Severity Rating

Adobe categorizes this issue as a important issue and recommends users implement this workaround to their installations.

Details

Remote Administrator Interface Denial of Service Vulnerability

Flash Media Server remote administrator interface connects using TCP to port 1111. An error exists in the way that the server handles malformed data allowing a remote attacker to crash the administrator service.

Note: This vulnerability does not prevent the Flash Media Server from streaming content.

Solution

NOTE: Back up your existing files before making changes. As always, test the changes in a non-production environment before applying the changes to production servers.

Adobe has tested the following workarounds for Flash Media Server. These workarounds will not eliminate the underlying vulnerability; however, they will limit your exposure to attacks.

Block Access via Firewall

The Flash Media Server should always be deployed within a Demilitarized Zone (DMZ – network segment between the internet and a LAN). Network access controls (VPN) should be in place to restrict who has access to the trusted DMZ. Most importantly, a firewall should be used to restrict the ports allowed in and out of the DMZ. Currently, Adobe’s Flash Media Server deployment procedures recommend that the Administrator port (1111) be blocked from public networks (i.e., Internet) via a firewall. Customers should continue this practice.

Restrict the IP(s) allowed to access the Administrator service.

Most modern operating system have firewalls built in that can restrict allowed IP addresses; for example, IPTables on Unix/Linux and IP Security Policy on Windows.  To set up your host based firewall, please refer to your operating system documentation.  Adobe recommends limiting access to localhost (127.0.0.1).

Disable the Administrator Service on production systems.

Since the Administrator and Flash Media service run as different non-dependent processes, the Administrator service can be disabled without effecting streaming content delivery.

For more information on Flash Media Server security visit: http://www.macromedia.com/devnet/flashcom/articles/security_setup.html

Revisions

December 15, 2005 — Bulletin first created.

Reporting Security Issues

Adobe is committed to addressing security issues and providing customers with the information on how they can protect themselves. If you identify what you believe may be a security issue with an Adobe product, please send an email to PSIRT@adobe.com. We will work to appropriately address and communicate the issue.

Receiving Security Bulletins

When Adobe becomes aware of a security issue that we believe significantly affects our products or customers, we will notify customers when appropriate. Typically this notification will be in the form of a security bulletin explaining the issue and the response. Adobe customers who would like to receive notification of new security bulletins when they are released can sign up for our security notification service.

For additional information on security issues at Adobe, please visit: http://www.macromedia.com/security.

ANY INFORMATION, PATCHES, DOWNLOADS, WORKAROUNDS OR FIXES PROVIDED BY ADOBE IN THIS BULLETIN ARE PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. ADOBE AND ITS SUPPLIERS DISCLAIM ALL WARRANTIES, WHETHER EXPRESS OR IMPLIED OR OTHERWISE, INCLUDING THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. ALSO, THERE IS NO WARRANTY OF NON-INFRINGEMENT, TITLE OR QUIET ENJOYMENT. (USA ONLY) SOME STATES DO NOT ALLOW THE EXCLUSION OF IMPLIED WARRANTIES, SO THE ABOVE EXCLUSION MAY NOT APPLY TO YOU.

IN NO EVENT SHALL ADOBE, INC. OR ITS SUPPLIERS BE LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING, WITHOUT LIMITATION, DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, SPECIAL, PUNITIVE, COVER, LOSS OF PROFITS, BUSINESS INTERRUPTION OR THE LIKE, OR LOSS OF BUSINESS DAMAGES, BASED ON ANY THEORY OF LIABILITY INCLUDING BREACH OF CONTRACT, BREACH OF WARRANTY, TORT(INCLUDING NEGLIGENCE), PRODUCT LIABILITY OR OTHERWISE, EVEN IF ADOBE, INC. OR ITS SUPPLIERS OR THEIR REPRESENTATIVES HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. (USA ONLY) SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES, SO THE ABOVE EXCLUSION OR LIMITATION MAY NOT APPLY TO YOU AND YOU MAY ALSO HAVE OTHER LEGAL RIGHTS THAT VARY FROM STATE TO STATE.

Adobe reserves the right, from time to time, to update the information in this document with current information.