From 567f2b57352d98cb373acf1bf31604d1f88170c3 Mon Sep 17 00:00:00 2001 From: =?utf8?q?Fr=C3=A9d=C3=A9ric=20Buclin?= Date: Tue, 13 Nov 2012 18:42:46 +0100 Subject: [PATCH] Bug 808845 (CVE-2012-5475): [SECURITY] Security vulnerability in YUI's swfstore.swf in YUI 2.8.2 and 2.9.0 a=LpSolit --- js/yui/swfstore/swfstore.swf | Bin 4879 -> 4720 bytes 1 file changed, 0 insertions(+), 0 deletions(-) diff --git a/js/yui/swfstore/swfstore.swf b/js/yui/swfstore/swfstore.swf index b2f5cd071e58ec7f1e5b54a60ab2cc967ebc9c8d..cfd42c18da82ca6bfc1d4cafabc529789a61e168 100644 GIT binary patch literal 4720 zc-jGQ5|8aeS5pgs9RL7$+I?ARbQ{N!?i$RXF#t#cBt?^zW+ff|naGb-AlQ?(w-gvXw2ar$F+rRr` z-~RH?{jqa)k%@R8OS25i+E(8{?*Ix)#D@$s zpV94MJ(o+T;yM@Cx6)%J&G^-2eTnrLY28X5@7rSJd+d~*X2T;1Gsd)VnyqL@wUMp; zg4SUlOv3dIzE+SWmrBhat<%bK|t66i|Ibw^- zdE$Ad+veRI6&hbp>)FMEzQ~5h&xy6_T z942Fd|8^ZGqtfQ)=4G!7J?zFNE9a+)_}l#-*FQLh9{<0O=(%?%%At1J5J<-+|DRrkQ4XR$ekw3HP*}Ph}TfsjRJxvq8s z3^k6-M9Rvg^;HE|7MZ7_y?Z)`;#kdsmDKYr;mA^*9a(1kr?-(k3wl1DOf9jxg@VOK z%}g%OEDP=Db#~(gbpJvso3c}SI`uS5)GsV2Q8>EP4yV%W99n0Gg{PtdJ=K+7M7O$H zNX7E0#3HLj`1G#oNz?2t*r~L7X?F6YSO_jMd-kqVgVwziKk`ghHLL9 zUPz-mM+^BpdSDuj!8PFDy0RapnQbEotOk^M)=Z>~a;R|>aMdQW3APe3YSN~jxLC23 z*Ua+krkTxrIo(d4)$MqaS=7u5Jk*)lyYN9#&Us|3%dtF<_1UR2Vn@@KkGA`_2H78F zt7W6e7A6a>^-L(KOH&k_;d%@y}b1=1}=PmET zlh%ZuO{7^K*OraRF+XB=R8Oa4di<)TS}dDzfO~fG+~nEWvkMm|$7UvKE3=95$x{J-KQ#CkZ4tPRkMITjt7^!!BM%xMHLW zR+5$@s21H2SWyr{B-*(X7BxDm}D^IYa)OSWv|ZQWCBaeO7`Ztv{v?rNubhG2*@ zc*Il4V#(HX>;wl>!pvZ-R$#;hX_*4*ncmMx2cB7%aRA3rxX zdF~X&gpt5-d;w;&BH%axuuk-9qv;gt)MKR*tO^OtMOuupERSf;ozSofIT$IsMVm1- zCM1QbVb6UR=Fq<<_C;7DNz^t?TT!mYjph;~CHa94wsi|pS^GSs$WG8qYZEa{h(|We`Tx+ED zeA84DYgz+b*w=be_A3}eez~T$E)cBusL(`r`aR7+e-9KS3N8vV1%-l}0;S-gl9x(8 zD)}kYP^hC)fV%1_G*DL~Rd!JKPO3ChrG+Z3RM|z9-Bj62sYYQxg##20QfQ;lPT>%R z4ho$Vx+rv0I7}f#p@%{*g+2=X6b2{^QaD1Dqg1(%D)&?60jfMmm17i!sPYh%k5l|+d=ICwHMSr zPzOLA1ho^?E>I7Ex*yawP!EDSf);p;HcV5PQD<>{fx<-!bLu5fFT*ZSp8$0p)GMGa z0QJwSQDlkJMuRpkQbpza)nrzqqpSQKmu1qw?P7N~!j`d6v{Y3ja4;TZ~_ zpzuj`28CRuJ3fV)5`5v~Pm?27r1K+na#%x3GN|_g$v&Jsf@?+YgZShuGf0_71im zVf!(%`~+|EQ(S)+)EKDmp@g4ddmr1+vHgNe`z5ybK>an&f5+#4#P+v9rN0B}`g?5u zfbAb)7ozH4P~gAf>YqW?TwSE{hrh5uf^7o{Tw>>J3IOB zJZD+LMsXs$oC!!CB1w)AN#&ilEE8A7Kk(r`1xY>}coe_C7X0`JE|C13zovXdRpDAr z^_4sEC)EX1nLuZdkb2TUh>tXK#vQzC;@wU{TzjCIkQUMkMB0Vd+l{x|14P*i#JvxH zV`@M=`+*=FiT5B7UmFmAJCK?~cwh&Rx=tX0E+D~fAoYiVG=zXO_TU-4ctjtb&<~_} z07%Oqkk%tWb{z$>`#vCh?gz5>0U-Mx1ft<@-~B^C4z&1G4{3KlMDQ-hxw;Rdeq@+; zj{rGz0!RmuMhN&N*GVGzU9L7F9fUd=NGG)5MZ3^y9yM6(zcSK(2lSCEC)=L~{p2Zb zSxNQ20mc5}Bq>IE$t+p(-6|E0eflW&?fMw@nm&&GK|PFpn|=!WkUoKZmp+O8Ui~!o zhxA9W@6gX+->IL)zFR+s{b4_U+=C* zq;!>*>h}{eKX-bLAj^8uXox%x>yamj;9S=)<2N!-P_TTLU`0Y}_;6NA?kGm?;|y+v zs@`=pkai<3YiqtcD9pH03NJu?Cn3(nh^{vxbUP-BrSLwe@~rF8(BpAAfQSm!#^oxJ z5A;$b2E|fL-dGPmATM>tm0*e>UEX(Bm<8 zE5=eA3AFN4$}adJu(a6M|*kh~h;z9Lfgrs$ANx?b5tk(q0qdyqrZ9;xu>-2|n(~ z9nKyd*{VmZ%A5=g0$QJwpc5^f{btqWvLx!p$WI{}PSbzK}KcsGow5sfg| zc*VZ6QQGmJo10u*ty@vO4~WBiz`9-0tm>_biPzg8Vo1eONZ-)VHwyYj#_e@{`_Z!Q zYrfl#Nu0eKmAxfr??y;p*GgM^0}9@|gWn_==_JL_rCAbs;sTkKk`19)Xm}Ro-4a+o z0f&%12xSx^SQqVEB_!3m&`^yWgs6D1)V}6>V#DKG=()PG}ytH{1sP)Gk~-v z*{ymDT&p|t+0$9Fmc3PqdJMB@^hI(~DXJPz6^#Kg^cwl1F^I#cW!R|qx>0yFyab_@ zchE!}DeG;dZ8N+q;aVG653Ph(fY0u1gjQ}Ajh#1d#Ff(gYD_u33X!L|t~(XQTlWzL z=Ed&Y{S36VYZ-|_N5nj;giqevx9yb2zba1tWDR*XRtZ}c@FE7i+mO<)HU)stWhrV zJXR?mY34CjU+gcfhd&R{wpoh-c4(pl-Pgi#M$x5_qde2K$}W)(%EytIM@Wxq*Ks- zQ+i8!8D0V9i|Aq(c@oW-v|=-coP7CUG9RcG3WH~J1bcSk)!H3ZKF6e8^O>`k;t zF+oF&qAsu$6fDDdBGc!J~OGDxZ~XC>}~Sp+|7f+b|0v zus(wSf&Yb+KhsFVX61Zbj{{h6@>-yW+m-HWEzoEZ_eN5JW z#6ODuW7MEI<`%`q+58h|+#$-s2f&L)++AVlm~hM*`jtop+ZW*RM3TdlXwp`-x>VBB zm?!qTF;AQo73p@#_$e6gLg;#9r#Rv_5PA4 zIUwP4przO!y=eRlq9@<&<_Wb6XYWIFbL3|{7u*xzL_4P-84*k(zVEZMu53mLB zzd5o;{3Yv7@kbK=0C5%jaoFy1$x4pv`y$-t58+bsAq2}q1`mql@uG1&^iN>?3YNO- z@fSoFpZ{}tPPq=(jbFo3eMlgzyp$Z~Ir2{s`VdY^Tr9p%hQq(Xpip>F;5wdrNLFNJ zR8(~#qy8v=$=xaOqJqClR4gfb`Ou&~gzaHPx3&UGI;apFXG&*ARFhdYs@(^^W~+G1zg+TYs8 z1q|s{G@HoS2{Wy-xfU^V_T8&X3Xt$o!Q+nFAx({_7LP4=;uVH3W zn%$>mGRZ_#W8%6OJFU1Gy}F>y>zzhYv*IVaHyGI-J7FjFzW$gQ(bZs5UsR8%{Tur^ zx5L7iV;hS0ZMvq$c6UY1RCgw8#&S{A$v{zj^X4r~L?#zWCak!g?aQUFrp*QChz%;^ ziDq@pHn(z=Xly;HrRQ?moZdHlj<1#HTu05;`zG{^dgy3CJ=}As$5De(Pj-L8+C>UF zu#XJ+|0$j%gTmu4zkb;xqK94BMCs0E!v8+^&z9EXS3Rpl*6Gkgu3~- zbGr0-=23Z={rE;h!`ZBv<&&BTJ(|lV?4=EoD-?N9kJ_RZi@DC_QV~5{c}}+{Y|YMD zoT0*z8B181q_!mE%AD>lY44iIpg6rEX=<^HaU7xj?QL<*>W}FU9vofJk~tjK%r2D93MP{J zIW*fg3)Ml*I?F3v2z#%YE?>rt`$ug(#gCduJghT;qv@Ew7&6!?OiI69jiV_`A2d^$ ztZp&Im8D!Fl1;?s^h(5L*OC@D&90oCNGg}6MhEypRYuRUV3-;oJFD5zxG$@x%z2%i z)^Gb}6X}GV(2{s$%$w2dIOox=T0H8k8A}+&C}9q)wmx}0MXvL>sbbcOYgs+!xJz-I zlGbhC#3nMk8aq{vB3iOOc2Ty9k~M0kxj{XS97bZd9@EovcD!WekWsdB$f)1Yd-EA} zQ7swGB~jVITsDgU;kMkkvByj^^^-cnac+|W6*#$9Un;t=YBsm!nhjfR+grA+XZAsB zL`%n#de${-Ef}LiilwJx9GZ?5=C!QlL--DA$z()}UbT>qfwc1M=(*9eQ)g#KhDT42 zOjeYp7e|LCNA?yI&qmVepE%NexToii?no|?L`>Fg!F{g-^yaO^A?MdI%%F)0Ig!@0 zd$ux-rfof|MQwz>!?@%B5wdf01o!e=vUQG_tjzD_by%30EM;KH)}15}V@@uHn0J9G z>qvA*i&mD6WX_7yVxUxFkcJl0=d&h)*IshvGAy}CNR3Mw#ms2 zoGRG}6v;xTSK!t(2JaAp#GEVU9&5=$5V%W0Tu~aF*V1~jVk|V+KQ=ot85-|DJ?z7x zvQSC@b&0h0shmMms5dHmbTY21Q3q}+J6bgj)kYfTAvIyCwrQ$X3jL2GwP;uM3S+Q} z;?)d0ze_!jfnn)tBF!oR4j7L%uO*UNB&n+liI^Q%5p8N*Pt3(_ChqW|W0^&DQ9X3z zIR2VhHK}Fi^lX^6r-o#hHlwn9`K@tODW5Pr;MY$bjz05CUN@g zn9F9W*|N?8y|Rd;MMPg(OI8mT2ON%u7S-E~Tsq2>Z)?An)$Lq1jrUK-%!RI`>D;O- zp4E-J9+fcSlhxSFg-$IRMVE9MSu<5(ZBEqpl^m_|X)m{IIT@=lQ@7N#X{%g}>WE?H zEy7V{5^)bYvvj(`G7=X?GsuDWmFF=V#Uz$PJyDD{G$`I$)aUWa%({||w{?x{bHj@n zS4&%0M|%s+>IjCY4)?foX)M`VMnA>C6f;v8t0fpQ`D!YMdZt*Um7vvX75Tb6=aB=a zs6?*{9l)Bc`_QS_~;IcMzZFDg%NJz(OIRO zq9r?<(<`^8N)KD$)pwTFv@tYS(sOQj62q#0a%w_BV8>WmusrDB;x-Q>I{Cm?wA?sS zmK0{}B&#nXj^qg2reOSLxBymrSW(`-IsXS)7I8`{4USDsj0_J+35M6J`jXpB#(08v zr}YIska49RM*ja+{xAD$3zL_Qq+v;M<jnmrg$i|ay$mS zJg1NFbmQUUi!2FMeIoT&Y^f5}pQ#4Rmd1)KB=Oz z%3obmt0=JD)!=hC)`IKLKtZ4&QjjRf6kHT21veEuRPa*4N1=j36&3tctf5d##X2f) zqfk%f?Nn-@&`6~wD(|4Mlfo`4@1~MUVK0S!RNhaanL-Pd4^USdmD?$FQ28L00~9(b zbW!N0au214DIB42l)^D8-$CU&DIBM8f@qh%;OL?KJTqF__VQJAMNOMMH}w?uspQ+kcUBNQH`@EK(igx^?m`U_lww`#P%g@^VItk{ydFGn-so`OwZu(IsAPd+t;vt9hYCi_6=;`#P%}M zz6HuF0LlusR{`g*Vf!BLyG-HxID8%350LeT*xtnU3br3%`!TZo1aIY-eb~!j;wEEdl%b#*nWxa9c&Tm{S_|14a%>P^#jKGdu)FIDtrV~{3EtM zVf!=eK)`*BXZtgJNA~$D!H0h!g5YEP6~!aU z3Rg0!x7hJNp~|mF1lp>B)YkynS4)VO)B)ME4M=T05Oq6{rUoFMMj-Ac{Hoo9a3gzn z0;$*qq-HmeZF_)tRUpD%LiUmUKz23*scK=z9RSkM3Z$+LZPE^8M+YGXNdSne6NtYH zh};dNv4?RU0^&Oi1Y?2Fqd;~Y15$kl>U$@U?Z?rWCxGnkWsLj0ikq~!?m|t-N!HyB zq_vMJeGi^@im)pR{Y3By;s61kC^i#eKU7IT+F&1Ev>mPHR;u$oR|Z;cgEnxbzvW5L z`cE^<3X10y$oJ$&Nj_9frpU7QW+87J(FU>KsSRP@s10MkM+;(qNIQ*vt2ToDF>Mt4 zfOZD^JG6VTZ`Q`J@6^s>ze_uZ{WdLx{bB7q_6^#7*tcop*sIzE_FdW}_Q$oU^0-F3 zke}HXzIbLI#P{Zny@k*{aGHS(6pstFGNxeI*d!k z7+f+{JgaCR^+r@um%X=9m~o{LoQ0Y;LY#>aUadpuwvOZr!6Q)SS=GXU`=gS-o{&Ig zR4NnMKr4hIkS|1}wbfvqG~W@Gs}qFyG0qf+Z%qsPFP3KyhTHkBP?Y%lk?KbjM5L%I zaDT+rgt632{7vkX;tc#434S&b`~vIUt{s10Ul-n3Uw?mn9Y+xvZ%f&2o7mk;H&Qlk zG@>GhTaXk_GqXo<58Sx5T8+Zg5zew|gz=(l4rL8_6(()RW@(-cX)kbb9>$_@agFc- z61>cj+nhZbvXzfm#YG=;jizDD~t?VWpp-z$yT$&<*2QH8)AzmAZ1RADL z-c646yWs$`S3?nn2-Z3KW&uexA{wfWfe;n%D6}lQUk%PMkKkG@lg^_7r37n8%`QYj zBoNyyHXIKpj0Zzk!M~j^J{Y(fNCr|XQ^E!hg1wG8s5aj-L!FRHo}sWzxdz+VlCR{d zUz-q?=Auw~e&_o|V5 zJ~$77#W&GJ3@NM4qd+e)x>q_7SY%jtJ+s8vJB|AQp(T@H`2Dt)*+^r(y7}z+_ zgwxQnBD^L%3(tZ474BkmrR*ioqbo)7RdlgPUO=adWS5NA{_BRdm!}=$P8X5y*yKep zz6Liss`16t9{4t1K*$>{)w@vxXYuP0_zt{@#mP3CVT~-QTsn-!+#UD0t-Jm_-!C~G%H5Mv*NY+1MwF02<~|U zrho_5zu4(BAX(Ec9~l?I73hue+{!%#Kp`NrQBY--0Vbm`1@eI z4t3|adtEHaXg`4BP|)5e4MF>1X((!MmWGn{qtZ~;ehd!6UA%^sWd8)}8jJDqKCpU( zDY4AfI>HywYk^-lnQqG>ep0=JpGzzh6bu5Fmw7>%CO>5!sl=}!B6)qjx6v~ah(BX4 z^ZDLEpCR#GOn)MI58v)0QH70Sda0l#F^%nYVH!Kj3+AnY@pCZVhrso^HeMKi1A(_8 z@LS;YUtkzt4SWbw;zk0ejkbX9vrraq9i}U^nDs` zv3GhQehRUC%3v`Y@5>u~fxm$9Aqr%Z?I#_wRh<~R?4B5V9Emcsu7 z0)K-6fr-WE(_O*eW6a7dW^p}V785^-IvkK>NxsA%AY5L}8TRPBU10T(JzBB)?Pg1> zg;m@V`U40vA3@+Bz^5yLJgls)ggydbg)i?EzC4<-Pz*nOJWGNkx1s&GbgYAH|0??7 zkH9yEucL-}<76SU3?lNkp*clAK2`n%%%0w9*cIQ0^om;c?N|O^j`(dv{twhbp}zY( BXgdG^ -- 2.47.2