RETIRED: Adobe Flash Player Unspecified Clickjacking Vulnerability
BID:31625
Info
RETIRED: Adobe Flash Player Unspecified Clickjacking Vulnerability
| Bugtraq ID: | 31625 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2008-4503 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 07 2008 12:00AM |
| Updated: | May 12 2015 07:48PM |
| Credit: | Robert Hansen of SecTheory, Jeremiah Grossman of WhiteHat Security, Eduardo Vela, Matthew Matracci, and Liu Die Yu |
| Vulnerable: |
Adobe Flash Player 9.0.124 .0 Adobe Flash Player 9.0.48.0 Adobe Flash Player 9.0.47.0 Adobe Flash Player 9.0.45.0 Adobe Flash Player 9.0.31.0 Adobe Flash Player 9.0.28.0 Adobe Flash Player 9.0.115.0 Adobe Flash Player 9 |
| Not Vulnerable: | |
Discussion
RETIRED: Adobe Flash Player Unspecified Clickjacking Vulnerability
Adobe Flash Player is prone to a vulnerability that may allow an attacker to trick a victim into unknowingly clicking on a link or dialog.
An attacker may exploit this issue by creating a malicious web page embedding a flash control used to modify privacy settings. It's possible to have an unsuspecting user click on this control and modify their settings without further notification or prompting.
NOTE: This BID is being retired because the issue described affects a specific flash control hosted by Adobe; it is not a specific fault in Flash Player itself.
Adobe Flash Player is prone to a vulnerability that may allow an attacker to trick a victim into unknowingly clicking on a link or dialog.
An attacker may exploit this issue by creating a malicious web page embedding a flash control used to modify privacy settings. It's possible to have an unsuspecting user click on this control and modify their settings without further notification or prompting.
NOTE: This BID is being retired because the issue described affects a specific flash control hosted by Adobe; it is not a specific fault in Flash Player itself.
Exploit / POC
RETIRED: Adobe Flash Player Unspecified Clickjacking Vulnerability
An example exploit is available; please see the references for more information.
An example exploit is available; please see the references for more information.
Solution / Fix
RETIRED: Adobe Flash Player Unspecified Clickjacking Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
RETIRED: Adobe Flash Player Unspecified Clickjacking Vulnerability
References:
References:
- Adobe Flash Homepage (Adobe)
- Clickjacking (Robert Hansen and Jeremiah Grossman)
- Malicious camera spying using ClickJacking (GUYA.NET )
- APSA08-08 Flash Player workaround available for 'Clickjacking' issue (Adobe)