Adobe flash work around for clickjacking

Started by R-C, October 09, 2008, 01:39:38 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

R-C

http://www.adobe.com/support/security/advisories/apsa08-08.html
Flash Player workaround available for "Clickjacking" issue

Release date: October 7, 2008

Vulnerability identifier: APSA08-08

Platform: All Platforms

Affected Software: Adobe Flash Player 9.0.124.0 and earlier

this is their work around till they issue a new updated version.
registered Linux user:476595
May inspiration fill your heart and hands, run down your legs onto your feet and cause Spontaneous Dancing! :dance:

R-C

if that is in the wrong place go ahead and move it I just thought it would be good to have it on this site too in case anyone missed seeing it on Corrine's blog.
registered Linux user:476595
May inspiration fill your heart and hands, run down your legs onto your feet and cause Spontaneous Dancing! :dance:

Corrine

Anyone who uses CCleaner needs to adjust their settings if they have have this setting checked: CCleaner > Applications > Multimedia > Adobe Flash Player

During the "Analyze" stage, you can see the settings.sol being listed for removal, which would remove the workaround provided by Adobe:

C:\Documents and Settings\%User%\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol

http://forum.piriform.com/index.php?showtopic=18200


Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

MikeW

Thanks for the 'heads up' Corrine. I had not noticed that happening. Corrected now
Win 11 Home MS Edge - WD - Mbam Pro

Temmu

scary.  a cleaner that removes a fix.  not good.  thx for the heads up, corrine!   :rose:

Corrine

http://www.adobe.com/support/security/bulletins/apsb08-18.html

Flash Player update available to address security vulnerabilities
Release date: October 15, 2008
Vulnerability identifier: APSB08-18
CVE number: CVE-2007-6243, CVE-2008-3873, CVE-2007-4324, CVE-2008-4401, CVE-2008-4503
Platform: All Platforms

This update addresses a potential 'Clickjacking' issue in Flash Player. Clickjacking is an issue in multiple web browsers that could allow an attacker to lure a web browser user into unknowingly clicking on a link or dialog. This update helps prevent a Clickjacking attack on a Flash Player user's camera and microphone. (CVE-2008-4503)

This update includes further changes to enhance Flash Player's interpretation of cross-domain policy files. These changes could help prevent privilege escalation attacks against web servers hosting Flash content and cross-domain policy files. For more information, see the following section of the "Adobe Flash Player 10 Security Changes" Adobe Developer Connection article. (CVE-2007-6243)

This update introduces functionality to further mitigate a potential port-scanning issue. For more information, see the following Adobe Developer Connection article. (CVE-2007-4324)

This update introduces changes to the Clipboard API that will prevent potential 'Clipboard attacks'. For more information, see the following section of the "Adobe Flash Player 10 Security Changes" Adobe Developer Center article. (CVE-2008-3873)

This update introduces changes to the FileReference upload and download APIs to require user interaction. For more information, see the following section of the "Adobe Flash Player 10 Security Changes" Adobe Developer Connection article. (CVE-2008-4401)

Get the Update:  http://www.adobe.com/go/getflashplayer/



Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

R-C

registered Linux user:476595
May inspiration fill your heart and hands, run down your legs onto your feet and cause Spontaneous Dancing! :dance:

Corrine

Using Firefox with NoScript does though -- as long as you leave the default settings intact except for trusted sites. 

{OT:  I really, really, really dislike the term "malvertisement"}


Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

R-C

I sorry it was the actual title of the article not my creation. It took me a while when I first started seeing the term to figure out what they were talking about.
registered Linux user:476595
May inspiration fill your heart and hands, run down your legs onto your feet and cause Spontaneous Dancing! :dance:

Corrine

No need to be sorry, R-C.  I know you didn't coin the term. 


Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.