Clickjacking attack in Adobe AIR and Adobe Flash Player - CVE-2009-1867

 

Clickjacking attack in Adobe AIR and Adobe Flash Player - CVE-2009-1867

Published: December 20, 2016 / Updated: March 16, 2017


Vulnerability identifier: #VU1427
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2009-1867
CWE-ID: CWE-59
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to hijack the clicking action of the victim.

The vulnerability exists in IBM Security Identity Manager Virtual Appliance. A remote attacker can hijack the target user's mouse clicks and take actions on the site acting as the target user by tricking the victim into visiting a malicious web site.

Successful exploitation of this vulnerability may result in disclosure of user information.

Affected software

Adobe AIR
Adobe Flash Player
Gentoo Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Desktop

How to mitigate CVE-2009-1867

Update Adobe Flash Player 9.x and earlier to version 9.0.246.0:
http://www.adobe.com/support/flashplayer/downloads.html#fp9
Update Adobe Flash Player 10.x to version 10.0.32.18:
http://www.adobe.com/go/getflashplayer
Update Adobe Air to version 1.5.2.
http://get.adobe.com/air/


External References

Related Security Bulletins