PT-2018-2997 · Adobe+3 · Flash+3

David Parks

·

Publicado

2018-05-09

·

Atualizado

2024-12-12

·

CVE-2018-5165

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 60
Description The issue concerns the Adobe Flash plugin setting for "Enable Adobe Flash protected mode" in Firefox, which is displayed as unchecked by default, even though the Adobe Flash sandbox is enabled. This discrepancy can lead to user confusion, potentially causing users to inadvertently turn off protections. The vulnerability is related to errors in privilege management and can be exploited by a remote attacker to bypass existing security restrictions.
Recommendations For versions prior to 60, update to version 60 or later to resolve the issue. As a temporary workaround, consider manually verifying the Adobe Flash protected mode setting to ensure it aligns with the intended security configuration. Restrict access to the Adobe Flash plugin until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-1787
ALT-PU-2018-1854
BDU:2019-03316
CVE-2018-5165
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
SUSE-SU-2019:2872-1

Produtos afetados

Alt Linux
Flash
Firefox
Suse