본문 바로가기

취약점 정보2

Security updates available for Adobe Connect

728x90
Security updates available for Adobe Connect | APSB17-22
Bulletin IDDate PublishedPriority
APSB17-22July 11, 20173

Summary

Adobe has released a security update for Adobe Connect for Windows. This update resolves two input validation vulnerabilities (CVE-2017-3102, CVE-2017-3103) that could be used in reflected and stored cross-site scripting attacks, respectively.  This update also includes a mitigation to protect users from UI redressing (or clickjacking) attacks (CVE-2017-3101). 

Affected product versions

ProductVersionPlatform
Adobe Connect9.6.1 and earlierWindows

Solution

Adobe categorizes these updates with the following priority ratings and recommends users update their installation to the newest version:

ProductVersionPlatformPriorityAvailability
Adobe Connect9.6.2Windows3Release note

Vulnerability details

Vulnerability CategoryVulnerability ImpactSeverityCVE Number
User Interface (UI) Misrepresentation of Critical InformationClickjacking attacksModerateCVE-2017-3101
Improper Neutralization of Input During Web Page Generation
Cross-site scripting attacksImportantCVE-2017-3102
Improper Neutralization of Input During Web Page Generation
Cross-site scripting attacksImportant
CVE-2017-3103

Acknowledgments

Adobe would like to thank the following individuals for reporting these issues and for working with Adobe to help protect our customers:

  • Anas Roubi (CVE-2017-3101)
  • Adam Willard of Raytheon Foreground Security (CVE-2017-3102)
  • Alexis Laborier (CVE-2017-3103)
728x90