Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Security Fixes and Improvements

October 21st, 2011, 08:57 GMT · By Eduard Kovacs

Adobe Fixes Webcam and Microphone Spying Issue

SHARE:

Adjust text size:


Feross Aboukhadijeh, the student who discovered the issue
Enlarge picture
Adobe released the much expected update that would fix the problem pointed out by a Stanford University student, which revealed to the world that any website administrator can easily spy on his customers using a bug in the Flash Settings Manager.

According to V3, Adobe blamed the communication error between them and Feross Aboukhadijeh, the one who discovered the issue, on the fact that the student sent his findings to an employee that was off duty at the time.

They mention that the information was supposed to be sent to their incident response team instead.

"The email with the report was sent to an Adobe employee who has been on sabbatical. The issue was not reported to the Adobe Product Security Incident Response Team (PSIRT), which is the contact for all vulnerability reports," revealed a company spokesman for V3.

Because the actual update process was required on their servers, users don't have to apply any patches or updates manually.

The story broke out when Feross Aboukhadijeh found that an older issue which allowed any webmaster to spy on his sites visitors was only partially fixed.

The initial problem allowed someone to take over our webcams and microphones by placing the Adobe Flash Setting Manager inside an iframe, that when clicked, could enable the devices.

By adding only the settings SWF file to an iframe, he was able to bypass the framebusting JavaScript code that was supposed to patch up the hole.

Fortunately, the correction was made fairly fast, before too many potentially criminal masterminds could deploy the findings.

It's highly unfortunate that these situations keep showing up, but at least vendors are acting quickly to solve the problems. Recently, Opera encountered the same scenario, where a year-old bug was endangering their customers well-being, by allowing a remote attacker to execute arbitrary code.

TELL US WHAT YOU THINK:

1,511 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Flash Vulnerability Allows Website Admins to Spy on Visitors

Browser Vendors Prepare for SSL Attacks

Opera SVG Vulnerability Fixed and Explained

Zero-Day Vulnerability Found in Opera 11.51

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM