Red Hat Bugzilla – Bug 466154
CVE-2008-4401 flash-plugin: upload/download user interaction
Last modified: 2008-12-19 14:32:55 EST
Previosuly ActionScript could initiate uploads and downloads without user interaction. Flash Player 10 beta changes this behavior. FileReference.browse and FileReference.download calls now can only be initiated via user interaction, such as click the mouse or pressing keys on the keyboard. For more information please see: http://www.adobe.com/devnet/flashplayer/articles/fplayer10_security_changes.html#head3
Public now via: http://www.adobe.com/support/security/bulletins/apsb08-18.html
This issue was addressed in: Red Hat Enterprise Linux Extras: http://rhn.redhat.com/errata/RHSA-2008-0945.html http://rhn.redhat.com/errata/RHSA-2008-0980.html