Top Stories
|
Image uploader bug blights MySpace1 Feb 2008 13:02 Nasty ActiveExploitSecurity flaws in an ActiveX control used in MySpace upload images onto the social networking sites leave users open to attack. Facebook users may also be at risk. A buffer overflow vulnerability in Aurigma's Image Uploader Control Library might be used to compromise a user's system. The affected control is used for uploading images onto social networking sites using Microsoft's Internet Explorer. Users might be vulnerable if tricked into visiting a specially crafted web page that exploits the vulnerability. The flaw was first reported by Elazar Broad on a full disclosure mailing list, who said that the vulnerable control was used by MySpace. Facebook also reportedly repackages the Aurigma control, though which version it uses is unclear. Broad reported the problem to Aurigma. Aurigma, a Washington-based software developer, acknowledged that version 4.5.70 of its control was vulnerable but said that later versions of its software were safe from attack. It didn't comment on the use of its software on social networking sites. Security notification firm Secunia advises MySpace users to set the "kill-bit" for the affected ActiveX control, which is known as MySpaceUploader.ocx version 1.0.0.4. Advise from Microsoft on how to disable vulnerable ActiveX controls can be found here. ® 6 comments posted — Comment period finished ActiveX, Cancer at the heart of IE?Posted: 14:31 1st February 2008 Serves them right...Posted: 14:41 1st February 2008 ActiveX: Insecure from the beginningPosted: 20:16 1st February 2008 Someone beat me to itPosted: 15:02 2nd February 2008 Secunia "extended solution"Posted: 03:31 4th February 2008
Track this type of story as a custom Atom/RSS feed or by email. Related storiesMySpace wins lawsuit against Spamford Wallace (29 April 2008)
|
Breaking Hardware News
San Francisco City Council regained access to its own computer network today after Mayor Gavin Newsom convinced network administrator Terry Childs to give them the passwords.
Newsletter |