eWeek Security Watch
Advertisement
Advertisement
January 31, 2008 7:36 PM

'Critical' Flaw in MySpace, Facebook Image Uploader



'Critical' Flaw in MySpace, Facebook Image Uploader Security researchers have raised an alert for serious security problems with the MySpace and Facebook image upload feature.

According to a warning from Symantec's DeepSight threat analyst team, the issue centers around a buffer overflow in the 'Action' property of multiple ActiveX controls that's used in the image upload process for the two popular social networks.

The ActiveX controls are designed and distributed by Aurigma Imaging Technology.

The vulnerability, publicly disclosed by hacker Elazar Broad on the Full Disclosure mailing list, could allow attackers to use booby-trapped Web pages to compromise Windows machines.

Exploit code that provides a roadmap to launch remote code-execution attacks has been published at Milw0rm.com.

Symantec DeepSight researcher Patrick Jungles said his team has confirmed the reliability of the exploit.

"We also expect to see exploits for the Facebook issue in the next few days, given the popularity of the social-networking community," Jungles added.

"Since exploits are starting to come out for these issues, users are advised to use caution when browsing the Web," he added.

In the absence of a fix, Windows/Internet explorer users should immediately disable these CLSIDs:

* MySpace: {48DD0448-9209-4F81-9F6D-D83562940134}

* Facebook: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0}

* Aurigma: {6E5E167B-1566-4316-B27F-0DDAB3484CF7}

See this Microsoft document for instructions on disabling ActiveX components.

TrackBack

TrackBack

http://securitywatch.eweek.com/cgi-bin/mte/mt-tb.cgi/12610

Post a Comment

 
 


RSS Syndication
Advertisement
Advertisement
Security Watch     Contact Us | Advertise | Site Map
Ziff Davis Enterprise

Ziff Davis Enterprise Home | Contact Us | Advertise | Link to Us | Reprints | Magazine Subscriptions | Newsletters
RSS Feeds | White Papers | ROI Calculators | Tech Podcasts | Tech Video |

Baseline | Careers | Channel Insider | CIO Insight | DesktopLinux | DeviceForge | DevSource | eSeminars |
eWEEK | LinuxDevices | Linux Watch | Microsoft Watch | Mid-market | Networking | PDF Zone |
Publish | eWeek Security | Strategic Partner | Web Buyer's Guide | Windows for Devices

Developer Shed | Dev Shed | ASP Free | Dev Articles | Dev Hardware | SEO Chat | Tutorialized | Scripts |
Code Walkers | Web Hosters | Dev Mechanic | Dev Archives | IT Marketplace | igrep

Use of this site is governed by our Terms of Use and Privacy Policy

Copyright ©1996-2007 Ziff Davis Enterprise, Inc. All Rights Reserved. Security Watch is a trademark of Ziff Davis Enterprise, Inc. Reproduction in whole or in part in any form or medium without express written permission of Ziff Davis Enterprise Inc. is prohibited.

Ziff Davis Enterprise