On TechRepublic: Five super-secret features in Windows 7
BNET Business Network:
BNET
TechRepublic
ZDNet

February 4th, 2008

Facebook image uploader: The flaws continue

Posted by Larry Dignan @ 2:18 am

Categories: Browsers, Exploit code, Responsible disclosure, Viruses and Worms, Vulnerability research

Tags: Facebook, Vulnerability, ActiveX, Flaw, ActiveX/COM/COM+/DCOM, Middleware, Security, Software Development, Software/Web Development, Enterprise Software

Security researcher Elazar Broad has found another vulnerability in Facebook’s Aurigma ImageUploader control.

And these vulnerabilities are stacking up. In an advisory on the Full Disclosure email list on Sunday, Broad wrote:

The control is vulnerable to a stack-based buffer overflow in the
ExtractExif and ExtractIptc properties. See the exploit code for
buffer offsets. Other properties may be vulnerable as well to a DoS
and/or code execution.

The controls, distributed by Aurigma Imaging Technology, include: FaceBook PhotoUploader 4.5.57.0, Aurigma ImageUploader4 4.6.17.0, Aurigma ImageUploader4 4.5.70.0, Aurigma ImageUploader4 4.5.126.0 and Aurigma ImageUploader5 5.0.10.0. On the bright side, FaceBook PhotoUploader 4.5.57.1 is not vulnerable so upgrade pronto.

Broad noted that the latest flaw is a different one than the photo uploader issues he flagged last week affecting Facebook and MySpace. Last week, Broad flagged ActiveX photo uploader tools distributed by Aurigma Imaging Technology. Those attacks could allow rigged Web pages to hit Windows systems

There are two fixes here. You can disable the uploader tools involved in the aforementioned flaws or disable ActiveX components. Here’s a Microsoft walkthrough. Given how these vulnerabilities are springing up at a rapid clip you may just want to disable ActiveX.

Larry DignanLarry Dignan is Editor in Chief of ZDNet and Editorial Director of ZDNet sister site TechRepublic. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 3 Talkback(s)
Applauds croberts
facebook is ok if used properly! I have a "friend who uses every add-on and sends me roses, beer, wants to know what colour condom I am, etc etc.

time to get a life, buddy!!!... (Read the rest)
Posted by: tony_rly@... Posted on: 02/04/08 You are currently: a Guest | | Terms of Use
Or maybe just drop facebook  croberts | 02/04/08
Applauds croberts  tony_rly@... | 02/04/08
RE: Facebook image uploader: The flaws continue  johndavid_77@... | 02/04/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here