ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

Facebook image uploader: The flaws continue

By | February 4, 2008, 2:18am PST

Security researcher Elazar Broad has found another vulnerability in Facebook’s Aurigma ImageUploader control.

And these vulnerabilities are stacking up. In an advisory on the Full Disclosure email list on Sunday, Broad wrote:

The control is vulnerable to a stack-based buffer overflow in the
ExtractExif and ExtractIptc properties. See the exploit code for
buffer offsets. Other properties may be vulnerable as well to a DoS
and/or code execution.

The controls, distributed by Aurigma Imaging Technology, include: FaceBook PhotoUploader 4.5.57.0, Aurigma ImageUploader4 4.6.17.0, Aurigma ImageUploader4 4.5.70.0, Aurigma ImageUploader4 4.5.126.0 and Aurigma ImageUploader5 5.0.10.0. On the bright side, FaceBook PhotoUploader 4.5.57.1 is not vulnerable so upgrade pronto.

Broad noted that the latest flaw is a different one than the photo uploader issues he flagged last week affecting Facebook and MySpace. Last week, Broad flagged ActiveX photo uploader tools distributed by Aurigma Imaging Technology. Those attacks could allow rigged Web pages to hit Windows systems

There are two fixes here. You can disable the uploader tools involved in the aforementioned flaws or disable ActiveX components. Here’s a Microsoft walkthrough. Given how these vulnerabilities are springing up at a rapid clip you may just want to disable ActiveX.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

5
Comments

Join the conversation!

Just In

RE: Facebook image uploader: The flaws continue
lovedong 12th Sep
hmmmm,nice post i like you post chanel bags
0 Votes
+ -
Or maybe just drop facebook
croberts 4th Feb 2008
.. and spend your time doing something useful instead of pimping your life to everyone who doesn't have the heart to say they couldn't care less about the mundane details of your life.
0 Votes
+ -
Applauds croberts
tony_rly@... 4th Feb 2008
facebook is ok if used properly! I have a "friend who uses every add-on and sends me roses, beer, wants to know what colour condom I am, etc etc.

time to get a life, buddy!!!
hmmmm,nice post i like you post chanel bags
0 Votes
+ -
RE: Facebook image uploader: The flaws continue
johndavid_77@... 4th Feb 2008
Great article!

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix