Archive for September 18th, 2008

Adobe Illustrator Malformed AI File Remote Code Execution Vulnerability

The internet is so much a part of life and business these days that desktop applications are still a target. It is easy for a malicious user to exploit a desktop application via social engineering, man in the middle attacks, phishing and other means. In my opinion graphic designers are a good target for those with ill intent to target. Think about it, while most of their work relies on using a computer, they may not have the technical skills to understand the dangers of opening strange files, or visiting URL’s. Graphic designers often also work on new products for companies, therefor have inside information on a product as they are designing identities and media. Here is an vulnerability targeting the popular Adobe Illustrator. What irritates me about such products is the end user must rely on the Vendor for a patch. In this case CS2 has been replaced with CS3. Adobe products also have a tendency to be expensive, so it is unlikely that every graphic designer will update.

http://www.securityfocus.com/bid/31208/info
Adobe Illustrator is prone to a remote code-execution vulnerability. An attacker can exploit this issue by enticing an unsuspecting victim to open a malicious AI file. Successfully exploiting this issue will allow attackers to execute arbitrary code with the privileges of the user running the affected application. This issue affects only Adobe Illustrator CS2 for Macintosh.

Add comment September 18th, 2008

Three days, five different Drupal vulnerabilities

In the world of security a lot can happen in three days. Lets take the popular web content management system Drupal. Over the past three days both Secunia and Security Focus have published a total of five Drupal vulnerabilities. Although These advisories have all been patched in the latest release of Drupal, many companies and organizations on the web rely on Drupal to handle their day to day business, but how many of them keep their installation up to date? Cross Site Scripting or HTML Injection, SQL Injection and security bypasses are just the attack vectors targeted in these five Drupal vulnerabilities.

Drupal XSS / HTML Injection
http://www.securityfocus.com/bid/31146
http://www.securityfocus.com/bid/31224

Drupal Script Insertiaion
http://secunia.com/Advisories/31889/

Drupal SQL Injection
http://secunia.com/Advisories/31877/

Drupal Talk Module Script Insertion and Security Bypass

http://secunia.com/Advisories/31908/

Add comment September 18th, 2008


Calendar

September 2008
M T W T F S S
« Jan   Oct »
1234567
891011121314
15161718192021
22232425262728
2930  

Posts by Month

Posts by Category