Risk
2/20/2010
07:14 PM
George V. Hulme
George V. Hulme
Commentary
50%
50%

Adobe, Mozilla Users At Risk To Remote Code Execution Flaws

Software maker Adobe Systems has certainly had its share of vulnerabilities recently. This week a security researcher added to the company's pain when he announced a vulnerability in Adobe Download Manager that allows remote attacks. Mozilla Firefox users are also at-risk to attacks against an unpatched flaw in that browser.

Software maker Adobe Systems has certainly had its share of vulnerabilities recently. This week a security researcher added to the company's pain when he announced a vulnerability in Adobe Download Manager that allows remote attacks. Mozilla Firefox users are also at-risk to attacks against an unpatched flaw in that browser.Israeli security researcher Aviv Raff says he discovered a flaw in Adobe's web site that enables malicious attackers to abuse Adobe Download Manager to force the automatic download of Adobe applications. Theoretically, the attackers could force the installation of a vulnerable Adobe product on a target's system, and then use that application to exploit the end user. Considering the wave of Adobe software vulnerabilities in Adobe Reader and Adobe Flash recently, such a scenario is well within reason.

As Raff explains it on his blog, an attacker merely needs to entice a user to click on a link to initiatate the download, or embed the link within an iFrame on a website.

David Lenoe of the Adobe Product Security Incident Response Team says the company is working with Raff and the vendor Adobe's third part vendor for the component of their software to resolve the issue.

Meanwhile, users of Mozilla Firefox are vulnerable to remote code exploitation, where an attacker can inject code of their choice onto a victim's system.

No other details have been released on this particular flaw, but security firm Secunia has ranked the vulnerability as "highly critical."

No fix or workaround information is currently available, other than the advice to avoid untrusted links and web sites.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-1421
Published: 2014-11-25
mountall 1.54, as used in Ubuntu 14.10, does not properly handle the umask when using the mount utility, which allows local users to bypass intended access restrictions via unspecified vectors.

CVE-2014-3605
Published: 2014-11-25
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-6407. Reason: This candidate is a reservation duplicate of CVE-2014-6407. Notes: All CVE users should reference CVE-2014-6407 instead of this candidate. All references and descriptions in this candidate have been removed to pre...

CVE-2014-7839
Published: 2014-11-25
DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which allows remote attackers to conduct XML external entity (XXE) attacks via unspecified vectors.

CVE-2014-8001
Published: 2014-11-25
Buffer overflow in decode.cpp in Cisco OpenH264 1.2.0 and earlier allows remote attackers to execute arbitrary code via an encoded media file.

CVE-2014-8002
Published: 2014-11-25
Use-after-free vulnerability in decode_slice.cpp in Cisco OpenH264 1.2.0 and earlier allows remote attackers to execute arbitrary code via an encoded media file.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?