• On TV.com: Why Is Everyone in TV High School SO OLD
February 4, 2008 10:51 AM PST

Facebook, MySpace image uploaders vulnerable to attack

by Robert Vamosi
  • Font size
  • Print
  • 2 comments

Updated at 3:37 p.m. PST with statement from MySpace and Facebook.

Within the last week, researcher Elazar Broad has disclosed two ActiveX vulnerabilities in the tools that MySpace.com and Facebook users use to upload images to their sites. On Sunday, Broad disclosed a buffer overflow vulnerability within the Facebook image upload control. Last week, Broad disclosed a similar buffer overflow flaw within MySpaceAurigma's ImageUploader ActiveX; the MySpace vulnerability also affects Facebook users.

Facebook and MySpace use controls repackaged from Aurigma Imaging Technology. Vulnerable to the recent attack scenario are FaceBook PhotoUploader 4.5.57.0, Aurigma ImageUploader4 4.6.17.0, Aurigma ImageUploader4 4.5.70.0, Aurigma ImageUploader4 4.5.126.0, and Aurigma ImageUploader5 5.0.10.0.

The MySpace attack outlined last week could allow specially crafted Web pages to crash Windows systems. The Facebook attack announced Sunday could allow for denial-of-service attacks or for malicious code to run on compromised PCs. An exploit exists for the MySpace attack. An exploit for the Facebook attack is expected to be posted on the Internet shortly.

Recent versions of Facebook PhotoUploader 4.5.57.1 are not vulnerable. Also, for the MySpace vulnerability, Aurigma Imaging Technology recommends upgrading to the latest 4.x and 5.x releases.

Additional workarounds include disabling all ActiveX within Internet Explorer. Microsoft provides detailed instructions here. You can also disable just the image uploader within either Facebook or MySpace.

On Monday afternoon, MySpace and Facebook issued a joint statement: "MySpace and Facebook are firmly committed to keeping all users as safe and secure as possible. Recently, the companies were alerted to a vulnerability in Aurigma Imaging Technology's software that could potentially put certain users with Windows-based systems at risk. Immediately after identifying a solution, Facebook, MySpace, and Aurigma collaborated to resolve the issue and are working to individually alert users of any additional steps that need to be taken to ensure user security."

As CNET's resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security. Listen to his podcast at securitybites.cnet.com or e-mail Robert with your questions and comments.
advertisement
Click here!
Recent posts from Defense in Depth
Window Snyder to leave Mozilla
How to handle ID fraud's youngest victims
Is white listing going mainstream?
How Live OneCare changed the antivirus landscape
Express Scripts clients threatened with extortion
Study: DDoS attacks threaten ISP infrastructure
Security expert talks Russian gangs, botnets
Extortion used in Express Scripts database breach
Add a Comment (Log in or register)
what about using firefox?
by krosavcheg February 4, 2008 11:27 AM PST
So many problems with IE. Who can keep track unless it's their job?
Reply to this comment
by UploadEase May 24, 2009 2:20 PM PDT
This continues to be a problem, and having to support ActiveX for one browser and Java for the rest must be a real nuisance.

I've heard the latest Java offering from Aurigma (at least the one Facebook uses) freezes Firefox or Vista if you don't have Java 1.6.0_07 or newer installed - will the problems never end?

There are much better uploaders out there - you only have to look!
Reply to this comment
advertisement

A CNET Conversation with Eric Schmidt

CNET's Tom Krazit and Molly Wood sit down with Google CEO Eric Schmidt to discuss the future of Android, the Chrome OS, the problem of real-time search indexing, and more.

Verizon tests sending RIAA copyright notices

The No. 2 phone company, known for its reluctance to intervene in antipiracy cases, strikes an agreement to forward copyright notices on behalf of the music industry.

About Defense in Depth

Covering computer viruses and computer crime, Robert Vamosi goes beyond the hype to provide you with expert interviews of the top security researchers, as well as offering the hands-on, nontechnical advice you'll need to stay safe online.

Add this feed to your online news reader

Defense in Depth topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right