Friday March 12, 2010 4:07 AM AEST
 
Latest Comments
"Sounds funny. Did they ever tell the customers in plainly-worded language that the co-lo space ..."
by Dave - The Network Mule | Mar 11, 2010 10:28 AM
 
"Sunglasses of wto-store.com www.wto-store.com Versace Sunglasses http://wto-store.com/catego..."
by Luxury Handbags 100% Authentic, 2010 Lastest Styles, Buy Now! | Mar 10, 2010 8:59 PM
 
"First Post Hooray"
by Random Stranger | Mar 10, 2010 12:38 PM
 
"virus"
by new | Mar 10, 2010 8:27 AM
 
"I just received one of those emails. As I have sent a UPS parcel, I thought for sure that it was ..."
by Frank | Mar 10, 2010 3:14 AM

Source of Adobe zero-day bug patched

  • Email a Friend
  • Print Page
By Chuck Miller
Jul 7, 2009 10:42 AM
Tags: Adobe | ColdFusion | vulnerability | zero-day | bug | flaw | patched
One of the flaws at the heart of Adobe's ColdFusion 8.0.1 zero-day vulnerability has been patched.

Recent attacks were due, in part, to a vulnerable text-editor bundled with web design and development platform ColdFusion, according to Adobe. It had been shipped with an open source text editor called FCKeditor, versions of which contained a security hole.

“Adobe is aware of reports of ColdFusion websites being compromised through a vulnerability in the FCKeditor rich text editor,” David Lenoe, Adobe product security program manager, wrote in a post on the company's Product Security Incident Response Team (PSIRT) blog.

He said Adobe is working on a fix, which is expected to be made available this week. He also outlined a workaround in the post.

In the meantime, a new version of FCKeditor has been released to address the vulnerability. In an advisory, US-CERT said that it “encourages users and administrators to upgrade to FCKeditor version 2.6.4.1 to help mitigate the risks.”

The FCKeditor vulnerability was “due to improper verification of input passed to the ‘CurrentFolder' parameter," US-CERT said in its advisory. "Exploitation of this vulnerability may allow an attacker to execute arbitrary code.”

ColdFusion also suffered from a second attack vector through vulnerable FCKeditor installations.

“One of the common applications that has been seen in attacks is CFWebstore, a popular e-commerce application for ColdFusion,” wrote Bojan Zdrnja, senior information security consultant at Infigo IS, in an updated post on the SANS Internet Storm Center. "Older versions of CFWebstore used a vulnerable FCKeditor installation. If you are using CFWebstore, make sure that you are running the latest version and that any leftovers have been removed.”

See original article on scmagazineus.com

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
 
Patch Management Whitepapers