Tuesday December 2, 2008 4:01 AM AEST
Latest Comments
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM
 
"That will enhance Microsoft Office system, including SharePoint - good platform for enterprise ..."
by SGE | Nov 25, 2008 3:29 PM
 
"how many users allow per session? because the digital persona password manager allows only 10 ..."
by Daniel | Nov 25, 2008 12:14 AM
 
"security through obscurity...shows how detached HIPAA is from reality."
by priceOfFishInChina | Nov 20, 2008 1:19 PM
 
"I have been the recipient of Agent.JEN.Trojan through an email suggesting a UPS parcel (including..."
by Vincent Laing | Nov 13, 2008 4:01 PM

LinkedIn fixes critical bug

  • Email a Friend
  • Print Page
LinkedIn fixes critical bug
By Dan Kaplan
Jul 27, 2007 10:07 AM
Tags: LinkedIn | fixes | critical | bug
The mandatory fix "was pushed out to all of our users" on Wednesday, Mario Sundar, community evangelist at LinkedIn, told SCMagazine.com. "The fix is required for users; otherwise the toolbar shuts down."

There were no reports of active exploits, he said.

The client-side ActiveX flaw, which garnered Secunia's highest severity rating of "extremely critical," could have allowed an attacker to remotely execute arbitrary code. Users can be exploited when they visit a malicious website. The bug is caused by an error in the toolbar when handling the "Search () method."

One of the discovering researchers, Jared DeMott of Michigan-based VDA Labs, said he and his partner, Justin Seitz, decided to drop the vulnerability "0-day style' after officials at LinkedIn would not pay VDA for consulting fees or to purchase the flaw outright.

"We ultimately really want to protect the end-users," DeMott said in an email to SCMagazine.com on Wednesday. "And if a company won't spend money on security testing, they're not thinking about their end-users...Vendors should be responsible to consider the security of their users."

A spokeswoman for LinkedIn, which has more than 12 million members, said company policy is to not respond to such requests.

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Patch Management Whitepapers