Welcome
Arachne's Web
A group focused on serving the AW community by providing help and discussion on topics such as HTML, CSS, web design, homesite decorating, netiquette and issues important to web artists.

Systems & Security (- threads, 995 posts)
    Virus Alerts (583 posts)
    Social Thread

    For the posting of the latest virii, worms, trojans out there in the wild. Discussions should take place in Q&A. I am doing cell phone and Apple Computer alerts as well.
    ...
    23 Members have made 533 Posts here to date.
    Google
    AncientWorlds.net Web
    Next: Google pulls malicious sponsored links
    Prev: Web threats to surpass e-mail pests
    Exploit code released for Adobe Photoshop flaw
    scarabsmall.gif
    Author: * Toman Thutmose - 474 Posts on this thread out of 1,403 Posts sitewide.
    Date: Apr 28, 2007 - 21:22

    Exploit code that could take advantage of a "highly critical" security flaw in the most recent versions of Adobe Photoshop has been published, a security researcher reported.

    The security flaw affects Adobe Photoshop Creative Suite 3, as well as CS2, according to a security advisory issued by Secunia on Wednesday.

    The vulnerability concerns the way Adobe Photoshop handles the processing of malicious bitmap files, such as .bmp, .dib and .rle. A malicious attacker could exploit the flaw to launch a buffer overflow attack. That buffer overflow would then allow the intruder to take over a user's system.

    Although a security researcher has published code to demonstrate how to exploit the vulnerability, Secunia has yet to detect any malicious use of the code, said Thomas Kristensen, Secunia's chief technology officer.

    "There are no active exploits out there yet, but any attacks will be limited," Kristensen said. "Photoshop is primarily used by advertising agencies and image editors and not a lot of private individuals."

    Until Adobe Systems develops a fix, Secunia advises users to forgo opening bitmap files where the source of the file is not clear or verifiable.

    A researcher named Marsu is credited with discovering the vulnerability.

    Adobe, meanwhile, issued a statement saying it has been notified of the potential Photoshop security flaw and is investigating the issue.

    Adobe recently released Photoshop CS3, which was part of its larger Creative Suite 3 product line, or next-generation design and Web applications. Adobe noted that it will update customers on its Photoshop CS3 investigation as it learns more.

    Dawn Kawamoto


    NEXT: Google pulls malicious sponsored links
    PREV: Web threats to surpass e-mail pests
Rome - Rome, Season 1 - The Stolen Eagle


Copyright 2002-2008 AncientWorlds LLC | Code of Conduct and Terms of Service | Contact Us! | The AncientWorlds Staff