AplusWebMaster
Topic Starter
FYI…
- http://secunia.com/advisories/28715
Release Date: 2008-01-31
Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Unpatched
Software: MySpace Uploader Control 1.x
…The vulnerability is confirmed in MySpaceUploader.ocx version 1.0.0.5 and reported in version 1.0.0.4. Other versions may also be affected.
Solution:
Set the kill-bit for the affected ActiveX control…
Original Advisory:
http://lists.grok.org.uk/pipermail/full-di…ary/059980.html
> http://www.theregister.co.uk/2008/02/01/my…e_uploader_bug/
1 February 2008 - "…Facebook also reportedly repackages the Aurigma control, though which version it uses is unclear… Aurigma, a Washington-based software developer, acknowledged that version 4.5.70 of its control was vulnerable… It didn't comment on the use of its software on social networking sites…"
- http://preview.tinyurl.com/3xmsuo
January 31, 2008 (Computerworld) - "…Symantec, which claimed that the ActiveX control used by Facebook and MySpace came from Aurigma, was able to confirm some of Broad's findings. "The affected ActiveX control originates from Aurigma… However, we haven't confirmed if the original Aurigma control is vulnerable or if both MySpace and Facebook have changed the control to suit their needs and introduced the flaw in the process," Symantec said in a warning to customers of its DeepSight threat network… "Considering the massive user base for [Facebook and MySpace] and the potential widespread distribution of this vulnerable ActiveX control, we consider this a high-profile issue," Symantec concluded…"

- http://secunia.com/advisories/28715
Release Date: 2008-01-31
Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Unpatched
Software: MySpace Uploader Control 1.x
…The vulnerability is confirmed in MySpaceUploader.ocx version 1.0.0.5 and reported in version 1.0.0.4. Other versions may also be affected.
Solution:
Set the kill-bit for the affected ActiveX control…
Original Advisory:
http://lists.grok.org.uk/pipermail/full-di…ary/059980.html
> http://www.theregister.co.uk/2008/02/01/my…e_uploader_bug/
1 February 2008 - "…Facebook also reportedly repackages the Aurigma control, though which version it uses is unclear… Aurigma, a Washington-based software developer, acknowledged that version 4.5.70 of its control was vulnerable… It didn't comment on the use of its software on social networking sites…"
- http://preview.tinyurl.com/3xmsuo
January 31, 2008 (Computerworld) - "…Symantec, which claimed that the ActiveX control used by Facebook and MySpace came from Aurigma, was able to confirm some of Broad's findings. "The affected ActiveX control originates from Aurigma… However, we haven't confirmed if the original Aurigma control is vulnerable or if both MySpace and Facebook have changed the control to suit their needs and introduced the flaw in the process," Symantec said in a warning to customers of its DeepSight threat network… "Considering the massive user base for [Facebook and MySpace] and the potential widespread distribution of this vulnerable ActiveX control, we consider this a high-profile issue," Symantec concluded…"