Source of Adobe zero-day bug patched

One of the flaws at the heart of Adobe's ColdFusion 8.0.1 zero-day vulnerability has been patched.

Recent attacks were due, in part, to a vulnerable text-editor bundled with ColdFusion, a web design and development platform, according to Adobe. It had been shipped with an open source text editor called FCKeditor, versions of which contained a security hole.

“Adobe is aware of reports of ColdFusion websites being compromised through a vulnerability in the FCKeditor rich text editor,” David Lenoe, Adobe product security program manager wrote Friday in a post on the company's Product Security Incident Response Team (PSIRT) blog.

He said Adobe is working on a fix, which is expected to be made available this week. He also outlined a workaround in the post.

In the meantime, a new version of FCKeditor has been released to address the vulnerability. In an advisory, US-CERT said that it “encourages users and administrators to upgrade to FCKeditor version 2.6.4.1 to help mitigate the risks.”

The FCKeditor vulnerability was “due to improper verification of input passed to the ‘CurrentFolder' parameter," US-CERT said in its advisory. "Exploitation of this vulnerability may allow an attacker to execute arbitrary code.”

ColdFusion also suffered from a second attack vector through vulnerable FCKeditor installations.

“One of the common applications that has been seen in attacks is CFWebstore, a popular e-commerce application for ColdFusion,” wrote Bojan Zdrnja, senior information security consultant at Infigo IS, in an updated post on the SANS Internet Storm Center. "Older versions of CFWebstore used a vulnerable FCKeditor installation. If you are using CFWebstore, make sure that you are running the latest version and that any leftovers have been removed.”

close

Next Article in News

Sign up to our newsletters

More in News

Bitcoin mining botnet has become one of the most prevalent cyber threats

Fortinet researchers have tracked 100,000 new ZeroAccess trojan infections per week, making the botnet very lucrative to its owners.

House Intelligence Committee OKs amended version of controversial CISPA

House Intelligence Committee OKs amended version of controversial ...

Despite the 18-to-2 vote in favor of the bill proposal, privacy advocates likely will not be satisfied, considering two key amendments reportedly were shot down.

Judge rules hospital can ask ISP for help in ID'ing alleged hackers

Judge rules hospital can ask ISP for help ...

The case stems from two incidents where at least one individual is accused of accessing the hospital's network to spread "defamatory" messages to employees.