Patch or get PWNED in a flash

Recently fixed vulnerabilities in Sun's Java Runtime Environment and Adobe's Flash player mean that unpatched systems are vulnerable and could be infected with spyware or recruited into a botnet by simply visiting a Web page with exploit code -- and Google last month warned that 10 percent of Web sites contain this kind of malicious code.

IT professionals have been warned to patch vulnerabilities in the Adobe Flash Player application and Sun Java Runtime Environment as soon as possible.

The vulnerabilities mean that employees can get "hacked just by viewing a Web page that contains malicious Flash or Java content", warned antivirus company F-Secure in its blog.

Both Adobe and Sun issued patches for the vulnerabilities in updates last week. The Adobe update addresses an input validation error in Flash Player version 9.0.45.0 and earlier versions that could lead to the potential execution of arbitrary code.

The Sun update links to a patch for a buffer overflow vulnerability in the image-parsing code in the Java Runtime Environment that may allow an untrusted applet or application to elevate its privileges.

The flaw in the Java Runtime Environment could be particularly serious if left unpatched, according to Chris Gatford, a security professional from penetration-testing firm Pure Hacking.

"Java runs on everything: cell phones, PDAs and PCs. This is the problem when you have a vulnerability in something so modular -- it affects so many different devices," Gatford told ZDNet Australia.

"Also, this exploit is browser independent, as long as it invokes a vulnerable Java Runtime Environment," Gatford added.

ZDNet Australia's Liam Tung contributed to this report.

Tom Espiner reported for ZDNet UK from London

Like this article? Click below to send it to your mobile for free!

Advertisement

Talkback 0 comments


Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Angus Kidman Storage infrastructure on the tender track
    For a large-scale storage project, it's not uncommon to go out to tender for the best deal — but when was the last time you had to put together a tender for a document management room?
  • Array Apple has killed the video store; will ISPs be next?
    The Olympics are nearly over, and the Australian team deserves kudos for an excellent performance all around. Yet even as the Olympic sun sets on the Bird's Nest for the last time this weekend, millions of spectators around the world will be scanning their dials in the hope of finding something else to fill their viewing hours.
  • Array Conroy's filtering plan: security worries
    Communications Minister Stephen Conroy has welcomed "improvements" in ISP filtering technologies, but will a broad-scale roll-out make ISPs a thief's favourite target?
  • More blogs »

Tags

Back to top

Featured