CyberInsecure.com

Daily cyber threats and internet security news: network security, online safety and latest security alerts
August 18th, 2009

Adobe Patches Critical Flaws In ColdFusion And JRun

Adobe Systems has released updates that patch vulnerabilities in two widely used web development applications, several of which let attackers steal sensitive data or take complete control of users’ machines.

In all, the patches fix seven flaws in versions 8.0.1 and earlier of ColdFusion and JRun 4.0. The most serious of them are XSS, or cross-site scripting, bugs that allow attackers to execute malicious code on an underlying system by supplying a target with a booby-trapped web link.

Adobe engineers also fixed a separate management console flaw. It allowed unauthenticated users to traverse restricted directories, a vulnerability that could lead to information disclosure. Proof-of-concept code released Tuesday showed the flaw could be exploited using a URL that looks something like this:

http://[server]/server/[profile]/logging/logviewer.jsp?logfile=../../../../../../../boot.ini

The fixes come as Adobe, whose software is perhaps more ubiquitous than Microsoft’s, struggles to patch a variety of security vulnerabilities that have been exploited to install malware on the machines running the programs. Three weeks ago, its security team pushed out a fix for a bug in its Flash Player that criminals were using to hijack user machines. Attackers last month were also able to compromise a large number of websites by targeting an open-source text editor bundled with ColdFusion.

In May, Adobe announced it was reinvigorating security measures used to design its Reader application used to view PDF documents. The initiative was a great start, but by no means adequate because it left Flash and other widely used Adobe titles out of the tent.

Adobe says it is currently unaware of any exploits targeting the latest ColdFusion and JRun bugs. The company’s security bulletin is available here.

Credit: The Register

Share this item with others:

More on CyberInsecure:
  • Six Security Vulnerabilities Updated By Adobe In Flash Player 9
  • Critical Security Vulnerability Patched In Adobe AIR 1.5
  • Microsoft Patch 14 PowerPoint Vulnerabilities, Adobe Patch Reader And Acrobar 0-day Vulnerability
  • Drive-by Download Attack Hits Multiple Sites Running Vulnerable ColdFusion Application
  • Buffer Overflow Critical Vulnerabilities In Adobe Reader And Acrobat

  • If you found this information useful, consider linking to it from your own website.
    Just copy and paste the code below into your website (Ctrl+C to copy)
    It will look like this: Adobe Patches Critical Flaws In ColdFusion And JRun

    Leave a Reply

    Comments with unsolicited links to other resources will be marked as spam. DO NOT leave links in comments. Please leave your real email, it wont be published.

    *
    To prove you’re a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.