Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

ActiveX flaw could affect up to 70 apps
IT Week ^ | 24 Jan 2007 | Shaun Nichols

Posted on 01/24/2007 7:53:33 PM PST by holymoly

Vulnerable 3rd-party component used by more than two-dozen vendors.

A vulnerability within a software component used in more than 70 products could allow for an attacker to remotely run malware on a targeted system.

The vulnerability lies in NCTAudioFile2.dll, an ActiveX component used by Internet Explorer. An attacker could use a specially crafted web page to exploit the vulnerability and take control of a system, warned Danish security firm Secunia.

The component is made by Online Media Technologies Ltd., a UK-based firm that produces .net and ActiveX components for developers. The company said its clients include AT&T, Dell, and Intel.

Secunia estimates that the vulnerable component is used by more than 70 products from at least 28 different software developers.

Secunia has warned all vendors distributing the compontent, but hasn't yet heard back from Online Media Technologies.

While the vulnerability lies in a third-party component, Secunia said that it is partially up to the developers who use NACTAudioFile2 in their products to help protect users.

"Just because you didn't develop the original library file or component doesn't mean that you can eschew support for it, and leave it up to the original vendor to create a patch," said Secunia technical writer Ina Ragragio.

The vulnerability has been rated by Secunia as "highly critical," its second-highest severity rating. Ragragio said that Secunia is not aware of any publicly available exploit for the vulnerability, but that "actually crafting one is pretty straight-forward."

Secunia recommends that users either disable ActiveX or use a different web browser than Internet Explorer.

Online Media Technologies didn't immediately respond to a request for comment.


TOPICS: Computers/Internet
KEYWORDS: activex; ie; microsoft; msie
Navigation: use the links below to view more comments.
first 1-2021-30 next last
Secunia recommends that users either disable ActiveX or use a different web browser than Internet Explorer.

Take your pick:

Firefox
Opera
Seamonkey Suite

1 posted on 01/24/2007 7:53:35 PM PST by holymoly
[ Post Reply | Private Reply | View Replies]

To: holymoly

bump to see what happens in this thread.


2 posted on 01/24/2007 8:00:00 PM PST by knarf (Islamists kill each other ... News wall-to-wall, 24/7 .. don't touch that dial.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: holymoly

Jeeezz.

Good lord that isn't a good one.


3 posted on 01/24/2007 8:06:41 PM PST by Danae (Anail nathrach, orth' bhais's bethad, do chel denmha)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Danae

In the battle between functionality and security MS always chose functionality. That model made sense a decade ago. Now it is banging them. Active X was always an exciting but dangerous technology.


4 posted on 01/24/2007 8:40:58 PM PST by tomcorn
[ Post Reply | Private Reply | To 3 | View Replies]

To: holymoly

The only thing IE is good for is downloading the Windows updates.

I recently tried out the AVG AntiVirus, and it found 4 Trojans on my system that Norton had missed for several weeks. That is not very encouraging either.


5 posted on 01/24/2007 8:44:09 PM PST by TommyDale (If we don't put a stop to this global warming, we will all be dead in 10,000 years!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: TommyDale

I've been using AVG for years. Hands down better than any of the usual suspects, and far less intrusive on your system overall.


6 posted on 01/24/2007 9:02:50 PM PST by bamahead
[ Post Reply | Private Reply | To 5 | View Replies]

To: holymoly

The downside of software reuse.


7 posted on 01/24/2007 9:08:12 PM PST by El Gato ("The Second Amendment is the RESET button of the United States Constitution." -- Doug McKay)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Czar; glock rocks; Brian Allen; Brad's Gramma

ping


8 posted on 01/24/2007 9:18:14 PM PST by B4Ranch (Press "1" for English, or Press "2" and you will be disconnected until you learn to speak English.)
[ Post Reply | Private Reply | To 7 | View Replies]

To: TommyDale
> I recently tried out the AVG AntiVirus, and it found 4 Trojans on my system that Norton had missed for several weeks

Same with me. AVG is a very good product.

Norton has a name. They were once the best, but they have lost it.

9 posted on 01/24/2007 9:18:41 PM PST by dinasour (Pajamahadeen, SnowFlake, and Eeevil Doer.)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Echo Talon

Hey, Echo... over here!


10 posted on 01/25/2007 1:54:44 AM PST by Swordmaker (Remember, the proper pronunciation of IE is "AAAAIIIIIEEEEEEE!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: holymoly

bump


11 posted on 01/25/2007 6:24:42 AM PST by thegreatmalcolmx (I came to love white people.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: bamahead
I've been using AVG for years. Hands down better than any of the usual suspects, and far less intrusive on your system overall.

Give Avast! 4 Home Edition a try... let me know what you think...

Link

Its pretty sweet, I think you will like it... ;)

12 posted on 01/26/2007 5:08:05 AM PST by Echo Talon
[ Post Reply | Private Reply | To 6 | View Replies]

To: TommyDale

My AVG found the same four trojans in the last week. AVG is great.


13 posted on 01/26/2007 5:11:46 AM PST by Gracey
[ Post Reply | Private Reply | To 5 | View Replies]

To: dinasour

Do you all use the free or paid version of AVG


14 posted on 01/26/2007 5:13:21 AM PST by Gracey
[ Post Reply | Private Reply | To 9 | View Replies]

To: bamahead

Combine AVG with Zone Alarm Pro, and you're locked down as near to 100% as is possible today.


15 posted on 01/26/2007 5:15:33 AM PST by savedbygrace (SECURE THE BORDERS FIRST (I'M YELLING ON PURPOSE))
[ Post Reply | Private Reply | To 6 | View Replies]

To: bamahead

ADDENDUM: Assuming you're using a browser other than IE. I use Firefox.


16 posted on 01/26/2007 5:16:25 AM PST by savedbygrace (SECURE THE BORDERS FIRST (I'M YELLING ON PURPOSE))
[ Post Reply | Private Reply | To 6 | View Replies]

To: savedbygrace
Combine AVG with Zone Alarm Pro, and you're locked down as near to 100% as is possible today.

Give these 4 programs a try they work pretty well togeather and they are all free

Free antivirus - avast! 4 Home Edition This is nice lots of features, you may need to add port 12080 to the Webshield application just use a "comma" it will look like this (80,12080) when you have it right, turn all to high :)

PC Tools Firewall Plus 1.0.0.9 Nice easy to use

a-squared (a²) Free edition 2.1.0.12

Ad-Aware SE Personal 1.06

_______________________________________________

Windows Defender This is nice to have also....

17 posted on 01/26/2007 5:50:38 AM PST by Echo Talon
[ Post Reply | Private Reply | To 15 | View Replies]

To: savedbygrace
you really want to be paranoid?

PeerGuardian 2

18 posted on 01/26/2007 5:52:26 AM PST by Echo Talon
[ Post Reply | Private Reply | To 16 | View Replies]

To: Gracey

Intersting, eh? ?I would tell Norton, but since they seem to think they have all the answers, I'll let them find out elsewhere. It took a long time to get their crap out off my hard drive and out of the registry.


19 posted on 01/26/2007 5:58:23 AM PST by TommyDale (If we don't put a stop to this global warming, we will all be dead in 10,000 years!)
[ Post Reply | Private Reply | To 13 | View Replies]

To: Echo Talon

I have no clue why I would need that and why it would make me more paranoid.

What does it do? Allow you to download and upload music using P2P sites without getting caught? Is it more than that?

I'm trying to figure out how it is relavant to this thread. I'm probably missing something there.


20 posted on 01/26/2007 6:01:42 AM PST by savedbygrace (SECURE THE BORDERS FIRST (I'M YELLING ON PURPOSE))
[ Post Reply | Private Reply | To 18 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-30 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson