Adobe: Patch for ColdFusion bug will be out next week
Adobe Systems will have a patch ready next week for a flaw in its ColdFusion Web development software that other security authorities say could result in a hacked system.
The problem lies in the FCKEditor rich text editor, which is installed with ColdFusion 8, Adobe said on its security blog. Adobe also listed in its warning three steps that could in the meantime mitigate an attack.
FCKEditor is an open-source application that handles file uploads and file management, but the feature is supposed to be disabled in the version embedded on a ColdFusion server, wrote John Mason, a ColdFusion consultant who writes a blog called CodFusion. In some cases, the connector that enables the feature is left on.
"If left on, this means a hacker might be able to directly call the file manager system to upload files and take control of the server," Mason wrote. "FCKEditor has had some history on being exploited by this type of attack."
The SANS Internet Storm Center, which monitors security threats, said it had seen a "high number" of Web sites running ColdFusion that had been compromised.
"The attacks we've been seeing in the wild end up with inserted <script> tags into documents on compromised Web sites," wrote Bojan Zdrnja of the Internet Storm Center. "As you can probably guess by now, the script tags point to a whole chain of web sites which ultimately serve malware and try to exploit vulnerabilities on clients."
Zdrnja wrote on the Internet Storm Center's blog that there appear to be two attack vectors. ColdFusion version 8.0.1 installs a vulnerable version of FCKEditor, which can be directly exploited and allow a hacker to upload arbitrary files.
Other third-party applications also use FCKEditor, such as CFWebstore, which is an e-commerce application for ColdFusion, Zdrnja wrote. CFWebstore has also been exploited in the attacks, he wrote.
IDG News Service
Sign up for ITworld's Daily newsletter
Follow ITworld on Twitter @IT_world
On Twitter now
adobe
Powered by Twitter
Esther Schindler
If the comments are ugly, the code is ugly
claird
SVG a graphics format for 21st century
pasmith
Take Chrome OS for a test spin
Sandra Henry-Stocker
Solaris Tip: Have Your Files Changed Since Installation?
jfruh
Android fragments vs. the iPhone monolith
mikelgan
What Gizmodo missed about the Pro WX Wireless USB disk drive
Sidekick: The Good News & the Bad News
Either way you look at it Microsoft Data Center management did not follow standards or best practices in this failure. In which case it makes me wonder more about the outsourcing of corporate data much less personal data.
- mburton325
Join the conversation here
Quick, practical advice for IT pros. Made fresh daily.
Want to cash in on your IT savvy? Send your tip to tips@itworld.com. If we post it, we'll send you a $25 Amazon e-gift card.













