Browsers - 'Critical' Flaw in MySpace, Facebook Image Uploader - eWeek Security Watch

‘Critical’ Flaw in MySpace, Facebook Image Uploader

Written By
Ryan Naraine
Ryan Naraine
Feb 1, 2008
1 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Security researchers have raised an alert for serious security problems with the MySpace and Facebook image upload feature.

According to a warning from Symantec’s DeepSight threat analyst team, the issue centers around a buffer overflow in the ‘Action’ property of multiple ActiveX controls that’s used in the image upload process for the two popular social networks.

The ActiveX controls are designed and distributed by Aurigma Imaging Technology.

The vulnerability, publicly disclosed by hacker Elazar Broad on the Full Disclosure mailing list, could allow attackers to use booby-trapped Web pages to compromise Windows machines.

Exploit code that provides a roadmap to launch remote code-execution attacks has been published at Milw0rm.com.

Symantec DeepSight researcher Patrick Jungles said his team has confirmed the reliability of the exploit.

“We also expect to see exploits for the Facebook issue in the next few days, given the popularity of the social-networking community,” Jungles added.

“Since exploits are starting to come out for these issues, users are advised to use caution when browsing the Web,” he added.

In the absence of a fix, Windows/Internet explorer users should immediately disable these CLSIDs:

“* MySpace: {48DD0448-9209-4F81-9F6D-D83562940134}* Facebook: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0}* Aurigma: {6E5E167B-1566-4316-B27F-0DDAB3484CF7}“

See this Microsoft document for instructions on disabling ActiveX components.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.