Telstra has revealed the addition of almost one million new mobile services in the six months to December 2011, but Sensis revenues plummeted 24 percent in 12 months.
This time the problem involves the routine used to process PNG (Portable Network Graphics) files. It's another example of the old 'maliciously crafted file causes a buffer overflow' problem. A successful exploit allows the execution of arbitrary code.
The flaw was discovered by 'Marsu', who found last week's flaw in Photoshop's handling of BMP and related files. iTWire's warning at that time ("It is also possible that Photoshop's routines for handling other types of files have similar flaws") has thus been borne out.
The bug lies in the PNG.8BI plugin. Other software known to be vulnerable includes Photoshop CS2, Photoshop Elements 5 and Paint Shop Pro 11, but there could be others.
Marsu has posted a sample exploit, so users should add PNG to the list of files types to be avoided unless they come from a trusted source.
Although that exploit is coded specifically for Windows, nobody seems to be claiming that the Mac version of the plug-in doesn't contain the same vulnerability.
There is an open source alternative to PNG.8BI: SuperPNG claims to be faster than Adobe's plug-in, as well as generating smaller PNG files. iTWire makes no comment on how secure it is, or its compatibility with recent versions of Photoshop.
David Bass
| For the fourth year in a row, IDC has placed content security provider Websense (NASDAQ: WBSN) at the top of the IDC Worldwide Web Security 2011 –…
How to Make Business Discovery Work for Your Business
Business Discovery takes its cues from consumer apps. Like Google, it encourages us- ers to hunt for and explore data without worrying about or even noticing the underly- ing technology. Their entire experience is working within an intuitive interface to get real-time, self-service results with only minimal training. ...more
Try an easy-to-use set of web-enabled
tools for business-class productivity services. Office 365 provides
anywhere-access to email, important documents, contacts, and calendars
on almost any device.