Feeds

Exploit emerges for LZO algo hole

Take one Nyan Cat, add Firefox and hope your Linux distro has been patched

5 things you didn’t know about cloud backup

Security Mouse security researcher Don A Bailey has showcased an exploit of the Lempel-Ziv-Oberhumer (LZ0) compression algorithm running in the Mplayer2 media player and says it could leave some Linuxes vulnerable to attack.

The LZO data compression algorithm was created by Markus Oberhumer in 1994 and was discovered to be vulnerable in June.

Bailey's demo of the Mplayer2 plugin shows a vulnerability that can trigger remote code execution (RCE) by way of a Nyan Cat image reel displayed on an updated version of FireFox version 30.

It was revealed the vulnerability could trigger an integer overflow vulnerability that caused a denial of service or buffer overflow resulting in remote code execution under specific conditions.

"This is not a Firefox attack," Bailey said.

"I said [in a blog] I would be releasing an Mplayer2 app, and pointed at gecko-mediaplayer being straight-up vulnerable."

"My concern is that these apps/plugins are installed by default on some distributions of Linux."

He said Linux distributions were surprisingly slow at applying LZO fixes despite it existing for media platforms Libav and FFmpeg.

Firefox itself is vulnerable to RCE but only in very constrained cases using certain browser versions which limited the attack enough that Bailey would not bother releasing his lz4 compressed bookmark boy-in the browser demonstration.

NCC Group security bod Wade Alcorn (@WadeAlcorn) said plugins represent unwelcome risk.

"Plugins have a considerable attack surface and have been a thorn in the side of browser security for some time. The browser plugin model is baked into browser design and won't go away anytime soon," Alcorn said. ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
Ice cream headache as black hat hacks sack Dairy Queen
I scream, you scream, we all scream 'DATA BREACH'!
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
JLaw, Kate Upton exposed in celeb nude pics hack
100 women victimised as Apple iCloud accounts reportedly popped
Scratched PC-dispatch patch patched, hatched in batch rematch
Windows security update fixed after triggering blue screens (and screams) of death
Researchers camouflage haxxor traps with fake application traffic
Honeypots sweetened to resemble actual workloads, complete with 'secure' logins
Attack flogged through shiny-clicky social media buttons
66,000 users popped by malicious Flash fudging add-on
New Snowden leak: How NSA shared 850-billion-plus metadata records
'Federated search' spaffed info all over Five Eyes chums
Three quarters of South Korea popped in online gaming raids
Records used to plunder game items, sold off to low lifes
Oz fed police in PDF redaction SNAFU
Give us your metadata, we'll publish your data
prev story

Whitepapers

Endpoint data privacy in the cloud is easier than you think
Innovations in encryption and storage resolve issues of data privacy and key requirements for companies to look for in a solution.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Advanced data protection for your virtualized environments
Find a natural fit for optimizing protection for the often resource-constrained data protection process found in virtual environments.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.