Ubisoft patches dangerous plugin flaw

Powered by SC Magazine
 

Add-on allows attackers to execute applications on user machines.

Ubisoft has scrambled to fix a vulnerability discovered in its web browser plugin that allowed web sites to execute applications on user machines.

The flaw was reported on the Full Disclosure mailing list by Google security researcher Travis

Ormandy who stumbled across the flaw while installing the Ubisoft game title Assassin's Creed Revelations.

The vulnerable browser plugin was installed on customer machines as part of a game package and was used to take command line arguments while games were in under development.

But the function allowed the application to run any executable.

Ormanday created a brief proof of concept code that allowed a website to launch the Windows calculator via the vulnerable plugin.

Hours after the Monday post, Ubisoft issued a patch to close the vulnerability, blaming the gaffe on a "coding error".

Ubisoft denied claims by users it had installed rootkits on user machines to preserve its contentious digital rights management.

Copyright © SC Magazine, Australia


Ubisoft patches dangerous plugin flaw
 
 
 
Top Stories
Myer CIO named retailer's new chief executive
Richard Umbers to lead data-driven retail strategy.
 
Empty terminals and mountains of data
Qantas CIO Luc Hennekens says no-one is safe from digital disruption.
 
BoQ takes $10m hit on Salesforce CRM
Regulatory hurdles end cloud pilot.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  35%
 
Your insurance company
  5%
 
A technology company (Google, Facebook et al)
  9%
 
Your telco, ISP or utility
  8%
 
A retailer (Coles, Woolworths et al)
  4%
 
A Federal Government agency (ATO, Centrelink etc)
  18%
 
An Australian law enforcement agency (AFP, ASIO et al)
  15%
 
A State Government agency (Health dept, etc)
  7%
TOTAL VOTES: 4095

Vote
Do you support the abolition of the Office of the Information Commissioner?

   |   View results
I support shutting down the OAIC.
  26%
 
I DON'T support shutting the OAIC.
  74%
TOTAL VOTES: 1396

Vote