[Home]   [Full version]  

Month of ActiveX Bugs (MoAxB)

May 02 ,Technology


Here we go again. Someone's planning to release one bug a day having to do with ActiveX in May.

Perhaps the biggest vulnerability research fad in the last year or so has been the "month of (whatever) bugs." Whatever. This time it's ActiveX, and the MoAxB or (as the author, after saying "sorry for my poor english," puts it: "Month of ActiveX Bug."

The author says: most of them are simple DoS (don't worry there are also some code execution) but that's because MoAxB has only a sense: to inform developers about the risk of using activex controls. (A DoS (Denial of Service) (in this context) is a bug that crashes an application.)

Some DoS bugs are evidence of hidden code execution bugs, but not all are. Don't assume that a DoS bug indicates anything more than the ability to crash a program by feeding it bad input.

Furthermore, the author is somewhat misleading when he refers to the risks of using ActiveX controls. The first bug of the month (see below) is probably typical: It's a commercial program that runs in the context of a Web browser. The fact that it's an ActiveX control has little or nothing to do with the bug. If the program were in another form, such as a Firefox plug-in, it would likely have the same bug.

On to the first bug: It's (as promised) a DoS in a third-party PowerPoint viewer control .

Not an auspicious opening for the MoAxB, but perhaps more important bugs will be forthcoming.

Copyright 2007 by Ziff Davis Media, Distributed by United Press International

Related stories:

The Month of (Yawn!) Search Engines Bugs
This June, look for at least one bug a day in Google, Yahoo, and the rest of the gang.
End tyranny of software updates
Q. Is there any way to know what is being updated when Microsoft updates come through? Being a learned - rather than born - skeptic, I'm suspicious each time an automatic update appears indicating that something is happening that will make it easier for somebody else to run my life or take more of my money or freedoms away.
Naughty Norton: Symantec Fixes Flaw in Security Software
The security vendor has patched a buffer overflow vulnerability that could allow an attacker to remotely execute malicious code.
Security Bigwigs Patch Their Programs
Symantec, McAfee, and Computer Associates have all fixed serious flaws in their software with recent patches and updates.
No News Is Big News for Sana Security
Sana Security today announced version 2.2 of the Primary Response SafeConnect anti-malware utility, which works exactly the same in Vista as in Windows XP.
Researcher: JavaScript Attacks Get Slicker
An Arbor Networks researcher at CanSecWest details JavaScript exploits' increasingly sophisticated means of attack and what tools to use to fight them.
Yahoo Patches IM Vulnerability
A buffer overflow problem is patched by the company.
Web sites get cool with Ajax or die
By this time next year, Web sites not developed using the Ajax technique "will simply not be cool enough to use," an Internet analyst said Tuesday.

News discussion:

Technology news

[Home]   [Full version]