TIFF CVE-2010-0188: Fixed?
Yet another example of why learned helplessness (relying on vendors for the “only” solution to a bug in their product) is bad. So there’s a patch that everyone thinks solved everything and what we see is that those who can work with POC are able change a few things and BOOM! The bug is actually STILL THERE. Of course, thanks to non-disclosure, only the bad guys are figuring this out.
Recently, we also found very frequent, targeted attacks, making use of the patched (not complete ) TIFF vulnerability (CVE-2010-0188).
What is interesting is that these exploits insert the javascript as well as crafted TIFF(exploit.tif) into XML Form, and generate malicious PDF by Adobe livecycle ES. The javascript is embedded within the form, and there is not detected by AV.
Leave a Reply
You must be logged in to post a comment.










