Members
  • Total Members: 12814
  • Latest: Rono
Stats
  • Total Posts: 28518
  • Total Topics: 8240
  • Online Today: 1026
  • Online Ever: 51419
  • (01. January 2010., 10:27:49)












Author Topic: At least, 8 Corel products have 0-day vulnerabilities... ( wintab32.dll )  (Read 2634 times)

0 Members and 1 Guest are viewing this topic.

Samker

  • SCF Administrator
  • *****
  • Posts: 7206
  • KARMA: 291
  • Gender: Male
  • Whatever doesn't kill us makes us stronger.
    • SCforum.info - Samker's Computer Forum


Local zero day vulnerabilities have been disclosed in Corel applications, potentially affecting more than 100 million users.

The holes were dropped by Marcos Accossatto of Core Security after the doodleware company did not respond to his private disclosure.

Corel has been contacted for comment.

"Given that this is a client-side vulnerability, affected users should avoid opening untrusted files whose extensions are associated with Corel software and contain any of the [affected] DLL files," Accossatto said in an advisory: http://www.coresecurity.com/advisories/corel-software-dll-hijacking

"When a file associated with the Corel software is opened, the directory of that document is first used to locate DLLs, which could allow an attacker to execute arbitrary commands by inserting malicious DLLs into the same directory as the document."

At least eight Corel products were affected including DRAW x7, PaintShop Pro x7, CAD 2014, and VideoStudio PRO. Some other Corel products were not tested.

The flaws occurred due to DLL hijacking where an attacker replaced wintab32.dll within the program's directories which would be executed within Corel programs.

Corel was warned 9 December and 2 January of the vulnerabilities and that they would be publicly disclosed if no response was made. It appears not to have responded, hence the disclosure and this story.

Corel claimed to have some 100 million users as of 2012. Plenty of those will be home users who acquired the company's products as bloatware and are now open to exploitation. Again.

(ElReg)

Samker's Computer Forum - SCforum.info





Fintech

  • SCF Advanced Member
  • ***
  • Posts: 329
  • KARMA: 41
  • Gender: Male
Fortunately for me is not any Corel program.  :D
I'm old man but still alive as well :)

A41202813GMAIL

  • SCF Advanced Member
  • ***
  • Posts: 370
  • KARMA: 32
  • Gender: Male
  • XPOCALYPSE FOREVER !
GOOGLE AND M$.
« Reply #2 on: 18. January 2015., 15:08:04 »
I Hope Everyone Gives 90 Days For These Kinds Of Bugs To Be Patched, Before Making Them Public.

And ... If They Are Not Patched, Just Act Like GOOGLE Did With M$ Several Times This Month Alone.

Private Individuals Must Be Careful, Though.

If These Disputes Reach The Courts They Do Not Have Enough $$$ To Defend Themselves.

Better Leave That Job To The Really Big Sharks Like GOOGLE.

---

GOOGLE FIBER WORLDWIDE, PLEASE !

devnullius

  • SCF VIP Member
  • *****
  • Posts: 3507
  • KARMA: 152
  • Gender: Female
    • SCForum.info

---

GOOGLE FIBER WORLDWIDE, PLEASE !


I recently saw a screenshot on 9gag... I understand now. I have dreams once more to live for!

Check it out..
More information about bitcoin, altcoin & crypto in general? GO TO  j.gs/7385484/btc

Cuisvis hominis est errare, nullius nisi insipientis in errore persevare... So why not get the real SCForum employees to help YOUR troubled computer!!! SCF Remote PC Assist http://goo.gl/n1ONa9

Samker

  • SCF Administrator
  • *****
  • Posts: 7206
  • KARMA: 291
  • Gender: Male
  • Whatever doesn't kill us makes us stronger.
    • SCforum.info - Samker's Computer Forum

---

GOOGLE FIBER WORLDWIDE, PLEASE !


I recently saw a screenshot on 9gag... I understand now. I have dreams once more to live for!

Check it out..


Photoshop... ???

??

devnullius

  • SCF VIP Member
  • *****
  • Posts: 3507
  • KARMA: 152
  • Gender: Female
    • SCForum.info

---

GOOGLE FIBER WORLDWIDE, PLEASE !




No Photoshop as far as I know... Crazy speeds for 2015 people... The ones that have Google Fibre, all report extreme (upload) speeds... Time to replace that 14k4 dial-up modem at last!

:) Devvie
More information about bitcoin, altcoin & crypto in general? GO TO  j.gs/7385484/btc

Cuisvis hominis est errare, nullius nisi insipientis in errore persevare... So why not get the real SCForum employees to help YOUR troubled computer!!! SCF Remote PC Assist http://goo.gl/n1ONa9

A41202813GMAIL

  • SCF Advanced Member
  • ***
  • Posts: 370
  • KARMA: 32
  • Gender: Male
  • XPOCALYPSE FOREVER !
GOOGLE FIBER.
« Reply #6 on: 17. February 2015., 07:11:01 »
If Companies Want Customers To Embrace The "Cloud", Unmatched Download And Upload Speeds Should Become A Thing Of The Past.

If The Browser Is The Future OS ( ? ), And A Dumb Terminal Is Just What You Will Need, Because All Software And Data Are Not Locally Stored Anymore ( Yeah, Right  ! ), Equal Speeds On Both Directions Is A Must.

GOOGLE Fiber Is Advertising 1Gbps Speeds On Both Directions, So That Screenshot Should Be Legit.

Cheers.

---

Samker

  • SCF Administrator
  • *****
  • Posts: 7206
  • KARMA: 291
  • Gender: Male
  • Whatever doesn't kill us makes us stronger.
    • SCforum.info - Samker's Computer Forum
Re: What is the maximum speed of Google Fiber ?!
« Reply #7 on: 18. February 2015., 20:25:43 »
It looks that you both had a right... :thumbsup:

Quote
...

"Google Fiber will provide an Internet connection speed of one gigabit per second (1,000 Mbit/s) for both download and upload which is roughly 100 times faster access than what most Americans have. Google Fiber says its service allows for the download of a full movie in less than two minutes."

...

Source Wikipedia: http://en.wikipedia.org/wiki/Google_Fiber


More information on official page: https://fiber.google.com/about/

 

With Quick-Reply you can write a post when viewing a topic without loading a new page. You can still use bulletin board code and smileys as you would in a normal post.

Name: Email:
Verification:
Type the letters shown in the picture
Listen to the letters / Request another image
Type the letters shown in the picture:
Second Anti-Bot trap, type or simply copy-paste below (only the red letters):www.scforum.info:

Enter your email address to receive daily email with 'SCforum.info - Samker's Computer Forum' newest content:

Terms of Use | Privacy Policy | Advertising