Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

November 1st, 2012, 09:30 GMT · By

BLOG

Yahoo! Experts Warn Users of SWF Vulnerability in YUI 2

SHARE:

Adjust text size:


Vulnerability found in YUI 2 Enlarge picture - Vulnerability found in YUI 2
Yahoo! experts warn users that a SWF security hole exists in Yahoo! User Interface Library (YUI) 2.

According to a post published on the YUI Blog, the vulnerability affects self-hosted YUI 2 SWF files, but customers of YUI 3 and those of YUI 2 via yui.yahooapis.com or a different CDN are not affected by the flaw.

No other details are provided, but engineers advise the owners of projects that host YUI 2 SWF files on their own servers to email them at security@yuilibrary.com for support and more information.

The H Security believes that the vulnerability might have something to do with the SWFStore class, which supports the persistence of data utilizing Flash Player.

In the meantime, customers don’t seem to be too pleased by the fact that the developers have decided to keep the details of the vulnerability to themselves.

“You haven’t created a meaningful barrier for malicious people; you’ve only made it harder for people who are legitimately affected by this issue to get the information they need to fix it,” one unhappy customer wrote.
FILED UNDER:
vulnerability
Yahoo!
YUI

TELL US WHAT YOU THINK:

1,277 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Persistent XSS and SQL Injection Flaws on ESET Taiwan Website Fixed

Secunia Vulnerability Intelligence Manager 4.0 Released

"60 Second" Flaw in Citibank Systems Allowed Crooks to Steal $1 Million

US Government and Military Sites Hacked by NullCrew, Thousands of Credentials Leaked

Ford Website Hacked by NullCrew, User Credentials Leaked Online (Updated)

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM