Menu
Flaw in open-source PDF viewer could put WikiLeaks users, others at risk

Flaw in open-source PDF viewer could put WikiLeaks users, others at risk

The flaw could be exploited to launch XSS and content spoofing attacks

An open-source component used to display PDF files on WikiLeaks.org and other websites contains vulnerabilities that could be exploited to launch cross-site scripting (XSS) and content spoofing attacks against visitors.

The vulnerable component is called FlexPaper and is developed by a company called Devaldi, based in New Zealand. The company confirmed the issues, which were first reported Thursday on the WikiLeaks supporters forum, and released FlexPaper 2.3.0 to address them.

However, it seems that the component hasn't yet been updated on WikiLeaks.org, which was still using FlexPaper 2.1.2 on some pages Tuesday.

The incident comes after Wired reported last week that in 2012 the FBI used a Flash-based component to decloak Tor users and find their real IP (Internet Protocol) addresses in an operation that targeted users of child pornography websites hosted on the Tor network.

Since WikiLeaks' audience includes a lot of users that value their privacy and anonymity, any vulnerability in the site that could potentially be used to expose their real location is likely to be viewed as a serious threat.

"Given the fact that most browsers use plugins to enable the reading of PDFs, we strongly urge WikiLeaks to link directly to PDF files instead of using third party software that could put users at risk," said a user named Koyaanisqatsi, who reported the flaws on the WikiLeaks forum.

That's what WikiLeaks did with two secret documents about travelling through airports using false ID that were allegedly leaked from the U.S. Central Intelligence Agency. The site published the documents Sunday and directly linked to the PDF files instead of displaying them in an embedded viewer.

Subscribe here for up-to-date channel news

Follow Us

Join the New Zealand Reseller News newsletter!

Error: Please check your email address.

Tags patchesDevaldisecuritywikileaksExploits / vulnerabilitiesprivacy

Featured

Slideshows

Tight lines as Hooked on Lenovo catches up at Great Barrier Island

Tight lines as Hooked on Lenovo catches up at Great Barrier Island

​Ingram Micro’s Hooked on Lenovo incentive programme recently rewarded 28 of New Zealand's top performing resellers with a full-on fishing trip at Great Barrier Island for the third year​ in a row.

Tight lines as Hooked on Lenovo catches up at Great Barrier Island
Inside the AWS Summit in Sydney

Inside the AWS Summit in Sydney

As the dust settles on the 2017 AWS Summit in Sydney, ARN looks back an action packed two-day event, covering global keynote presentations, 80 breakout sessions on the latest technology solutions, and channel focused tracks involving local cloud stories and insights.

Inside the AWS Summit in Sydney
Channel tees off on the North Shore as Ingram Micro hosts annual Cure Kids Charity golf day

Channel tees off on the North Shore as Ingram Micro hosts annual Cure Kids Charity golf day

Ingram Micro hosted its third annual Cure Kids Charity Golf Tournament at the North Shore Golf Club in Auckland. In total, 131 resellers, vendors and Ingram Micro suppliers enjoyed a round of golf consisting of challenges on each of the 18 sponsored holes, with Team Philips taking out the top honours.

Channel tees off on the North Shore as Ingram Micro hosts annual Cure Kids Charity golf day
Show Comments