-
Notifications
You must be signed in to change notification settings - Fork 7.5k
Vulnerabilities in VideoJS #435
Description
Hello developers of VideoJS!
Two months ago, 08.02.2013, I've informed you about security vulnerabilities in your software (VideoJS Flash Component). These are Denial of Service and Cross-Site Scripting vulnerabilities in VideoJS Flash Component. The same day Simon answered me, thanked and passed this information to your engineering team.
The DoS which leads to BSOD I've found in January (and after that I found XSS in your software) and it's related to Adobe Flash Player 11.5.502.146. I've informed Adobe about it in January and Adobe has fixed this hole in version 11.6.602.168 at 12.02.2013. But already for two months there were no answers from you and XSS hole still was not fixed. I've wrote reminders to Zencoders at 23.02, 09.03 and 26.03 by e-mail (and at 26.03 also via contact form at site), but without any answers.
So I'm reminding you about this vulnerability through github. Since after giving you two months and after disclosing vulnerability in Adobe Flash last week, I'm planning to disclose the hole in VideoJS this week. And you still haven't fixed it.
Details of XSS I've wrote in my February's letters, so you had them already for two months. And details of DoS in Flash with using your player you can see in the video (I've sent it for you earlier in my letters):
Adobe Flash DoS BSOD
http://www.youtube.com/watch?v=xi29KZ3LD80
Vulnerable are VideoJS Flash Component v3.0 (from different web sites and github) and v3.0.1 (from github). Including flash-file from the last version VideoJS 3.2.3.