Flaw in open-source PDF viewer could put WikiLeaks users, others at risk

An open-source component used to display PDF files on WikiLeaks.org and other websites contains vulnerabilities that could be exploited to launch cross-site scripting (XSS) and content spoofing attacks against visitors.

The vulnerable component is called FlexPaper and is developed by a company called Devaldi, based in New Zealand. The company confirmed the issues, which were first reported Thursday on the WikiLeaks supporters forum, and released FlexPaper 2.3.0 to address them.

To read this article in full or to leave a comment, please click here

Read more: Flaw in open-source PDF viewer could put WikiLeaks users, others at risk

Story added 23. December 2014, content source with full text you can find at link above.