Infosec Europe 2008
Infosec Europe 2008

Infosec: Experts warn of null pointer flaws

'Next big IT security threat,' says security firm

Written by Robert Jaques

Users need to be more vigilant than ever

Geoff Sweeney Tier-3

Recently discovered Flash vulnerabilities indicate that 'null pointer' security flaws could quickly evolve into "the next big thing in hacking exploits ".

Security vendor Tier-3 warned that null pointer security flaws are exploitable and could quickly replace buffer overflows as the next big threat.

A 'null pointer' is a link in software code that points to an empty location in computer memory.

Geoff Sweeney, chief executive at Tier-3, said: "Buffer overflows are still an issue, but they are a problem that has been tackled by the industry for many years.

"Null pointer de-referencing has not received anywhere near the same level of attention, which means that users need to be more vigilant than ever."

Sweeney added that computer users could face problems if a reliable exploit approach for null pointer de-referencing can be harnessed.

Organisations and home users will need to be on alert as their infrastructure is already under constant threat, particularly when the affected software is as pervasive as Adobe's Flash.

Tags:

Further reading

Infosec Video Lounge Part 1

Infosec 2008 Preview: Ed Gibson, Chief Security Advisor at Microsoft UK, talks to vnunet.com about the security focus for the coming year.   More...

Infosec Europe 2008 Special Report

The latest news and views from Europe's number one information security event   More...

Infosec: 2007 online card fraud tops £500m

Retailers fighting an ever increasing threat   More...

Infosec: Most breaches down to lost or stolen kit

Hacking fades in favour of theft   More...

Related articles

Expert roasts web-enabled coffee maker

IT security message still not filtering through   More...

Infosec: Critical infrastructure open to IT security threats

ISF makes warning at Infosecurity Europe 2008   More...

Hackers take aim at city power grids

Threat is nothing new, but criminals are turning to extortion   More...

Shape-shifting malware hits the web

Cyber-criminals changing malware signatures every few hours   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

22 Jul 2008

3.22 MBSat-nav crashes, open source security and female gamers More...

21 Jul 2008

3.12 MBGlobal internet reach, online spending and the space race More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Security

Major DNS flaw revealed

Experts sound alarms over early disclosure   More...

Nintendo DS

Dodgy Chinese Nintendo chargers recalled

Experience could shock some users   More...

Advertisement

Houses of Parliament

Official 'spying' requests top 500,000

Information includes web records and itemised phone bills   More...

Hacking

Small firms naïve about security

SMBs remain prone to attack, says study   More...

Advertisement