ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Microsoft cursor flaw may affect Firefox users

Tom Espiner ZDNet.co.uk

Published: 04 Apr 2007 14:02 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The animated cursor vulnerability in Windows could also affect those using Firefox on Windows machines, according to one of the security researchers who discovered the flaw.

Read this

Talkback comment

"Anyone still using MSIE is flirting with danger. This has been proven to be the most vulnerable, insecure, browser on planet earth."

Read more +

Alexander Sotirov, a researcher for security company Determina, said in an email to security flaw mailing list Full Disclosure that while there was no vulnerability in the Firefox source code itself, a hacker can exploit the Windows flaw through its application programming interface (API) for Firefox. "Firefox uses a Windows API function which uses the vulnerable code in USER32.DLL, so the .ani vulnerability can be exploited through Firefox," Sotirov wrote.

The flaw — also known as the .ani stack overflow vulnerability — was made public by Microsoft on Thursday last week. By Friday there were reports of widespread exploits, and Microsoft issued a patch — detailed in the MS07-017 security bulletin — a week early, out of its monthly cycle of patching on a Tuesday. The vulnerability affects both Windows XP Service Pack 2 and Vista.

Sotirov said that installing the MS07-017 patch would protect both Internet Explorer and Firefox users against the .ani stack overflow vulnerability, and that he would delay releasing exploit code that could be used against people using Firefox on Windows machines until users had been given a chance to install the Microsoft patch.

Sotirov was adamant that the problem did not lie with the Firefox source code itself. "There is no vulnerability for the Firefox developers to patch. I recommend that they limit their use of the Windows API to avoid being affected by the next Windows vulnerability, but this is application hardening, not a vulnerability fix."

Mozilla Foundation, which heads the development of Firefox, could offer no comment at the time of writing.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
16 out of 16 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

Embedded C / C++ protocol stack engineer - Berks - Up to 50k!

My client is now looking for embedded C / C++ protocol stack engineer. You will be reliable for working on all layers of the protocol stack where you ...

C++ Windows Applications Developer - VC++ / STL/Boost - Dorset

To be considered your CV should outline your skills and technical experience using: - C++ with Visual Studio - Windows API, STL, Boost - Client / ...

Sophis API Developer - Strong Equity Derivatives Knowledge

One of my key investment management clients is putting considerable effort and resources into its use of derivatives strategies. As part of a ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment