Microsoft cursor flaw may affect Firefox users

By Tom Espiner, ZDNet UK
Thursday, April 05, 2007 07:12 AM

The animated cursor vulnerability in Windows could also affect those using Firefox on Windows machines, according to one of the security researchers who discovered the flaw.

Alexander Sotirov, a researcher for security company Determina, said in an e-mail to security flaw mailing list Full Disclosure that while there was no vulnerability in the Firefox source code itself, a hacker can exploit the Windows flaw through its application programming interface (API) for Firefox. "Firefox uses a Windows API function which uses the vulnerable code in USER32.DLL, so the .ani vulnerability can be exploited through Firefox," Sotirov wrote.

The flaw--also known as the .ani stack overflow vulnerability--was made public by Microsoft last week. By end week there were reports of widespread exploits, and Microsoft issued a patch — detailed in the MS07-017 security bulletin--a week early, out of its monthly cycle of patching on a Tuesday. The vulnerability affects both Windows XP Service Pack 2 and Vista.

Sotirov said that installing the MS07-017 patch would protect both Internet Explorer and Firefox users against the .ani stack overflow vulnerability, and that he would delay releasing exploit code that could be used against people using Firefox on Windows machines until users had been given a chance to install the Microsoft patch.

Sotirov was adamant that the problem did not lie with the Firefox source code itself. "There is no vulnerability for the Firefox developers to patch. I recommend that they limit their use of the Windows API to avoid being affected by the next Windows vulnerability, but this is application hardening, not a vulnerability fix."

Mozilla Foundation, which heads the development of Firefox, could offer no comment at the time of writing.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Hands-on programming: Extract plain text from documents with Syncfusion's components

Web Development

Justin James recently tried Syncfusion's Essential DocIO and Essential PDF to help him extract text from documents he downloaded from the Internet. Here's the code he wrote to get the plain text.


Read more »



Will technology divide us further?

Blog thumbnail

So I finally watched 2012 over the weekend, but the film left me feeling extremely agitated.

The possibility that the world may meet its watery end in three years didn't..... by Eileen Yu

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web