Slashdot Mirror


Image Causes Exploitable Overflow in Microsoft Products

Em Adespoton writes "Core Security researchers discovered that by electing a specially-crafted graphic as the user's display picture in MSN Messenger, an attacker could trigger a buffer overflow vulnerability on the chat partner's computer. Through this, it is possible to covertly take over machines running instant messaging software. Windows Messenger and Windows Media Player are also affected by this vulnerability. The story is also available at Newsfactor.com and SearchSecurity.com."

11 of 291 comments (clear)

  1. MS loss... by LazyPhoenix · · Score: 5, Funny

    Microsofts loss is my GAIM.

    ha.

  2. Where are the Cherubs? by Speare · · Score: 5, Interesting

    I think I heard of this method of attack in a security book I read once. Where the image of an avatar's identification turned out to be a computer-infecting virus. Oh, wait, it was a novel. "Snow Crash" by Neal Stephenson.

    --
    [ .sig file not found ]
  3. Re:Worst internet worm ever? by PapaBoojum · · Score: 5, Funny

    By spreading to everyone in your buddy list, a worm based on this exploit could infect 90% of the world in a couple hours.

    I'm doing my part. I don't have any friends.

  4. Re:That's genius... by robslimo · · Score: 5, Informative

    Is this one at all related to the previous image library flaws (the vulnerability for which the GDI detection tool was released to identify any Windows apps that were affected)?

    Oh, wait, I think I found it! A patch was released for PNG processing flaws on Tuesday this week; among the affected software: Microsoft MSN Messenger.

  5. Ah HA! by MrFreshly · · Score: 5, Funny

    The image that triggers it is an inverted picture of Bill Gates playing cards with Sadam, Satan, and Celine Dion.

  6. They're wrong about PNG by BluhDeBluh · · Score: 5, Informative

    They've said that PNG stands for "Proprietary Network Graphics". In fact, this is very wrong - it's not proprietary at all. The idea of the format is that it _ISN'T_ proprietary - it's free as in speech, free as in beer, free as in patents.

    PNG really stands for Portable Network Graphics. And I hope that people don't get confused and start blaming the PNG file format for a bug that is MS's fault.

  7. Before anyone goes off bashing MS... by k98sven · · Score: 5, Informative

    Perhaps one should take note that this overflow bug is not in MS code, but in the open-source LibPNG, which MS used.

    And it's also included in most Linux distros.

    If MS is to blame, it's for their lousy reaction speed. This vunerability has been known for months.

  8. Isn't it worth mentioning by apoplectic · · Score: 5, Insightful

    The Slashdot story blurb leaves out that this fix is already available. Certainly, if the fix hadn't already been made available you could count on that tidbit being mentioned....

  9. The exploit..... by FreshlyShornBalls · · Score: 5, Informative

    .....is already out.

    --
    This space intentionally left blank.
  10. once upon a time... by ultramk · · Score: 5, Interesting

    a friend of mine used to work for MS on a version of IE... one bug they were trying to track down involved jpg (or was it gif) images of a certain--very large--dimension that could in some circumstances cause boot-block overwrite on the boot drive as it was being cached... (this was a few years back...)

    when this bug was being discussed in a meeting, the first thing that was said was something to the effect of "oh, and if you tell anybody--anybody--about this, you might as well look for a new job at the same time, and a good lawyer."

    of course, this was a few years ago, and from what i understand it was fixed right away, but still...

    m-

    --
    You catch enchiladas by picking them up behind the head and holding them underwater until they don't kick anymore -VeGas
  11. Re:Removing MSN Messenger doesn't actually remove by MrP-(at+work) · · Score: 5, Informative
    Yeah that never uninstalls it

    You have to manually call the uninstall section of the msn messenger INF file.. ive done it so many times i type it from memory..

    go to start>run, and type
    rundll32 advpack.dll,LaunchINFSection %windir%\inf\msmsgs.inf,BLC.Remove
    make sure msn messenger is closed first so it wont error when it unregisters the dll files
    --
    [an error occurred while processing this directive]