Showing posts with label bug. Show all posts
Showing posts with label bug. Show all posts

Tuesday, February 19, 2008

Firefox and Opera Tells More

An intruder could manipulate a flaw in how the browsers handle image files to see where the user has been surfing.

Opera, Firefox Bug Could Reveal Web Travels

Jeremy Kirk, IDG News Service

A flaw in the way the Firefox and Opera browsers handle an image file could allow an attacker to see what Web sites a person has visited.

The problem concerns how the two browsers handle a ".BMP," or bitmap, image file, according to an advisory written by Gynvael Coldwind of Vexillium.org, who posted a video illustrating the problem.

A malicious bitmap file can be created that pulls other information from the browsers' memory. Some of the information that can be captured is random, but at other times could be valuable, the advisory said.

"The harvested data contains various information including parts of other Web sites, users' favorites and history and other information," Vexillium.org said.

Using the "canvas" HTML (Hypertext Markup Language) tag supported by the browsers, an attacker can capture the data. Then, using JavaScript, the information can be sent to a remote server.

The flaw could also crash Firefox. The vulnerability affects Firefox 2.0.0.11 and previous versions of that browser as well as the beta version of Opera 9.50.

source: www.pcworld.com

Wednesday, January 9, 2008

Microsoft's First Roundup of Patches

The first set of patches for 2008 was released by Microsoft this Tuesday, fixing a pair of networking flaws in the Windows kernel.

Microsoft Releases a New Set of Patches


Microsoft has released a patch to fix a security flaw in Windows that could be used by criminals to create as self-copying computer worm attack. The patch fixed a pair of networking flaws in the Windows Kernel. Another patch was also released for a less-serious Windows flaw that would allow attackers to steal passwords or run Windows software with elevated privileges.

The critical bug lies in the way Windows processes networking traffic that uses IGMP (Internet Group Management Protocol) and MLD (Multicast Listener Discovery) protocols, which are used to send data to many systems at the same time. Microsoft says that an attacker could send specially crafted packets to a victim's machine, which could then allow the attacker to run unauthorized code on a system.

No known code exploits this flaw, security experts say, but now that the patch has been posted, hackers can reverse-engineer the fix and create their own attack code. Since IGMP is enabled both in Windows XP and Vista by default, the bug could be used to create a self-copying worm attack, Microsoft has disclosed.

"Theoretically this is wormable and that's why this is rated critical," said Tim Rains, security response communications lead with Microsoft. However, Microsoft does not believe that hackers will have an easy time developing attack code that will work reliably. "We've done a thorough analysis of the vulnerability and we've come to the conclusion that there are several technical mitigating factors that make it unlikely to get reliable remote code execution," Rains said.

Windows uses the IGMP protocol for many popular consumer applications such as streaming video, multiplayer games and universal plug-and-play, but the protocol is usually blocked at the router. A derivative of IGMP, MLD is the multicast protocol used by IPv6 systems and is enabled on Vista by default

"If it became a worm it could take over an internal network pretty quickly, or at least all the machines where multicast is enabled," said Eric Schultze, chief technology officer with Shavlik Technologies. "But this one is going to be mitigated because a lot of people have blocked multicast."

Wednesday, December 19, 2007

IE Crippled By Update

Microsoft is investigating a security update released last week that has crippled Internet Explorer and prevented users from surfing the Web.

Microsoft Update Cripples IE
Microsoft has confirmed that it is investigating reports regarding a security update for Internet Explorer issued last week, crippling some users' ability to get on the web with the said browser.

Users started posting messages on forums and Microsoft support newsgroup after Microsoft released the MS07-069 Security Bulletin on December 11. Most of them are saying that they could not use Internet Explorer to connect to the internet, either because Internet Explorer refused to launch, or because when it did open, it could not open various websites.

"About 60% of the time, I would get an 'Internet Explorer has encountered a problem and must close' dialog," reported Bill Drake on the Windows Update newsgroup. Others echoed those comments on IE-specific forums, noting that both IE6 and IE7 balked at loading, or while loading, some pages, particularly home pages, on both Windows XP and Windows Vista machines.

Harold Decker, operations manager at San Diego-based Gold Peak IndustriesNA Inc., started fielding calls from users last Wednesday morning as soon as people hit the office. "I stopped everyone who hadn't installed the update from installing it, after four PCs out of 14 had the problem," said Decker, who manages a total of 35 Windows XP SP2 machines. "We're a pretty plain shop; all our systems run Windows XP SP2 and IE6," said Decker. "But some kept crashing. It seemed limited to the window that was opened, and changing the home page to something simple, like a blank page, gave a better success rate."

Microsoft said it is currently creating a patch. "Our customer service and support teams are investigating public claims of a deployment issue with Microsoft Security Bulletin MS07-069," Microsoft's Mark Miller, director of security response. "If necessary, Microsoft will update the Knowledge Base article associated with MS07-069 with detailed guidance on how to prevent or address these deployment issues," Miller added.

Other users on the support forums weren't much help, except to suggest uninstalling last Tuesday's security update. That's what Decker did. "We uninstalled [MS07-069] and have had no problems since then," he said.

Thursday, December 13, 2007

FolderShare Deletes Files

Microsoft fixed a bug in its online file storage and sharing service that deleted files without user authorization.

The Microsoft AutoDelete Bug
After users reported problems about Windows Live FolderShare, an online file storage and sharing service, Microsoft went to fix the bug. The bug in the service, the users reported, was deleting files without their authorization.

Windows Live FolderShare is a feature that allows users to store files online and then download and synchronize them to and between different devices and computers. This feature is currently available in beta release.

Microsoft acknowledge the bug and said, in an email on Friday, that it has fixed the problem. The bug may have "accidentally moved" user files from their original folders into the FolderShare Trash folder, and that users should not delete files in the Trash until they are sure all of them were meant to be deleted. Microsoft also advised users on how to retrieve deleted files from the Trash folder. The statement sent to the users was also posted on the FolderShare web site.

The company said it is working to assist users who have lost their files on how to retrieve them. It also said that another online storage service that is also in beta, Windows Live SkyDrive, had not been affected by the bug.

Even after Microsoft said it has fixed the problem, users on the discussion board were still reporting buggy behavior from the service. Users noted that they were having trouble synchronizing files between computers and locating directories when using the service on Windows Vista.

Thursday, December 6, 2007

Firefox Flaw

Four days after releasing version 2.0.0.10 of Firefox 2.0, Mozilla Corp. has to scramble to release another update. For the first time, Mozilla has issued two updates to fix Firefox bugs in one week.


Firefox to Fix 'Canvas' Problem
Just four days after releasing version 2.0.0.10 of Firefox 2.0 to fix six known bugs, browser developers at Mozilla Corp had to scramble to push out another update. Version 2.0.0.11 was released, last Monday, to fix a new known bug that caused problems when the browser was rendering "canvas" HTML elements. Mozilla released the update last Friday, marking the first time Mozilla has issued two updates to the open-source browser in one week.

The most recent canvas problems were detailed last week by Mozilla, which said at the time is expected to have an update out by last Friday.

The Canvas elements were first used by Apple Inc. in its Safari browser to allow web designers to dynamically render bitmap images in HTML. Microsoft Internet Explorer does this with a plug-in, but Firefox, Safari, and Opera support Canvas natively;

Firefox 2.0.0.10 for Windows, Mac OS X, and Linux, break pages that include the Canvas element, and cripple at least two Firefox extensions, FoxSaver and Fotofox.

The new version of Firefox is available for free download on the Mozilla website.

Wednesday, December 5, 2007

PC + Mac QuickTime Flaw

Symantec warns that both Windows and Mac systems may be vulnerable to exploits of an unpatched Quicktime flaws



Windows and Mac Shares QuickTime Flaw

Last Sunday, Symantec warned in a DeepSight Threat Management System alert that attackers are trying to exploit an unpatched vulnerability in Apple's QuickTime software that could let them run code on a victim's computer.

Attackers appear to be aimed at Windows users, but Mac OS users could be open to the risk as well, as QuickTime vulnerability in question affects both operating systems. The vulnerability, called the Apple QuickTime RTSP Response Header Stack-Based Buffer Overflow Vulnerability, was first revealed on November 23, and still remains unpatched by Apple.

Windows XP and Windows Vista running Internet Explorer, Firefox, Opera, and Safari are affected by this vulnerability, as well as Apple's own MacOS X 10.4 and 10.5.

Symantec said that there are two types of attacks underway. One involves redireting the victim's computer from an adult web site, Ourvoyeur.net, to another web site that infects the computer with an application called loader.exe. It can be saved to the victim's computer as metasploit.exe, asasa.exe, or syst.exe. Once installed on a computer, this application downloads another binary file, which Symantec identified as Hacktool.Rootkit, a set of tools that can be used to break into a system. It's possible that Ourvoyer.net was compromised as part of the attack.

The second method of attack also involves redirection, however, Symantec is currently investigating the attack to determine what, if any, malicious code is involved.

To protect systems from attack, Symantec recommended blocking access to affected sites. "Filter outgoing access to 85.255.117.212, 85.255.117.213, 216.255.183.59, 69.50.190.135, 58.65.238.116, and 208.113.154.34. Additionally 2005-search.com, 1800-search.com, search-biz.org, and ourvoyeur.net should be filtered," it said, adding IT managers can also block outgoing TCP access to port 554.

Alternatively, IT managers could take more drastic steps. "As a last measure, QuickTime should be uninstalled until patches are available," the alert said.

Thursday, October 25, 2007

The Excel Bug

Microsoft has acknowledged that there is indeed a display bug in Microsoft Office 2007


Microsoft Excel Math Problem

A bug in the new Office 2007 Excel causes a number to be displayed incorrectly. Microsoft said, that under certain specific circumstances, if a calculation yields the answer 65,535, the number will be displayed at 100,000. However, Microsoft said this is just a minor bug and only affects the display, not the actual value of the number itself. So, adding one to the answer will result to 65,536. Microsoft also said that Excel knows the real number, but shows the incorrect figure.

Well, good news: If your salary is exactly $65,535 and your company handles its payroll in Excel 2007, you may be in for a big raise! You can find more information and the patch at the Microsoft Excel team blog.