Microsoft cursor flaw may affect Firefox users

The animated cursor vulnerability in Windows could also affect those using Firefox on Windows machines, according to one of the security researchers who discovered the flaw.

Alexander Sotirov, a researcher for security company Determina, said in an e-mail to security flaw mailing list Full Disclosure that while there was no vulnerability in the Firefox source code itself, a hacker can exploit the Windows flaw through its application programming interface (API) for Firefox. "Firefox uses a Windows API function which uses the vulnerable code in USER32.DLL, so the .ani vulnerability can be exploited through Firefox," Sotirov wrote.

The flaw -- also known as the .ani stack overflow vulnerability -- was made public by Microsoft on Thursday last week. By Friday there were reports of widespread exploits, and Microsoft issued a patch -- detailed in the MS07-017 security bulletin -- a week early, out of its monthly cycle of patching on a Tuesday. The vulnerability affects both Windows XP Service Pack 2 and Vista.

Sotirov said that installing the MS07-017 patch would protect both Internet Explorer and Firefox users against the .ani stack overflow vulnerability, and that he would delay releasing exploit code that could be used against people using Firefox on Windows machines until users had been given a chance to install the Microsoft patch.

Sotirov was adamant that the problem did not lie with the Firefox source code itself. "There is no vulnerability for the Firefox developers to patch. I recommend that they limit their use of the Windows API to avoid being affected by the next Windows vulnerability, but this is application hardening, not a vulnerability fix."

Mozilla Foundation, which heads the development of Firefox, did not comment by press time.

Tom Espiner reported for ZDNet UK from London

Advertisement

Talkback 2 comments

    windows security "fix" Anonymous -- 05/04/07

    I've installed the security update on a number of different types of PC's (laptops and desktops, of different brands. all running up-to-date XP pro) and since the update i have found that an error occurs on start up in re: to a dll file used by the Realtek control panel. making it impossible to open the control panel.
    -has anyone else encounter this issue?

    Patch for Realtek patch bug Anonymous -- 05/04/07 (in reply to #320077402)

    See here...

    http://support.microsoft.com/kb/935448/

Add your opinion

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal Sick of broken tender sites
    Some of the state governments desperately need to invest in more user-friendly tender sites so that looking for information on government tenders doesn't have to be a game of blind man's bluff.
  • Array Cyberwar: What is it good for?
    In this week's episode, Cyberwar. What is Australia's place in the world of digital warfare? What are the implications for the NBN?
  • Array Is wholesale-only backhaul just a pipedream?
    The potential acquisition of Pipe Networks by SP Telemedia has raised the question about whether vertically integrated backhaul providers will mean higher wholesale prices for ISP customers.
  • More blogs »

Tags

Back to top

Featured