News Image flaw pierces PC security

Discussion in 'Article Discussion' started by GreatOldOne, 6 Aug 2004.

  1. GreatOldOne

    GreatOldOne Wannabe Martian

    Joined:
    29 Jan 2002
    Posts:
    12,092
    Likes Received:
    112
    Now pictures could be the perpetrators of attacks - and it looks like nobody's safe. This from News.com:

    Six vulnerabilities in an open-source image format could allow intruders to compromise computers running Linux and may allow attacks against Windows PCs as well as Macs running OS X.

    The security issues appear in a library supporting the portable network graphics (PNG) format, used widely by programs such as the Mozilla and Opera browsers and various e-mail clients. The most critical issue, a memory problem known as a buffer overflow, could allow specially created PNG graphics to execute a malicious program when the application loads the image.

    Among the programs that use libPNG and are likely to be affected by the flaws are the Mail application on Apple Computer's Mac OS X, the Opera and Internet Explorer browsers on Windows, and the Mozilla and Netscape browsers on Solaris, according to independent security researcher Chris Evans, who discovered the issues. Apple and Microsoft could not immediately be reached for comment. Evans did not test every platform to check which vulnerabilities work, he said.


    More here

    What's next? Malicious Movies?
     
  2. Guest-16

    Guest-16 Guest

    REF: See "Induce Act".
     
  3. Lorquis

    Lorquis lorquisSpamCount++;

    Joined:
    8 Sep 2002
    Posts:
    5,428
    Likes Received:
    106
    REF: See "Dodgy pr0n downloaded from kazaa"
     
  4. Xen0phobiak

    Xen0phobiak SMEGHEADS!

    Joined:
    8 Aug 2002
    Posts:
    3,847
    Likes Received:
    18
    I've known media player call up webpages from playing certain video files.
     
  5. Wolfe

    Wolfe What's a Dremel?

    Joined:
    7 Sep 2003
    Posts:
    776
    Likes Received:
    1
    ROFLAMO :D

    Cough... Winamp... Cough

    A virus that spreads through MP3 files. Thats a scary idea.
     
  6. jezmck

    jezmck Minimodder

    Joined:
    25 Sep 2003
    Posts:
    4,456
    Likes Received:
    36
    bet MS released this to the press (because their crappy browser doesn't support PNGs)
     
  7. dmcm01

    dmcm01 Banned

    Joined:
    15 Aug 2004
    Posts:
    444
    Likes Received:
    0
    lmao i can see bill gates running around on the streets with his little pres release shouting desperatly 'LOOK LOOK, THEY HAVE PROBLEMS TOO' 'COME BACK TO MICROSOFT, WE DONT EVEN SUPPORT PGN!!!' :D
     
  8. DeX

    DeX Mube Codder

    Joined:
    22 Jul 2002
    Posts:
    4,152
    Likes Received:
    3
  9. quack

    quack Minimodder

    Joined:
    6 Mar 2002
    Posts:
    5,240
    Likes Received:
    9
    It does support PNGs, it just does it badly. No alpha transparency, which is one of its best features!
     
  10. jezmck

    jezmck Minimodder

    Joined:
    25 Sep 2003
    Posts:
    4,456
    Likes Received:
    36
    the support doesn't really count in my opinion - as a demo, look at http://www.jazzle.co.uk/2005 (using IE of course)- grey block?! that's not supposed to be there! (I know there are work-arounds)
     
  11. quack

    quack Minimodder

    Joined:
    6 Mar 2002
    Posts:
    5,240
    Likes Received:
    9
    Microsoft needs to fix its PNG support, why they insist on ignoring the pleas of thousands of webmasters demanding full support is beyond me. It cannot be that hard to implement surely! They managed full GIF and JPEG support after all.

    Maybe it's something to do with hating open software. PNG is an open format after all, no patents to worry about.
     
Tags: Add Tags

Share This Page