JPHiP Forum

General => Akihabara => Topic started by: ziggurat on April 07, 2007, 03:20:57 AM

Title: Microsoft Windows Animated Cursor Buffer Overflow Vulnerability
Post by: ziggurat on April 07, 2007, 03:20:57 AM
I feel the urge to start this thread, because it affects most windows system.

A vulnerability has been discovered in Microsoft Windows, which can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to a boundary error within the handling of animated cursors and can be exploited to cause a stack-based buffer overflow via a specially crafted animated cursor file. (http://secunia.com/advisories/24659/)

Detail can be read from there, include patches, Secunia Software Inspector to check your pc for that vulnerability and others.

News:

Cursor hackers target WoW players (http://news.bbc.co.uk/2/hi/technology/6526851.stm)
Title: Re: Microsoft Windows Animated Cursor Buffer Overflow Vulnerability
Post by: frblckstr1 on April 07, 2007, 06:28:46 AM
^ That was patched like almost a week ago now.

But yes UPDATE YOUR SYSTEMS.
(and Mac users do not forget to update yours because there where like 20+ (security) patches last month alone)
Title: Re: Microsoft Windows Animated Cursor Buffer Overflow Vulnerability
Post by: ziggurat on April 07, 2007, 06:45:14 AM
^ Yeah, but not everyone use auto update. Like me. And not everyone is geek like you to discover this by themselves.
Title: Re: Microsoft Windows Animated Cursor Buffer Overflow Vulnerability
Post by: ebc on April 07, 2007, 06:59:29 AM
^ That was patched like almost a week ago now.
Actually more like 2 years ago but they forgot that they had done it
http://it.slashdot.org/article.pl?sid=07/04/06/2043211

hehe anyway, I've been having more problems with people calling me up complaining about an update they did that was causing an error to appear on the screen each time they booted up.
Everyone with the Realtek HD audio control panel actually and that's a lot of people.
http://it.slashdot.org/article.pl?sid=07/04/04/1256229

Many hours spent on phone guiding grandma's and angry mum's through getting the hotfix.
Title: Re: Microsoft Windows Animated Cursor Buffer Overflow Vulnerability
Post by: frblckstr1 on April 07, 2007, 07:32:26 AM
^ :) yup on both the above (had the realtek problem also on one machine, the hotfix is now directly downloadable)
Title: Re: Microsoft Windows Animated Cursor Buffer Overflow Vulnerability
Post by: ziggurat on April 07, 2007, 08:02:59 AM
@frblckstr1:

Sorry for being like a bitch -_-" I don't know what i was thinking when i'm posting that reply to you.

Really sorry.