By Alan DonalyPosted Wednesday 17th October 2007 06:03 GMT
Nothing to do with this story i don't guess but when I ran my mouse over the ms ad the title read "gratuitous monkey skull" which is the alt/title from my own sites bottom graphic and I haven't gone there this session fire fox maybe needs some work or perhaps it's a feature.
By Anonymous CowardPosted Wednesday 17th October 2007 12:46 GMT
The source code for this patch reveals it to have what as far as I can tell is a serious and very likely exploitable heap buffer overflow. I'll be posting a longer analysis later when I've had a chance to polish it up, but the underlying bug, in case anyone wants to take a look for themselves is in an algorithmic error: the author repeatedly tries to convert the count of WCHARs in a string into a size in bytes by dividing by the size of a WCHAR instead of multiplying it, which produces a result that is only a quarter of what it should be. Check the way cbPrefix is miscalculated and then used later to size a heap buffer that is LocalAlloc'd and, I'm fairly sure, the reassembled url gets written right over the end of this buffer and into trailing heap space.
By Morely DotesPosted Wednesday 17th October 2007 16:58 GMT
"Redmond's planned patch, whose release date remains unclear, is targeted at Windows Server 2003 and Windows XP with Internet Explorer 7 installed. Vista "
What about Vista? Perhaps the rest of the sentence would go something along the lines of, "Vista is not so much an Operating System, as a chocolate teapot, and since it can't be reasonably expected to do anything useful, may safely be ignored when applying Operating System patches."
By Ian EmeryPosted Wednesday 17th October 2007 17:36 GMT
I cant even install the LAST security update; every time I have done so, my PC wont start on reboot and I have to revert to "Last Known Good Configuration".
Lucky I use Firefox for everything except Windows Update which, despite M$ claims to the contrary WONT work with anything other than IE
Comments on: Researcher releases unofficial IE fix for URI bug
I just noticed something #
By Alan Donaly Posted Wednesday 17th October 2007 06:03 GMT
I noticed something even more interesting... #
By Anonymous Coward Posted Wednesday 17th October 2007 12:46 GMT
wow! AC - icon choice ;-) #
By Dave Posted Wednesday 17th October 2007 14:52 GMT
Vista? #
By Chris Clawson Posted Wednesday 17th October 2007 16:28 GMT
What about Schmidt? Er, I mean, Vista? #
By Morely Dotes Posted Wednesday 17th October 2007 16:58 GMT
IE 7 ?? PAH !!!! #
By Ian Emery Posted Wednesday 17th October 2007 17:36 GMT