Linked by Thom Holwerda on Mon 2nd Apr 2007 21:05 UTC, submitted by Dale Smoker
Windows Microsoft has decided to rush out a fix for a flaw in Windows, saying that the problem has become too serious to ignore. The flaw, which will be patched on Tuesday, was originally disclosed to Microsoft in December, but it was not publicly reported until last week. The bug lies in the way Windows processes .ani Animated Cursor files, which are used to create cartoon-like cursors in Windows.
Thread beginning with comment 226697
To read all comments associated with this story, please click here.
Pure comedy
by Laurence on Mon 2nd Apr 2007 22:03 UTC
Laurence
Member since:
2007-03-26

I know any OS, with as wide target base and as many lines of code as Windows does, is vulnerable to attack. However this has to be, by far, the funniest securiety threat i've heard to date!

(At least Microsoft are going out of their way to correct this problem though.)

Edited 2007-04-02 22:04

RE: Pure comedy
by TaterSalad on Mon 2nd Apr 2007 22:16 in reply to "Pure comedy"
TaterSalad Member since:
2005-07-06

Is it funnier than leaving telnet open?

Reply Parent Bookmark Score: 3

RE[2]: Pure comedy
by archiesteel on Mon 2nd Apr 2007 22:45 in reply to "RE: Pure comedy"
archiesteel Member since:
2005-07-02

Is it funnier than leaving telnet open?


Isn't that changing the subject?

Reply Parent Bookmark Score: 4

RE: Pure comedy
by MollyC on Mon 2nd Apr 2007 22:52 in reply to "Pure comedy"
MollyC Member since:
2006-07-04

"(At least Microsoft are going out of their way to correct this problem though.)"

They're going out of their way only because they sat on their behinds on this bug. This bug could've been patched in any of the Jan, Feb, or March updates, and there would've been no need for a rushed out-of-cycle patch. Atrocious decision making.

Edited 2007-04-02 22:53

Reply Parent Bookmark Score: 5

RE[2]: Pure comedy
by shykid on Tue 3rd Apr 2007 06:12 in reply to "RE: Pure comedy"
shykid Member since:
2007-02-22

Seriously.

Considering they knew about this bug since December 2006, "rush out a fix" makes about as much sense as saying Windows Vista was rushed out.

Reply Parent Bookmark Score: 4

RE: Pure comedy
by deathshadow on Tue 3rd Apr 2007 02:51 in reply to "Pure comedy"
deathshadow Member since:
2005-07-12

>> However this has to be, by far, the funniest
>> securiety threat i've heard to date!


Oh I don't know... the .jpg buffer overflow that effected EVERY operating system that used the reference code - meaning linux, MacOS and Windows - was a bit funnier IMHO.

I suspect this is something similar, where a programmer got lazy and didn't bother with range checking. I'm often amazed at how often programmers will try to save a few clocks by not bothering with making sure memory accesses don't go out of the expected range, especially on image decoders.

Reply Parent Bookmark Score: 1

RE: Pure comedy
by Darkelve on Tue 3rd Apr 2007 07:55 in reply to "Pure comedy"
Darkelve Member since:
2006-02-06

"However this has to be, by far, the funniest securiety threat i've heard to date!"

How about a remote, hostile takeover of clippy? :o)

Edited 2007-04-03 07:55

Reply Parent Bookmark Score: 3

RE[2]: Pure comedy
by dylansmrjones on Tue 3rd Apr 2007 08:18 in reply to "RE: Pure comedy"
dylansmrjones Member since:
2005-10-02

How about a remote, hostile takeover of clippy? :o)


Oh yeah, and use the control to kill clippy ;)

Reply Parent Bookmark Score: 2