Serious Security Bug In Microsoft Word and Microsoft MSN Messenger *update w/patch*

skace

Lifer
Jan 23, 2001
14,488
7
81
So wait, A malicious hacker could write up a malicious word document with a link that, when clicked, opens up a text file forcing my workstation to open notepad?! Am I understanding this right....
 

CTho9305

Elite Member
Jul 26, 2000
9,214
1
81
Originally posted by: skace
So wait, A malicious hacker could write up a malicious word document with a link that, when clicked, opens up a text file forcing my workstation to open notepad?! Am I understanding this right....

It's just as bad as the Mozilla "Serious Security Bug". You can do a shell:foo.grp, where "foo" is a really long string, and then, as described here, the program windows launches has a buffer overflow in the code that reads the filename passed to it. I tried it myself and successfullly crashed the msgrp.exe application, though I don't feel like consturcting an actual malicous string as that would take a long time, and prove nothing.

If this isn't a serious bug, Ameesh needs to edit his thread topic, since it's no more serious in Mozilla's product, and his post is libelous.
 

AnthraX101

Senior member
Oct 7, 2001
771
0
0
Originally posted by: CTho9305
Originally posted by: skace
So wait, A malicious hacker could write up a malicious word document with a link that, when clicked, opens up a text file forcing my workstation to open notepad?! Am I understanding this right....

It's just as bad as the Mozilla "Serious Security Bug". You can do a shell:foo.grp, where "foo" is a really long string, and then, as described here, the program windows launches has a buffer overflow in the code that reads the filename passed to it. I tried it myself and successfullly crashed the msgrp.exe application, though I don't feel like consturcting an actual malicous string as that would take a long time, and prove nothing.

If this isn't a serious bug, Ameesh needs to edit his thread topic, since it's no more serious in Mozilla's product, and his post is libelous.

You were correct with your first statement. It is a variant of the same underlying bug that was "patched" in Firefox.

AnthraX101
 

Bloodstein

Senior member
Nov 8, 2002
343
0
0
Originally posted by: BingBongWongFooey
But it's a firefox bug!

Firstly, whether or not the bug is of firefox or the underlying operating system is up for debate (Interesting point: the same firefox program on linux doesn't produce the bug :)). Secondly, the topic here is not the bug in firefox but MSN/Word. How you managed to link the bug in MSN/Word to firefox is totally beyond my imagination. It's a bug in MSN & Word whether you have Firefox or not!
 

AFB

Lifer
Jan 10, 2004
10,718
3
0
Originally posted by: Bloodstein
Originally posted by: BingBongWongFooey
But it's a firefox bug!

Firstly, whether or not the bug is of firefox or the underlying operating system is up for debate (Interesting point: the same firefox program on linux doesn't produce the bug :)). Secondly, the topic here is not the bug in firefox but MSN/Word. How you managed to link the bug in MSN/Word to firefox is totally beyond my imagination. It's a bug in MSN & Word whether you have Firefox or not!

lol, He was being sarcastic.
 

Ulukai

Member
Nov 29, 2003
28
0
0
Originally posted by: Bloodstein
Originally posted by: BingBongWongFooey
But it's a firefox bug!

Firstly, whether or not the bug is of firefox or the underlying operating system is up for debate (Interesting point: the same firefox program on linux doesn't produce the bug :)). Secondly, the topic here is not the bug in firefox but MSN/Word. How you managed to link the bug in MSN/Word to firefox is totally beyond my imagination. It's a bug in MSN & Word whether you have Firefox or not!


As amdfanboy said he was being sarcastic, go read the Firefox bug thread ;)

Also it's pretty easy to link the firefox and MSN/Word bugs since it's the same damn bug! The Firefox patch just prevents people exploiting this bug in Windows through Firefox.