Re: libpng exploit.. possible interim fix?

From: Karl Levinson [x y] mvp (levinson_k_at_despammed.com)
Date: 08/20/04


Date: Fri, 20 Aug 2004 06:04:05 -0400


"Mark Miller" <markhmiller__@juno.com> wrote in message
news:905401c48606$79e45770$a501280a@phx.gbl...

> For what it's worth, going into the recovery console and
> manually renaming pngfilt.dll to, e.g., pngfilt_.dll
> bypasses the problem at the cost of not being able to
> view .png files in IE. Since .png graphics are not nearly
> as popular as .gif and .jpg, until Microsoft bothers to
> advise US-CERT with something more than "unknown" (see
> link below), I'll assume the browser is vulnerable and
> just live without .png file viewing from within IE.

FWIW, Microsoft appears to have a policy that they avoid discussing
vulnerabilities in most cases until a patch is available. I would guess
they feel that acknowledging a vulnerability before there is a fix puts you
the user at additional risk. There is some merit to that. Also, this is a
relatively new vulnerability, and I can't blame Microsoft for not releasing
a patch yet.

Part of the blame lies on security investigators who announce a
vulnerability to the world without first contacting the vendor privately to
give them a reasonable amount of time to fix the problem without impact to
the customer. Security investigators that don't do that are endangering
Internet users like you and me. Microsoft can code a fix for things in
minutes or hours in some cases, but if they released that patch and it broke
something on your system, you and millions of other people would be pretty
upset. When there are serious vulnerabilities, work can happen round the
clock at Microsoft as needed. But most of the delay on making patches is
probably usually beta testing the patches, and if a problem is found, then a
new beta would probably have to be started.



Relevant Pages

  • SecurityFocus Microsoft Newsletter #176
    ... MICROSOFT VULNERABILITY SUMMARY ... Microsoft Windows XP HCP URI Handler Arbitrary Command Execu... ... PHPNuke Category Parameter SQL Injection Vulnerability ... Microsoft Baseline Security Analyzer Vulnerability Identific... ...
    (Focus-Microsoft)
  • SecurityFocus Microsoft Newsletter #83
    ... MICROSOFT VULNERABILITY SUMMARY ... Microsoft IIS CodeBrws.ASP Source Code Disclosure Vulnerability ... Microsoft Internet Explorer History List Script Injection ... Microsoft Windows 2000 Lanman Denial of Service Vulnerability ...
    (Focus-Microsoft)
  • SecurityFocus Microsoft Newsletter #81
    ... MICROSOFT VULNERABILITY SUMMARY ... WWWIsis Remote Command Execution Vulnerability ... Windows NT 4.0 Print Spooler Security ...
    (Focus-Microsoft)
  • Re: [Full-disclosure] Security Alert: Unofficial IE patches appear on internet
    ... created by a vulnerability is as serious as this case and the available ... Microsoft will be inclined strongly against holding on to this patch. ... Microsoft often have patches ready but wait for the corporate known ...
    (Full-Disclosure)
  • SecurityFocus Microsoft Newsletter #336
    ... MICROSOFT VULNERABILITY SUMMARY ... Microsoft Windows Unspecified Remote Code Execution Vulnerability ... Microsoft Windows Explorer BMP Image Denial of Service Vulnerability ... An attacker could leverage this issue to have arbitrary code execute with kernel level privileges. ...
    (Focus-Microsoft)