Page 1 of 1

Forum issue: Images

Posted: Wed Jan 11, 2006 12:42 am
by Rejecta
Source: http://www.classesofcamelot.com/

Normally I don't put warnings like this up on the news, since it's not really my job and I generally don't know much more than anyone else, but this one is very, very scary...

There's a flaw in Windows (yes, Mac/Linux users, go ahead and start being snide) that allows an image file, when cached and then interacted with in any way (displayed on a web page, indexed by a desktop search program, etc), to more or less take over your computer. Using Firefox makes you only marginally safer; ANY Windows user is vulnerable.

This has been showing up in forums all over the place - any site that allows users to display a signature with images could infect you. I'm working on changing the forums to make sure no one can do this via CoC (there's a good chance I'll disable use of images in signatures and possibly user avatars), but for now, there's a fix out. It's not official, but it's posted by a well-known security guru, so hopefully it's safe. Go to http://grc.com/sn/notes-020.htm to get that.

And of course this is just one more reason to have a good antivirus program and not to visit untrustworthy sites. Unfortunately now untrustworthy may also mean all forums...

Posted: Wed Jan 11, 2006 6:01 am
by Jupiler

Posted: Wed Jan 11, 2006 6:02 am
by Lieva
im a little confused.
are these img files viruses?

Posted: Wed Jan 11, 2006 6:53 am
by Kesxex
Run the Windows Update and at least some attack vectors are closed.

http://update.microsoft.com/windowsupda ... x?ln=en-us

Might not be all but there is a possibility that just viewing a picture can infect the computer but is unlikely.

Posted: Wed Jan 11, 2006 12:44 pm
by Musejedi
iirc there was a windows update (For XP) to fix this the other day.

Posted: Wed Jan 11, 2006 12:46 pm
by Mojo
Let Windows autoupdate if you use it.