MSIE 5 favicon bug

From: Flavio Veloso (flaviovsat_private)
Date: Mon May 03 1999 - 12:06:10 PDT

  • Next message: Przemyslaw Frasunek: "Re: Buffer overflow in ftpd and locate bug"

    Hi folks.
    
    When MSIE 5 users bookmark a page, the browser will request a file
    named "favicon.ico" which is to be used in the "Favorites" menu of the
    browser. Unfortunately MSIE 5 doesn't check the file integrity and
    crash if faced with a bad-formed icon file.
    
    Upon crashing the stack gets filled with information from the icon
    file itself, so it may be possible to run code on the client machine,
    tough I didn't test it.
    
    Microsoft was notified twice about this issue via the "Report a Bug"
    form on their web site. The first time about one month ago, the second
    time about two weeks ago. I didn't receive back any reply.
    
    More information about this bug (plus another privacy issue about the
    "favicon.ico" file) is available at
    http://web.cip.com.br/flaviovs/sec/favicon/index.html.
    
    --
    Flavio
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:44:42 PDT