Page is a not externally linkable
- Microsoft
-- (deprecated) Microsoft Windows OS (XP/NT/Vista)
---- "Extremely Critical " Secunia Advisory


kaled - 4:41 pm on Dec 30, 2005 (gmt 0)


I just had a quick look at registry stuff (mime types, etc.) and it looks to me that .BMP, .ICO, .GIF, and .JPG files might also be affected (under XP - haven't checked other versions).

If I am correct, you would not even have to visit a website to get infected - if the favicon of a website were downloaded and rendered (e.g. by opening a bookmarks menu) then that would be sufficient - it's scary stuff! This might mean that IE is actually more secure than Firefox (since IE doesn't bother downloading icons very often) - now that really would be ironic if true.

Kaled.


Thread source:: http://www.webmasterworld.com/microsoft_windows_os/357.htm
Brought to you by WebmasterWorld: http://www.webmasterworld.com