Go Back   Wireless and Wifi Forums > News > Newsgroups > comp.security.misc
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 01-16-2008, 06:56 PM
Zakko
Guest
 
Posts: n/a
Default Can font files be dangerous

Some web sites talk about their fonts files as being clean or checked.

Does this mean some types of font file can be infected with malware?

Reply With Quote
  #2 (permalink)  
Old 01-16-2008, 07:23 PM
Dick Margulis
Guest
 
Posts: n/a
Default Re: Can font files be dangerous

Zakko wrote:
> Some web sites talk about their fonts files as being clean or checked.
>
> Does this mean some types of font file can be infected with malware?


Fonts can be malformed in a number of ways that create problems for the
user. Probably the most obvious is an older font that is far enough out
of spec that recent versions of Windows will refuse to load it. I'm not
aware of fonts carrying malware, so I would just read those as product
benefit claims--our fonts are high quality, basically.

Reply With Quote
  #3 (permalink)  
Old 01-16-2008, 08:36 PM
Sebastian G.
Guest
 
Posts: n/a
Default Re: Can font files be dangerous

Dick Margulis wrote:

> I'm not aware of fonts carrying malware, so I would just read


> those as product benefit claims--our fonts are high quality, basically.


I remember a bug in a webbrowser causing a buffer overflow with specially
crafted font files. Now, that was Netscape 4.0, which is quite a long time ago.

Without a bug, there's no specified way to include executable code in font
files.

Reply With Quote
  #4 (permalink)  
Old 01-16-2008, 09:06 PM
David H. Lipman
Guest
 
Posts: n/a
Default Re: Can font files be dangerous

From: "Zakko" <scruff@mail.invalid>

| Some web sites talk about their fonts files as being clean or checked.
|
| Does this mean some types of font file can be infected with malware?

Font files are none malicious.

However, there are Trojans that will hide in the Windows font folder.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



Reply With Quote
  #5 (permalink)  
Old 01-16-2008, 10:38 PM
Character
Guest
 
Posts: n/a
Default Re: Can font files be dangerous

Zakko wrote:

> Some web sites talk about their fonts files as being clean or checked.
>
> Does this mean some types of font file can be infected with malware?


No, but I've accidentally created some otf fonts that, if
double-clicked, for some inexplicable reason result in a BSOD (Blue
Screen of Death)! No harm done, just very annoying.

- Character

Reply With Quote
  #6 (permalink)  
Old 01-16-2008, 11:46 PM
Sebastian G.
Guest
 
Posts: n/a
Default Re: Can font files be dangerous

Character wrote:


>> Does this mean some types of font file can be infected with malware?

>
> No, but I've accidentally created some otf fonts that, if
> double-clicked, for some inexplicable reason result in a BSOD (Blue
> Screen of Death)! No harm done, just very annoying.


Is your system up-to-date wrt. security updates? Did you install any
security relevant font management software?

If the answer to the first question is "yes" and to the second "no", you
should definitely report this issue to Microsoft.

Reply With Quote
  #7 (permalink)  
Old 01-17-2008, 12:16 AM
Character
Guest
 
Posts: n/a
Default Re: Can font files be dangerous

Sebastian G. wrote:

> Character wrote:
>
>
>>> Does this mean some types of font file can be infected with malware?

>>
>>
>> No, but I've accidentally created some otf fonts that, if
>> double-clicked, for some inexplicable reason result in a BSOD (Blue
>> Screen of Death)! No harm done, just very annoying.

>
>
> Is your system up-to-date wrt. security updates? Did you install any
> security relevant font management software?
>
> If the answer to the first question is "yes" and to the second "no", you
> should definitely report this issue to Microsoft.


Yes, no, and I did :)

Reply With Quote
  #8 (permalink)  
Old 01-17-2008, 02:23 PM
Larry A Barowski
Guest
 
Posts: n/a
Default Re: Can font files be dangerous


"Character" <Char@cters.bold.italic> wrote in message
news:Uzwjj.6$tQ1.1@en-nntp-03.dc1.easynews.com...
> Zakko wrote:
> No, but I've accidentally created some otf fonts that, if double-clicked,
> for some inexplicable reason result in a BSOD (Blue Screen of Death)! No
> harm done, just very annoying.


I've created buggy fonts that did that on Windows NT,
but they failed safely on XP. As I was writing hint code
directly, I knew the exact reason, but I can't recall what
it was.

I have accidentally put what, at certain resolutions, was
an infinite loop into a TTF hint. Some renderers will just
go ahead and loop infinitely if you do that.



Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Can font files be dangerous Zakko alt.computer.security 7 01-17-2008 02:23 PM
Doctor Who's security & encryption FAQ v21.4 newsmanis@yahoo.com.au alt.computer.security 0 10-10-2007 09:34 PM
SSRT4884 rev.6 - HP-UX TCP/IP Remote Denial of Service (DoS) Security Alert comp.security.misc 0 08-16-2005 04:48 PM
SSRT4884 rev.5 - HP-UX TCP/IP Remote Denial of Service (DoS) Security Alert comp.security.misc 0 07-25-2005 06:15 PM
SSRT4884 rev.4 - HP-UX TCP/IP Remote Denial of Service (DoS) Security Alert comp.security.misc 0 07-12-2005 11:28 AM


All times are GMT. The time now is 12:27 PM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45