Why you should switch to Firefox now

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

TECH GUIDE

Can you imagine the Internet without pictures? A new flaw in the way Windows, and therefore Internet Explorer, renders JPEG images -- one of the most common image formats on the Web--should make you think twice about whether you should display them. At the very least, it should nudge you into considering an alternative Internet browser, such as Firefox.

The code to exploit this flaw is now public. Usually, exploit code release is the first step toward a new virus or worm, and as we have seen before, the time from exploit to virus is generally about two to three weeks. In other words, the clock is ticking.

The GDIplus vulnerability
If you use a Windows operating system older than Windows 2000 or have already updated to Windows XP SP2, you're immune to the flaw. There are many ways to render JPEGs, but the Graphic Device Interface plus DLL, or gdiplus.dll, is enabled only in Windows 2000 and Windows XP. Because gdiplus.dll is vulnerable to a buffer overflow attack, malicious code lurking inside an infected JPEG file could allow new, potentially malicious code to take over the use of your computer (or, at the very least, crash it). Unfortunately, the applications that run in Windows 2000 and XP are also vulnerable.

Microsoft Office is vulnerable
The list of these vulnerable programs is not short and includes:

  • Microsoft .Net Framework 1.x
  • Picture It Digital Image Pro 7.x and 9.x
  • Digital Image Suite 9.x
  • FrontPage 2002
  • Greetings 2002
  • Internet Explorer 6.0
  • Office 2003 Professional Edition
  • Office 2003 Small Business Edition
  • Office 2003 Standard Edition
  • Office 2003 Student and Teacher Edition
  • Office XP
  • Outlook 2003 and 2002
  • Picture It 2002, 7.x, and 9.x
  • PowerPoint 2002 and PowerPoint 2003
  • Project 2002 and Project 2003
  • Publisher 2002
  • Visio 2002, Visio 2003
  • Visual Studio .Net 2002 and 2003
  • Word 2002

Now, what happens if you patch your system with Windows XP SP2, and then load one of the above applications? Believe it or not, the potential exists for that program to overwrite the patched gdiplus.dll with an older, more vulnerable version. You can see what a nightmare this has become already. Thus, Microsoft has posted a free online tool to assess the current vulnerability of your computer.

What if you don't use Microsoft applications on your Windows computer? Surprisingly, your solution might be even more complicated.

Macromedia products not vulnerable
Some non-Microsoft programs, such as those from Macromedia, also regularly use JPEG files. It turns out that some Macromedia applications do install the vulnerable gdiplus.dll, but they actually use the Microsoft graphics library instead to process JPEGs. As a result, products such as Macromedia Contribute, Dreamweaver, Fireworks, Flash, Flashpaper, FreeHand, RoboSource Control and Studio MX are not affected by the GDI flaw. Nonetheless, if you do load any of these programs after you've patched your system, make sure they don't overwrite the patched version of gdiplus.dll. To find out more about software vulnerability to this flaw, see this US-CERT document for more details.

Upgrade to Windows XP or else, says Microsoft
In a separate but related development, Microsoft announced that future security enhancements for its Internet Explorer will be available through its Windows XP update service only. By refusing to offer separate security enhancements for Internet Explorer, which is the main vector for any JPEG-related worm or virus, Microsoft is essentially saying that anyone who hasn't yet upgraded to Windows XP won't be protected from future exploits. Amazon charges £75 for upgrading to Windows XP Home and £144 to upgrade to the Professional Edition.

Firefox is a start but not the whole solution
If you've taken my past advice, you've already bailed out from Internet Explorer and installed Mozilla's Firefox as your default Internet browser. For the most part, you can avoid the JPEG flaw, right? Wrong. Because Microsoft bundles IE deep within Windows, you can't avoid IE by not using it. For example, say you get an HTML email message from someone that includes a JPEG image. If you're using Outlook 2002 or earlier, it calls on IE to render that image. The same is true for Microsoft Word and other Office applications that offer a Web view. Outlook 2003 at least gives you the option of viewing an image or not, but should you choose to view it, Outlook 2003 will still call IE. You can remove Internet Explorer from Windows, but it would take a column twice as long as this to cover all the Registry settings and such you'd need to tweak to do so. Want to move over to Firefox? You can download it here.

Talkback

Thanks for the info folks.
I switched to Firefox after my WindowsXP Pro & Home systems crashed five times in three weeks. Each time it required a complete re-install of all Win programs and the resetting of all preferences, etc., to recover, only to have it crash again the next time I used Internet Explorer. Thankfully, I was able to get a download of Mozilla Firefox, which took only a short while. Firefox is to IE what the Wright Brothers are to a Boeing747! It cruises the net beautifully, has brilliant tab features, and seems impervious to whatever it is that plagues the WinXP/IE combination. I've had absolutely no trouble and even felt confident enough in Firefox to uninstall the 25mgs of front line defence it took to daily protect IE. My system runs much faster on the net and has been wonderfully stable ever since. Firefox Rules!

via Facebook 30 September, 2004 19:35
Reply

Thank you for the usual very informative newsletter. I abandoned the virtually useless IE long since and have been using Opera (now 7.50j) - you stop looking when you have found what you want, and Opera is the best I have tried!

via Facebook 2 October, 2004 12:00
Reply

I read your article on firefox and the problems with Internet Explorer, and the mist cleared aha I thought so I downloaded Firefox and I aint looking back thanks a lot guys you have fixed most of my problems . Alistair Cruickshank

via Facebook 16 October, 2004 14:19
Reply

But there is no sound in Firefox visiting web pages?!

via Facebook 19 November, 2004 00:07
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Jack Strain

Just gimme a map to the fridge. :D

2 hours ago by Jack Strain via Facebook on Indoor navigation coming to a mobile near you soon
dede0202

Hello ALL USERS OF THE PIRATE BAY I WOULD PUT AN EXPLANATION ON PIRACY Story Idea ILLIGALE AND SHARING THOSE THAT NET Dissent NOT WELL BUT TO CA...

11 hours ago by dede0202 on The Pirate Bay infringes copyright, High Court decides
Sungwoo

do You know that? it can install 4G Ram. So i buy 4g and install It work! I can run call of duty 4,6,7 [Modern war... 1,2,3] Call of duty 1 was...

11 hours ago by Sungwoo on Loose Ends - Upgrading the Aspire One 522
itsajob

2. Bad idea. Making up patch cables loses you your commission from the cable supplier. 3. If you tidy up, other people can understand where the...

17 hours ago by itsajob on Ten IT jobs to save up for those rare lulls
Roberto_Store

Now On Sale, Unlocked iPhone 4S / Galaxy Note In Factory Box. Roberto-Techie(UK) ”Now on Sales” Smartphone, Android,Tablets,Gadget &...

21 hours ago by Roberto_Store on Samsung Galaxy S III lined up for sale
Paul Smyth

Is this classic FUD? One thing I would definitely have notice is a Mozilla threat to stop supporting GNU/Linux.

23 hours ago by Paul Smyth via Facebook on Firefox rapid release improves Fedora Linux
UnderINK

I agree with the previous commenter wholeheartedly. I couldn't say it better myself. This is very 'Big Brother'. And while I agree with protecting...

1 day ago by UnderINK on European e-identity plan to be unveiled this month
Simon Bisson and Mary Branscombe

Nice to see that Turing's idea of a general purpose computer doing once-hardware-powered tasks in software is now universal ;-) Mary

1 day ago by Simon Bisson and Mary Branscombe on Software with everything
Jason Burchell

seriously now. I've only bothered to read a small bit of the comments. do me and the rest of the world a favour. stop saying it does not work or...

2 days ago by Jason Burchell via Facebook on Music industry negotiating over 24-bit downloads
Philip Charles Cohen

Read about it and weep, John Donahoe ... In addition to Visa’s V.me, there is now MasterCard’s PayPass digital wallet soon to arrive; another...

2 days ago by Philip Charles Cohen via Facebook on PayPal takes phone-based payments to the high street
apexwm

Leslie Satenstein : Where have you ever seen Mozilla even mention this? Firefox is the most popular browser in the GNU/Linux OS, so I don't see...

2 days ago by apexwm on Firefox rapid release improves Fedora Linux
songmaster

SHleG: Do you remember building a clockwork scorpion kit (I'm pretty sure I have a photo of it somewhere) — I think it was called something like...

2 days ago by songmaster on Software with everything
Chris Wortman

Good I love Yahoo! Their search engine is getting better than Google as of late. I find more of what I want on the first page, and usually within...

2 days ago by Chris Wortman via Facebook on Linux Mint 13 ramps up for KDE release
PatrickG

openhgs has made the point for Windows 8 multiple monitors without realising it! With Windows 7 you have to switch the mouse and so your focus...

2 days ago by PatrickG on Windows 8 could speed multi-monitor uptake
Leslie Satenstein

Mozilla has threatened to stop supporting Linux. I guess that UBUNTU is going with another browser. I indicated that if Mozilla stops supporting...

2 days ago by Leslie Satenstein via Facebook on Firefox rapid release improves Fedora Linux
Andy Bolstridge

Much as I abhor Microsoft's licensing practices, this is almost certainly down to purchasing IT equipment via 3rd party consultants - you get the...

2 days ago by Andy Bolstridge via Facebook on 6 million wasted licences and £1,200 PCs: welcome to government IT
Jack Schofield

@openhgs Windows users have had multiple desktops since Linus started writing Linux. They just haven't shipped as standard because not enough...

3 days ago by Jack Schofield on Windows 8 could speed multi-monitor uptake
Jack Schofield

@Phil at Cloud4 What, Microsoft gets £1,200 per PC and £1,622 per server? Gosh, I'm amazed....

3 days ago by Jack Schofield on 6 million wasted licences and £1,200 PCs: welcome to government IT
craigsc

You guys have no idea what is going on at Autonomy. Autonomy could have been a much more profitable organization. The sales operations at Autonomy...

3 days ago by craigsc on HP cuts 27,000 staff as Autonomy chief Lynch leaves
Moley

How does this impact on dual or multi booting? Seems to me to more or less prohibit this, from Windows 8 anyway. Will Grub 2 recognise Windows 8,...

3 days ago by Moley on Windows 8 start-up speed forces USB boot workaround