Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: WMF Exploit |
|---|---|
| Date: | Wed, 28 Dec 2005 17:01:58 -0600 |
CERT now has posted Vulnerability Note VU#181038, "Microsoft Windows may be vulnerable to buffer overflow via specially crafted WMF file" (http://www.kb.cert.org/vuls/id/181038). The note provides additional details about the exploit and its effects. Very few workarounds have been proposed other than blocking at the perimeter and possibly remapping the .wmf extension to some application other than the vulnerable Windows Picture and Fax Viewer (SHIMGVU.DLL). Bill... -----Original Message----- From: davidribyrne@yahoo.com [mailto:davidribyrne@yahoo.com] Sent: Wednesday, December 28, 2005 4:18 PM To: bugtraq@securityfocus.com Subject: WMF Exploit Another quick observation, again, I apologize if this information has already been posted; I haven't been able to read all the posts today. The thumbnail view in Windows Explorer will parse the graphics files in a folder, even if the file is never explicitly opened. This is enough to trigger the exploit. Even more frightening is that you don't have to use the thumbnail view for a thumbnail to be generated. Under some circumstances, just single-clicking on the file will cause it to be parsed. David Byrne
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | PhpDocumentor <= 1.3.0 rc4 Arbitrary remote/local inclusion, retrogod |
|---|---|
| Next by Date: | RE: [Full-disclosure] Someone wasted a nice bug on spyware..., Jim Serino |
| Previous by Thread: | WMF Exploit, davidribyrne |
| Next by Thread: | RE: WMF Exploit, Bill Busby |
| Indexes: | [Date] [Thread] [Top] [All Lists] |