Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Bugtraq
[Top] [All Lists]

Lizardtech DjVu Browser Plug-in - Multiple Vulnerabilities

Subject: Lizardtech DjVu Browser Plug-in - Multiple Vulnerabilities
Date: Thu, 15 Feb 2007 15:48:25 +1300
========================================================================
= Lizardtech DjVu Browser Plug-in - Multiple Vulnerabilities
=
= Vendor Website: 
= http://www.lizardtech.com/
=
= Affected Version:
=    Windows DjVu Browser Plug-in < 6.1.1
=
= Public disclosure on February 15th 2007
========================================================================

== Overview ==

The DjVu Browser Plug-in is the primary means of viewing DjVu documents.

It runs inside most modern browsers including IE, Firefox and Safari.

Versions prior to 6.1.1 are vulnerable to buffer overflows through
various functions. One such example is through the ExportImageAs method.

It should be noted that CERT contacted Lizardtech at about the same time

as we did, advising of numerous overflow problems as well. These have
also been addressed by this update.

== Solutions ==

- Upgrade to version 6.1.1 from the lizardtech website
        http://www.lizardtech.com/
   
== Credit ==

Discovered and advised to Lizardtech November 2006, by Brett Moore of
Security-Assessment.com

== About Security-Assessment.com ==

Security-Assessment.com is Australasia's leading team of Information 
Security consultants specialising in providing high quality Information 
Security services to clients throughout the Asia Pacific region. Our 
clients include some of the largest globally recognised companies in 
areas such as finance, telecommunications, broadcasting, legal and 
government. Our aim is to provide the very best independent advice and 
a high level of technical expertise while creating long and lasting 
professional relationships with our clients.

Security-Assessment.com is committed to security research and 
development, and its team continues to identify and responsibly publish 
vulnerabilities in public and private software vendor's products. 
Members of the Security-Assessment.com R&D team are globally recognised 
through their release of whitepapers and presentations related to new 
security research..

<Prev in Thread] Current Thread [Next in Thread>
  • Lizardtech DjVu Browser Plug-in - Multiple Vulnerabilities, Brett Moore <=