Latest IE hole :: PNG Vulnerability :: Other Apps

| | TrackBacks (0)

Cumulative Patch for Internet Explorer :: Microsoft TechNet
Note as usual this affects multiple components, not just IE. If you're on the redmond hobby-horse, get patching.

A buffer overrun vulnerability that occurs because Internet Explorer does not correctly check the parameters of a PNG graphics file when it is opened.

PNG (Portable Network Graphics) Deflate Heap Corruption Vulnerability

During a review of the PNG image format implemented in Microsoft Windows, two separate vulnerabilities were discovered related to the interpretation of PNG image data. The first vulnerability deals with the handling of the IDAT header and does not appear to be of significant threat level. The second vulnerability can be exploited to execute code when the malicious PNG image is viewed. Due to the complexity of each of these vulnerabilities we have decided only to describe the latter in detail.

0 TrackBacks

Listed below are links to blogs that reference this entry: Latest IE hole :: PNG Vulnerability :: Other Apps.

TrackBack URL for this entry: http://kennethhunt.com/mt/mt-tb.cgi/486

About this Entry

This page contains a single entry by klsh published on December 11, 2002 9:46 PM.

Home Page Table-less Layout was the previous entry in this blog.

Elihu Vedder: rubaiyat is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.