|
Brought to you by:
Suppliers of:
|
|
|
| |
| In a previously featured article, Buffer Overrun in JPEG Processing (GDI+) Allows Code Execution (MS04-028), a buffer overrun in the GDI+ library was reported. Provided below is a proof of concept example that will crash various applications attempting to open the malicious JPEG image. |
| |
Credit:
The information has been provided by GulfTech Security.
|
| |
A proof of concept JPEG image that will crash an application attempting to open/preview it on an affected platform can be downloaded from http://www.gulftech.org/?node=downloads
The vulnerability in the comment parsing of the JPEG file is similar to a previous vulnerability found almost two years ago regarding Netscape handling of JPEG images. A more thorough analysis of the code and methods of exploitation can be found at http://www.openwall.com/advisories/OW-002-netscape-jpeg/ .
Some antivirus software can detect the presence of such a malicious JPEG image since the problem is specific in nature and a signature identification can be made. McAfee's antivirus with virus definitions version 4.0.4393 or greater can detect the problem.
|
|
|
|
|