Search the archives!
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Full-disclosure] More information on ZERT patch for ANI 0day
- From: james.mailing at gmail.com (James (njan) Eaton-Lee)
- Subject: [Full-disclosure] More information on ZERT patch for ANI 0day
- Date: Mon, 02 Apr 2007 17:17:48 +0100
Gadi Evron wrote: > Although eEye has released a third-party patch that will prevent the > latest exploit from working, it doesn't fix the flawed copy routine. It > simply requires that any cursors loaded must reside within the Windows > directory (typically C:\WINDOWS\ or C:\WINNT\). This approach should > successfully mitigate most "drive-by's," but might be bypassed by an > attacker with access to this directory. I'm thinking that an attacker with write access to %systemroot% probably has juicier, simpler targets to attack (which potentially let them run code in a higher security context) than animated cursors. - James. -- James (njan) Eaton-Lee | UIN: 10807960 | http://www.jeremiad.org "All at sea again / And now my hurricanes Have brought down this ocean rain / To bathe me again" https://www.bsrf.org.uk | ca: https://www.cacert.org/index.php?id=3 -- -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/x-pkcs7-signature Size: 3521 bytes Desc: S/MIME Cryptographic Signature Url : http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20070402/32d0cfed/attachment-0001.bin
- Follow-Ups:
- [Full-disclosure] More information on ZERT patch for ANI 0day
- From: Gadi Evron
- [Full-disclosure] More information on ZERT patch for ANI 0day
- References:
- [Full-disclosure] More information on ZERT patch for ANI 0day
- From: Gadi Evron
- [Full-disclosure] More information on ZERT patch for ANI 0day
- Prev by Date: [Full-disclosure] iDefense Security Advisory 03.31.07: Multiple Vendor ImageMagick DCM and XWD Buffer Overflow Vulnerabilities
- Next by Date: [Full-disclosure] Windows .ANI LoadAniIcon Stack Overflow
- Previous by thread: [Full-disclosure] More information on ZERT patch for ANI 0day
- Next by thread: [Full-disclosure] More information on ZERT patch for ANI 0day
- Index(es):