lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <5515b45c0608010824j34dd0e1bj345345c883d0e247@mail.gmail.com>
Date: Tue, 1 Aug 2006 17:24:27 +0200
From: "giacomo collini" <gcliste@...il.com>
To: "Early Warning Team" <ewt@...ecomitalia.it>
Cc: bugtraq@...urityfocus.com
Subject: Re: Gdiplus.dll division by 0

On 7/31/06, Early Warning Team <ewt@...ecomitalia.it> wrote:
> We tried the Proof of Concept on our test machines and couldn't reproduce the reported exceptional behavior. The scenarios we tested were:
> - Windows XP Service Pack 2, <img> tag in Internet Explorer 6
> - Windows XP Service Pack 2, "Insert picture" in Word 2003
> - Windows XP Service Pack 2, display picture in MSN Messenger 7.0 and 7.5
>
> In all cases, all we got were non-fatal "invalid picture" errors

I tried opening the picture created by the script on IE (without HTML,
only dragging) and also on Windows Picture And Fax Viewer,and i got a
nice crash  on both of them.
The hosting system is a Win XP SP2, gdiplus.dll release is 5.1.3102.2180

cheers

giacomo collini

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ