[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <db6a1t$li2$1@sea.gmane.org>
Date: Thu Jul 14 19:17:08 2005
From: davek_throwaway at hotmail.com (Dave Korn)
Subject: Re: MS05-036
----Original Message----
>From: David Chastain
>Message-Id: 7381300.1121354089894.JavaMail.dlcmacosx@....com
> Has anyone seen or does anyone know of an exploit in HTML code that would
> target the MCMM vulnerability?
Nope. I haven't tried any experimentation yet, but my first guess would
be that the overflow is in one of the functions that have to deal with
strings, so maybe it would be worth trying to get very long colour names
passed down from html code until the browser ends up calling
CMConvertColorNameToIndex on them.
Or perhaps we want to try and overflow CMGetNamedProfileInfo?
cheers,
DaveK
--
Can't think of a witty .sigline today....
Powered by blists - more mailing lists