[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <43C8362F.5000109@sdf.lonestar.org>
Date: Fri Jan 13 23:22:38 2006
From: bkfsec at sdf.lonestar.org (bkfsec)
Subject: Re: [ GLSA 200601-09
] Wine:Windows MetafileSETABORTPROC vulnerability
Peter Ferrie wrote:
>bkfsec:
>
>
>
>>The way I read what he's saying there, he's saying that you enter
>>malformed input and that malformed input pushes the executable code into
>>position to be executed...
>>
>>
>
>There is no need for malformed input, though.
>The description isn't great, since upon return from the function, Windows
>will resume parsing the records in the usual way.
>
>8^) p.
>
>
>
>
I agree - I was focusing on how Gibson described it and his
justification of it being a planted vulnerability. *shrug*
-bkfsec
Powered by blists - more mailing lists