Free Republic
Browse · Search
News/Activism
Topics · Post Article

To: Decepticon
Errr, I thought the flaw was in .wmv files, quit downloading porn and music files until the patch comes out.....problem solved.

No, it's in the DLL that displays .wmf files, not .wmv (Windows Movie). .wmf files are Windows Metafile files, which are basically image files, mostly used for clip art, rarely on legitimate web pages.

30 posted on 01/02/2006 4:11:43 PM PST by Mannaggia l'America
[ Post Reply | Private Reply | To 16 | View Replies ]


To: Mannaggia l'America
Precisely. The problem appears to be that an error message returned from clicking on a thumbnail can actually be redirected to execute code at whatever level of access the user doing so has. Any code. Not nice.

I've applied the Guilfanov patch to my local box and everything seems fine so far. I've heard of some problems in canceling large print jobs but haven't seen anything like that myself.

40 posted on 01/02/2006 4:19:59 PM PST by Billthedrill
[ Post Reply | Private Reply | To 30 | View Replies ]

To: Mannaggia l'America
No, it's in the DLL that displays .wmf files, not .wmv (Windows Movie). .wmf files are Windows Metafile files, which are basically image files, mostly used for clip art, rarely on legitimate web pages.

Thanks for that. I'm researching it now....

41 posted on 01/02/2006 4:21:55 PM PST by Decepticon (The sheep pretend the wolf will never come, but the sheepdog lives for that day (NRA)
[ Post Reply | Private Reply | To 30 | View Replies ]

To: Mannaggia l'America

Interesting. I thought the clip art exploit was addressed in 97 or 98.


72 posted on 01/02/2006 4:46:59 PM PST by RedBloodedAmerican
[ Post Reply | Private Reply | To 30 | View Replies ]

To: Mannaggia l'America
No, it's in the DLL that displays .wmf files, not .wmv (Windows Movie). .wmf files are Windows Metafile files, which are basically image files, mostly used for clip art, rarely on legitimate web pages.

It's possible for a file with any extension to exploit this security hole:

From the SANS WMF Exploit FAQ:

Should I just block all .WMF images?

This may help, but it is not sufficient. WMF files are recognized by a special header and the extension is not needed. The files could arrive using any extension, or embeded in Word or other documents.


186 posted on 01/03/2006 9:35:47 AM PST by steve-b (A desire not to butt into other people's business is eighty percent of all human wisdom)
[ Post Reply | Private Reply | To 30 | View Replies ]

Free Republic
Browse · Search
News/Activism
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson