re the WMF vulnerability


Go Back   Computer Help Articles > Windows XP Security Admin
User Name
Password
FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 01-05-2006, 03:51 PM
2pak
 
Posts: n/a
Default re the WMF vulnerability

if we view images on a website or open image attachments we could get spyware
etc through this WMF vulnerability.

I'm not sure what they mean by view images on a website?? Every website has
images basically. Can someone explain this?
Reply With Quote
  #2  
Old 01-05-2006, 03:51 PM
Rosanne
 
Posts: n/a
Default Re: re the WMF vulnerability

2pak wrote:
> if we view images on a website or open image attachments we could get spyware
> etc through this WMF vulnerability.
>
> I'm not sure what they mean by view images on a website?? Every website has
> images basically. <snip!>


Exactly. That's one reason this bug is kind of scary. If you look at
the source code behind a simple web page, for every picture you'll see a
line that says "img src", and points to a file. Your browser reads that
code and finds and opens the file (picture) for you. When you look at a
web page, you're usually looking at the contents of more than one file.
If the "picture" file has wmf code in it, the browser will still try to
open the pic for you - and end up executing the wmf code. Thumbnail
view does the same thing. So does viewing inline attachments in an
email message.

--
~ Rosanne
Don’t save my sneakemail address – when it gets spammed, it gets changed.
Reply With Quote
  #3  
Old 01-05-2006, 03:59 PM
Rosanne
 
Posts: n/a
Default Re: re the WMF vulnerability

2pak wrote:
> if we view images on a website or open image attachments we could get spyware
> etc through this WMF vulnerability.
>
> I'm not sure what they mean by view images on a website?? Every website has
> images basically. <snip!>


Exactly. That's one reason this bug is kind of scary. If you look at
the source code behind a simple web page, for every picture you'll see a
line that says "img src", and points to a file. Your browser reads that
code and finds and opens the file (picture) for you. When you look at a
web page, you're usually looking at the contents of more than one file.
If the "picture" file has wmf code in it, the browser will still try to
open the pic for you - and end up executing the wmf code. Thumbnail
view does the same thing. So does viewing inline attachments in an
email message.

--
~ Rosanne
Don’t save my sneakemail address – when it gets spammed, it gets changed.
Reply With Quote
  #4  
Old 01-05-2006, 11:14 PM
Carey Frisch [MVP]
 
Posts: n/a
Default RE: re the WMF vulnerability

A remote code execution security issue has been identified
in the Graphics Rendering Engine that could allow an attacker
to remotely compromise your Windows-based system and gain
control over it:

Microsoft Security Bulletin MS06-001
Vulnerability in Graphics Rendering Engine Could Allow Remote Code Execution
(912919)
http://www.microsoft.com/technet/sec.../ms06-001.mspx

Security Update for Windows XP (KB912919)
http://www.microsoft.com/downloads/d...displaylang=en

--
Carey Frisch
Microsoft MVP
Windows XP - Shell/User


"2pak" wrote:

> if we view images on a website or open image attachments we could get spyware
> etc through this WMF vulnerability.
>
> I'm not sure what they mean by view images on a website?? Every website has
> images basically. Can someone explain this?

Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Microsoft Security Advisory (912840): Vulnerability in Graphics Rendering Engine Could Allow Remote Code Execution PA Bear Internet Explorer 6 33 01-05-2006 04:38 PM
Re: Microsoft Security Advisory (912840): Vulnerability in Graphics Rendering Engine Could Allow Remote Code Execution PA Bear Windows XP General 0 01-05-2006 02:29 AM
Re: Microsoft Security Advisory (912840): Vulnerability in Graphics Rendering Engine Could Allow Remote Code Execution PA Bear Windows XP General 9 01-05-2006 02:28 AM
Re: Microsoft Security Advisory (912840): Vulnerability in Graphics Rendering Engine Could Allow Remote Code Execution Kerry Brown Windows XP General 1 01-05-2006 02:25 AM
Re: Microsoft Security Advisory (912840): Vulnerability in Graphic Tom [Pepper] Willett Windows XP General 0 01-05-2006 02:24 AM


All times are GMT. The time now is 10:08 AM.


Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd. SEO by vBSEO 2.3.2 © 2005, Crawlability, Inc.

re the WMF vulnerability