Security:
News ToolsReg Shops |
The Register » Security » And deep in IE, a creature was stirring…Bug in the RugPublished Tuesday 17th December 2002 13:14 GMT eEye security researcher Derek Soeder was moved to verse after analysing a complicated - and not particularly devastating - heap corruption vulnerability involving the way Windows handles PNG image format files. An advisory by eEye begins thus: Twas the night before Christmas, and deep in IE
But the engineers weren't nestled all snug in their beds,
When rendering an image, we saw IE shatter
The bug in the thick of the poorly-written code
With heap management structures all hijacked so quick
As well as noting various unpatched versions of IE and Windows as potentially vulnerable to the bug, eEye notes BackOffice 4.5 is flawed for the same reason. Although the vulnerability discussed in eEye's advisory might possibly be exploited to execute code when the malicious PNG image is viewed, the risk is not too serious. As eEye notes "exploitation may become extremely difficult and in some cases unreliable", because of Windows memory management system protection features. Also the flaw can be patched using either Internet Explorer 6 Service Pack 1 or by applying a separate security fixfrom MS, highlighted in eEye's not so terse verse. ®
Track this type of story as a custom Atom/RSS feed or by email.
|
|
Top 20 stories • All The Week’s Headlines • Archive • Search