AplusWebMaster
Topic Starter
FYI…
- http://isc.sans.org/diary.php?date=2005-07-21
Updated July 22nd 2005 01:58 UTC
"We've received reports that the Color Management Module ICC Profile Buffer Overflow Vulnerability has exploit code available and is being used out in the wild. The vulnerability information from Microsoft is available over at MS Technet. The mitigate this vulnerability, apply the appropriate patch ( http://www.microsoft.com/technet/security/…n/ms05-036.mspx ). It appears that this version of the exploit code will only crash the browser, but it wouldn't be difficult to put in code for execution. FrSIRT put out an advisory on the code being in the wild this morning"
- http://www.frsirt.com/exploits/20050721.icc_ex.c.php

- http://isc.sans.org/diary.php?date=2005-07-21
Updated July 22nd 2005 01:58 UTC
"We've received reports that the Color Management Module ICC Profile Buffer Overflow Vulnerability has exploit code available and is being used out in the wild. The vulnerability information from Microsoft is available over at MS Technet. The mitigate this vulnerability, apply the appropriate patch ( http://www.microsoft.com/technet/security/…n/ms05-036.mspx ). It appears that this version of the exploit code will only crash the browser, but it wouldn't be difficult to put in code for execution. FrSIRT put out an advisory on the code being in the wild this morning"
- http://www.frsirt.com/exploits/20050721.icc_ex.c.php