- http://isc.sans.org/diary.php?storyid=1031
Last Updated: 2006-01-09 18:27:08 UTC
"We had hoped the chapter on WMF exploits had finally been closed, pending the patching of countless millions of vulnerable workstations of course. However, today we were forwarded a Bugtraq disclosure of two additional functions vulnerable to memory corruption attack within the Microsoft graphics rendering engine. The flaw reportedly affects the 'ExtCreateRegion' and 'ExtEscape' functions and while there has been no current proof of concept exploit/DoS code publicly released we will be watching this issue closely.
reference: http://www.securityfocus.com/bid/16167 …"
More Unpatched Bugs Loose In Microsoft Windows Metafile
- http://www.techweb.com/article/printableAr…6&site;_section=
January 09, 2006
"…"An attacker may leverage these issues to carry out a denial-of-service attack or execute arbitrary code," Symantec said in a vulnerability alert issued through its DeepSight Management System… Without a patch for this new problem, Symantec was forced to fall back on earlier advice given to users two weeks ago by Microsoft: disable the Windows Picture and Fax Viewer application. That program is automatically launched when users of Internet Explorer encounter a WMF file on a Web site. As of mid-morning Monday, Symantec had not confirmed the vulnerabilities, or the allegation that last week's patch doesn't solve the problem. However, Alfred Huger senior director of engineering for Symantec's security response team, said the researcher is probably on the mark. "Frankly, we expected something like this," Huger said. "We thought it was very likely that people knew of other vulnerabilities in the graphic rendering engine, but would wait to disclose them until Microsoft had patched, to see if their vulnerabilities were affected." The researcher, identified as "Frank Ruder," claimed to be part of the China-based Xfocus group. "Xfocus is usually very accurate in its information," said Huger. "Its members have a history of finding vulnerabilities"…"
>>> http://blogs.technet.com/msrc/
posted Monday, January 09, 2006 11:57 PM
" Information on new WMF Posting
Lennart Wistrand here. I wanted to write a few lines about the public post made over the weekend about a new specially crafted WMF image that could potentially cause the application using the Windows Graphics Rendering Engine to crash. As it turns out, these crashes are not exploitable but are instead Windows performance issues that could cause some WMF applications to unexpectedly exit. These issues do not allow an attacker to run code or crash the operating system. They may cause the WMF application to crash, in which case the user may restart the application and resume activity. We had previously identified these issues as part of our ongoing code maintenance and are evaluating them for inclusion in the next service pack for the affected products.
Just to be clear, the security update accompanying MS06-001 did not include fixes for these performance issues. Security updates sometimes do include other fixes, quite often this is a result of the cumulative nature of development, i.e., it may be that those types of fixes get checked in to the code tree and then picked up when a file is serviced in that code branch. However, in order to keep the code churn in security updates to a minimum we try to avoid, as a general rule, including other code fixes for performance issues such as this. It may seem counter-intuitive to not want to improve the code quality whenever opportunity arises, but the fact is that code churn incurred might have a negative impact on the quality of the update or yield a need for even more testing to ensure that we meet the quality bar for security updates…"