[Full-Disclosure] Microsoft Windows LoadImage API Integer buffer overflow patch.

From: Artur Byszko (bajkero_at_sec-labs.hack.pl)
Date: 12/29/04

  • Next message: Todd Towles: "RE: [Full-Disclosure] And you're proud of this Mike Evanchick?"
    Date: Wed, 29 Dec 2004 07:40:08 +0100
    To: full-disclosure@lists.netsys.com
    
    
    
    

    Hello,

    Due to publication of Xfocus' Microsoft Windows LoadImage API Integer
    buffer overflow (high risk bug), we decided to release patch for this
    vulnerability.
    This is the first known patch for this bug and can be downloaded from
    http://sec-labs.hack.pl/patch/ico_patch2.zip
    Read README before any actions with this code.

    Best Regards,

    -- 
    // Artur Byszko, Sec-Labs Research Team, 0xFA2C0676
    // 7C0E 55A0 5039 FD1C 9083  91DB AF4D F474 FA2C 0676
    
    

    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html



  • Next message: Todd Towles: "RE: [Full-Disclosure] And you're proud of this Mike Evanchick?"

    Relevant Pages

    • Re: Download.ject - commentary - LONG
      ... > patch recently released by Microsoft. ... > vulnerability in question, but instead is just a partial workaround. ... > Granted these are known security best practices related to Internet ... > a new default browser to users and hope that it will be safe enough. ...
      (microsoft.public.win2000.security)
    • Vulnerability Details for MS02-012
      ... Microsoft released a patch for a denial of service ... vulnerability in the Windows 2000 SMTP component. ... This bug affects all Windows 2000 systems running the SMTP service that have ...
      (Bugtraq)
    • Microsoft Security Bulletin MS01-044
      ... Subject: Microsoft Security Bulletin MS01-044 ... 15 August 2001 Cumulative Patch for IIS ... - A denial of service vulnerability that could enable an attacker ...
      (Bugtraq)
    • [NT] 15 August 2001 Cumulative Patch for IIS
      ... Microsoft has released an important patch for IIS administrators. ... * A denial of service vulnerability that could enable an attacker to ...
      (Securiteam)
    • McAfee ePolicy Orchestrator Format String Vulnerability (a031703-1)
      ... ePolicy Orchestrator Format String Vulnerability ... on the host they wish to compromise. ... The vendor has made a patch available. ...
      (Bugtraq)