Re: Web based email issues

From: Colonel Flagg (colonel_flagg_at_NOSOUPFORJ00internetwarzone.org)
Date: 09/16/03


Date: Tue, 16 Sep 2003 00:53:23 -0400

In article <MPG.19d032ce4970ce9b989c9d@news-server.columbus.rr.com>,
void@nowhere.com says...
> In article <4Kt9b.140578$0v4.10349691@bgtnsc04-
> news.ops.worldnet.att.net>, Lohkee@worldnet.att.net says...
> [snip]
> > Hmmmmmm. Executable content in Jpeg. Buffer overflow in reader (or other
> > handling application). Where is the problem?
>
> Show me an example of a buffer overflow caused by a large JPG file :)
>
>

read the links I provided and you'll find many examples of executable
content within jpg's with potentially malicious intent.

buffer overflows? dunno if that's the outcome, however, the code is
EXECUTED with another application.

-- 
Colonel Flagg
http://www.internetwarzone.org/
Privacy at a click:
http://www.cotse.net 
Q: How many Bill Gates does it take to change a lightbulb?
A: None, he just defines Darkness? as the new industry standard..."
"...I see stupid people."


Relevant Pages

  • SDL_Image 1.2.6 and prior GIF handling buffer overflow
    ... SDL_Image 1.2.6 and prior GIF handling buffer overflow ... SDL_Image is an open source library providing image file handling ... GIF format handling routines suffers from lack of proper buffer ... in some cases the attack could be remote. ...
    (Bugtraq)
  • Re: incredible
    ... >> a critical vulnerability in its software's handling of the ubiquitous ... >> JPEG graphics format. ... >buffer overflow then execute a undocumented and secret language format ...
    (sci.electronics.design)
  • Re: Web based email issues
    ... Executable content in Jpeg. ... Buffer overflow in reader (or other ... > handling application). ... Show me an example of a buffer overflow caused by a large JPG file:) ...
    (alt.computer.security)
  • Re: incredible
    ... >>OTOH, buffer overflow is a very common security issue, so one might have ... There was little found on MS.com about "buffer overflow" attacks. ... a successful hack using a .jpg file? ...
    (sci.electronics.design)