Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
RE: [Full-disclosure] 0-day ANI vulnerability in Microsoft Windows(CVE-2007-0038) Mar 31 2007 12:47AM
Eric Sites (erics sunbelt-software com)
You really need to check for:

RIFF[4 byte file size] <-- The file size can be ignored.
Then the next 4 byte after the file size should contain:
ACON

Then look for:

anih and the 4 byte value following it greater than 0x50, this is the
stack buffer overflow point. New ANIs can be built with any num...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus