Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

WinImage Image Files Denial of Service and Directory Traversal Vulnerabilities

To exploit these issues, an attacker must entice an unsuspecting user to open or extract a maliciously crafted disk-image file.

The following example file path names are available:

readme.txt/../../../../../../../../sth.bat
readme.txt<40 spaces here>/../../../../../../../../asdf.exe

The following proof-of-concept images are available:







 

Privacy Statement
Copyright 2009, SecurityFocus