Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Zero-day WMF flaw underscores patch problems
Robert Lemos, SecurityFocus 2006-01-12

For four days in January, network administrators and security-savvy home users had a choice: Download and install an unofficial open-source fix for the critical flaw in the Windows Meta File (WMF) format or wait an estimated week for an official patch from Microsoft.

Comments Mode:
What Microsoft needs to be doing... 2006-01-12
Eric (2 replies)
Re: What Microsoft needs to be doing... 2006-01-13
Matthew Murphy (1 replies)
Alternative solution 2006-01-13
mxb (2 replies)
Re: Alternative solution 2006-01-13
DSMatthews
Re: Alternative solution 2006-01-13
Anonymous
Make'em pay! 2006-01-13
assurbanipal
The Squander of MS Admins && Users 2006-01-13
Anonymous (1 replies)
Re: The Squander of MS Admins && Users 2006-01-16
Anonymous (1 replies)
Does any one see this 2006-01-13
Anonymous
where come from a zero-day flaw 2006-01-15
lucmars
You may have heard, according to S. Gibson from media.grc.com, the wmf flaw seems to be an "undocumented Windows feature" : the Escape/SETABORTPROC procedure can respond to a specific value, normally impossible, from which Windows goes directly to the code included in the metafile and execute it.
So it looks like a backdoor already crafted in the source code, not something installed like a Trojan. This the kind of thing that kills the confidence ; Debian has been hit in a similar way but recovers the genuine source code in less than 24 hours. It's always possible to have a malicious contributor in an open source project. Hence, rewieving the code is a good practice, as it is said in a previous comment. And it's not a so flawed argument : one cannot argue that Wine's staff has not noticed something he cannot check.
Conclusion : a zero-day vuln can come from the inner and be exploited later. Just for this reason, it's important to rewieving the code since nobody has the same understanding of what is a feature and a security hole.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/11368/32964#32964
Patch from Guilfanov was not the only one 2006-01-16
Juha-Matti Laurio







 

Privacy Statement
Copyright 2008, SecurityFocus