BugTraq
RE: WMF Exploit Dec 28 2005 11:01PM
Hayes, Bill (Bill Hayes owh com) (1 replies)
RE: WMF Exploit Dec 29 2005 09:34PM
Bill Busby (williambusby2001 yahoo com) (1 replies)
Re: WMF Exploit Dec 30 2005 08:40PM
Paul Laudanski (zx castlecops com) (3 replies)
Re: WMF Exploit Jan 01 2006 08:31PM
Justin Myers (masterbofh gmail com)
Apologies if you've already read this, but this is interesting news:

Apparently shimgvw.dll isn't the problem; according to the Kaspersky
Lab blog, gdi32.dll is.

From http://www.viruslist.com/en/weblog?discuss=176892530&return=1
(which talks about an IM worm that uses this):

"Going back to the wmf vulnerability itself, we see number of sites
mention that shimgvw.dll is the vulnerable file.
This doesn't seem correct as it's possible to exploit a system on
which shimgvw.dll has been unregistered and deleted. The vulnerability
seems to be in gdi32.dll."

[ reply ]
RE: WMF Exploit Dec 31 2005 08:03PM
Paul (pvnick gmail com)
Re: WMF Exploit Dec 30 2005 10:45PM
Frank Knobbe (frank knobbe us)


 

Privacy Statement
Copyright 2010, SecurityFocus