Get a Pentest and security assessment of your IT network.

Advisories

iDEFENSE Security Advisory 2008-08-12.7

iDefense Security Advisory 08.12.08 – Remote exploitation of a heap-based buffer overflow vulnerability in multiple versions of Microsoft Corp.’s Windows operating system allows an attacker to execute arbitrary code with the privileges of the current user. This vulnerability specifically exists in the InternalOpenColorProfile function in mscms.dll. When a malformed parameter is supplied, a heap-based buffer overflow can occur, resulting in an exploitable condition. iDefense has confirmed the existence of this vulnerability in the following Microsoft products: Windows 2000 Service Pack 4, Windows XP Service Pack 2, Windows Server 2003 Service Pack 1, and Windows Server 2003 Service Pack 2.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/69053/08.12.08-7.txt

Source: https://packetstormsecurity.com/files/69053/iDEFENSE-Security-Advisory-2008-08-12.7.html

Related posts
Advisories

LynX-adv4_SignatureDB.txt

Advisories

Secunia Security Advisory 16497

Advisories

Secunia Security Advisory 19451

Advisories

Debian Linux Security Advisory 1187-1