Gen X at 40

Canada's Favorite Blog

Comments

'nee -

It's a browser exploit. It has something to do with the way that IE handles the execution of images that makes it possible to embed code into them. Anything not-IE is safe, and I expect that in a week or so where will be a Windows Update that will fix the hole (only to introduce a few new ones, of course).

alfons -

It's a Windows system exploit. Anything that uses a particular version of the affected system file is vulnerable. (I think the list at news.bbc.co.uk isn't complete.)

Alan -

Well that is helpful. Which is it?

alfons -

gdiplus.dll. It's a really awful vulnerability, see http://isc.sans.org/diary.php?date=2004-09-26

'nee -

Hmm, ok, I revise my statement; alfons is right. But only Microsoft programs appear to be using GDI. Firefox isn't.

Post a Comment: Get Foxfire

Email addresses are not displayed with your comment and will not be shared.
Allowed tags are: <em>, <strong>, <code> and <a href="url">. All other tags will be displayed as plain text.