最近出了很多GDI+的高危漏洞啊

ZDI-08-056: Microsoft Windows GDI+ GIF Parsing Code Execution Vulnerability <http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/63646>
ZDI-08-055: Microsoft Windows GDI+ BMP Parsing Code Execution Vulnerability <http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/63647>
MS08-052 <http://hi.baidu.com/tombkeeper/blog/item/f6576a310ed6271feac4af7a.html>
ZDI-08-062: Apple QuickTime MDAT Frame Parsing Memory Corruption Vulnerability <http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/63650>
ZDI-08-061: Apple QuickTime Player H.264 Parsing Heap Corruption Vulnerability <http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/63652>
ZDI-08-060: Apple QuickTime AVC1 Atom Parsing Heap Overflow Vulnerability <http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/63648>
ZDI-08-059: Apple QuickTime STSZ Atom Parsing Heap Corruption Vulnerability <http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/63653>
ZDI-08-058: Apple QuickTime Panorama PDAT Atom Parsing Buffer Overflow Vulnerability <http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/63649>
别忘了还有万众瞩目过的MS08046:
http://hi.baidu.com/wordexp/blog/item/50c25e248c0584358644f96a.html

GDI+ VML 缓冲区溢出漏洞 - CVE-2007-5348
GDI+ EMF 内存损坏漏洞 - CVE-2008-3012
GDI+ GIF 分析漏洞 - CVE-2008-3013
GDI+ WMF 缓冲区溢出漏洞 - CVE-2008-3014
GDI+ BMP 整数溢出漏洞 - CVE-2008-3015


[本日志由 子曰 于 2008-09-18 09:53 AM 编辑]
文章来自: 本站原创
引用通告: 查看所有引用 | 我要引用此文章
Tags:
评论: 0 | 引用: 0 | 查看次数: -
发表评论
昵 称:
密 码: 游客发言不需要密码.
内 容:
验证码: 验证码
选 项:
虽然发表评论不用注册,但是为了保护您的发言权,建议您注册帐号.