[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
RE: [Full-disclosure] Re: [ GLSA 200601-09 ]Wine:Windows MetafileSETABORTPROC vulnerability
- To: <full-disclosure@xxxxxxxxxxxxxxxxx>
- Subject: RE: [Full-disclosure] Re: [ GLSA 200601-09 ]Wine:Windows MetafileSETABORTPROC vulnerability
- From: "Peter Ferrie" <pferrie@xxxxxxxxxxxx>
- Date: Sun, 15 Jan 2006 14:47:19 -0800
>>It's insecure-by-design, but it's working exactly as written.
>>It's been in there for _15_ years, and ported to every version of Windows.
>>Windows 3.0 supports it. :-/
>
>I'm still having a bit of trouble following Gibson's explanation of how the
>WMF flaw works, but it's my impression he says it does *not* operate
>according to spec. And yet Wine is vulnerable. Am I wrong?
Steve is wrong. Wine was (I believe that a patch was released) vulnerable
because the function was documented exactly as it behaves, and they coded to
that.
8^) p.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/