<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
><channel><title>M32 Security &#187; buffer overflow attack</title> <atom:link href="http://m32consulting.com/tag/buffer-overflow-attack/feed/" rel="self" type="application/rss+xml" /><link>http://m32consulting.com</link> <description>Network Security Info, News, and Resources</description> <lastBuildDate>Fri, 30 Jul 2010 04:55:42 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <item><title>Microsoft DirectShow ActiveX Buffer Overflow exploit in the wild</title><link>http://m32consulting.com/2009/07/microsoft-directshow-activex-buffer-overflow-exploit-in-the-wild/</link> <comments>http://m32consulting.com/2009/07/microsoft-directshow-activex-buffer-overflow-exploit-in-the-wild/#comments</comments> <pubDate>Mon, 06 Jul 2009 17:50:48 +0000</pubDate> <dc:creator>Kyle</dc:creator> <category><![CDATA[Software]]></category> <category><![CDATA[ActiveX]]></category> <category><![CDATA[activex buffer overflow]]></category> <category><![CDATA[Advisory]]></category> <category><![CDATA[attack]]></category> <category><![CDATA[based buffer overflow]]></category> <category><![CDATA[boundary]]></category> <category><![CDATA[Buffer]]></category> <category><![CDATA[buffer overflow attack]]></category> <category><![CDATA[code]]></category> <category><![CDATA[DirectShow]]></category> <category><![CDATA[dll]]></category> <category><![CDATA[image content]]></category> <category><![CDATA[internet explorer]]></category> <category><![CDATA[microsoft]]></category> <category><![CDATA[microsoft directshow]]></category> <category><![CDATA[msvidctl]]></category> <category><![CDATA[network security appliance]]></category> <category><![CDATA[Overflow]]></category> <category><![CDATA[secunia]]></category> <category><![CDATA[stack overflow]]></category><guid
isPermaLink="false">http://m32consulting.com/?p=37</guid> <description><![CDATA[Be sure to check for patches and network security appliance definitions/signatures today, Microsoft has been reminded again of why people hate ActiveX; Secunia is reporting a nasty new DirectShow Buffer Overflow attack is in the wild. This one is very dangerous, as it exploits the built-in DirectShow control in Internet Explorer (msvidctl.dll) by using specially-crafted [...]]]></description> <content:encoded><![CDATA[<p>Be sure to check for patches and network security appliance definitions/signatures today, Microsoft has been reminded again of why people hate ActiveX; Secunia is reporting a nasty new DirectShow Buffer Overflow attack is in the wild. This one is very dangerous, as it exploits the built-in DirectShow control in Internet Explorer (msvidctl.dll) by using specially-crafted image content to create a boundary error and subsequently cause a stack-based buffer overflow allowing the attacker to execute arbitrary code on the compromised machine.</p><p>The worst part? It&#8217;s already being actively used by bad people. Although Secunia&#8217;s site currently shows Windows XP as the only OS vulnerable, I wouldn&#8217;t be surprised to see more versions of Windows tacked on in the near future.</p><p><a
title="Secunia Advisory 35683" href="http://secunia.com/advisories/35683/">More information can be found here.</a></p> ]]></content:encoded> <wfw:commentRss>http://m32consulting.com/2009/07/microsoft-directshow-activex-buffer-overflow-exploit-in-the-wild/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk
Page Caching using disk (enhanced)
Database Caching 1/9 queries in 0.016 seconds using disk
Object Caching 462/489 objects using disk

Served from: m32consulting.com @ 2010-07-30 09:02:52 -->