Lizardtech DjVu Browser Plug-in - Multiple Vulnerabilities

看板Bugtraq作者時間19年前 (2007/02/16 02:12), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/1
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D =3D Lizardtech DjVu Browser Plug-in - Multiple Vulnerabilities =3D =3D Vendor Website:=20 =3D http://www.lizardtech.com/ =3D =3D Affected Version: =3D Windows DjVu Browser Plug-in < 6.1.1 =3D =3D Public disclosure on February 15th 2007 =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D =3D=3D Overview =3D=3D The DjVu Browser Plug-in is the primary means of viewing DjVu documents. It runs inside most modern browsers including IE, Firefox and Safari. Versions prior to 6.1.1 are vulnerable to buffer overflows through various functions. One such example is through the ExportImageAs method. It should be noted that CERT contacted Lizardtech at about the same time as we did, advising of numerous overflow problems as well. These have also been addressed by this update. =3D=3D Solutions =3D=3D - Upgrade to version 6.1.1 from the lizardtech website http://www.lizardtech.com/ =20 =3D=3D Credit =3D=3D Discovered and advised to Lizardtech November 2006, by Brett Moore of Security-Assessment.com =3D=3D About Security-Assessment.com =3D=3D Security-Assessment.com is Australasia's leading team of Information=20 Security consultants specialising in providing high quality Information=20 Security services to clients throughout the Asia Pacific region. Our=20 clients include some of the largest globally recognised companies in=20 areas such as finance, telecommunications, broadcasting, legal and=20 government. Our aim is to provide the very best independent advice and=20 a high level of technical expertise while creating long and lasting=20 professional relationships with our clients. Security-Assessment.com is committed to security research and=20 development, and its team continues to identify and responsibly publish=20 vulnerabilities in public and private software vendor's products.=20 Members of the Security-Assessment.com R&D team are globally recognised=20 through their release of whitepapers and presentations related to new=20 security research..
文章代碼(AID): #15rAAB00 (Bugtraq)