OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Blue Boar (BlueBoarthievco.com)
Date: Fri Nov 09 2001 - 01:09:24 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    "Chris D. Sloan" wrote:
    >
    > As with most things where the question is, "Is it possible...?" the
    > answere is that, yes it is *possible*. Someone could have written the
    > viewer to specifically interpret the JPEG contents as an executable.
    > The particular viewer you are using might overflow its stack and maybe
    > a carefully constructed JPEG could take advantage of that to run
    > malicious code.

    http://securityfocus.com/bid/1503

    >
    > Unless the person who wrote your viewer was malicious, though, I would
    > suspect the threat of anything like this actually happening in the
    > real world is about as high as the threat that there exist malicious
    > text files which would cause Notepad to infect other text files.

    Wordpad, not Notepad (AFAIK.)

                                            BB