Graphic Design Blog > S-352: Vulnerability in Microsoft Windows Image Color Management ...

The UNIX and Linux Forumshttp://www.unix.com/security-advisories-rss/77232-s-352-vulnerability-microsoft-windows-image-color-management-system.html [The UNIX and Linux Forums] A remote code execution vulnerability exists in the way that Microsoft Color Management System (MSCMS) module of the Microsoft ICM component handles memory allocation. The vulnerability could allow remote code execution if a user opens a specially crafted image file.

Previous [Previous] VU#309739: Microsoft Color Management System (MSCMS) module...

Next [Next] Awesome Photoshop Tutorials...

Some related posts from Technorati and Google.

securityfocus Vulnerabilitieshttp://www.securityfocus.com/bid/30594 [securityfocus Vulnerabilities] Vuln: Microsoft Windows Image Color Management Remote Code ...: Microsoft Windows Image Color Management Remote Code Execution Vulnerability.

US-CERT Recently Published Vulnerability Noteshttp://www.kb.cert.org/vuls/id/309739 [US-CERT Recently Published Vulnerability Notes] VU#309739: Microsoft Color Management System (MSCMS) module remote ...: OverviewThe Microsoft Color Management System (MSCMS) module for the Microsoft ICM component is vulnerable to a remote code execution vulnerability which may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system.

CA Security Advisor Newly Discovered Vulnerabilitieshttp://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=36538 [CA Security Advisor Newly Discovered Vulnerabilities] Microsoft Windows Image Color Management System remote code ...: For: Microsoft Windows 2000 Advanced Server SP4 x86 32 DE, Microsoft Windows 2000 Advanced Server SP4 x86 32 EN, Microsoft Windows 2000 Advanced Server SP4 x86 32 ES, Microsoft Windows 2000 Advanced Server SP4 x86 32 FR, Microsoft Windows 2000 Advanced Server SP4 x86 32 IT, Microsoft Windows 2000 Professional SP4 x86 32 DE, Microsoft Windows 2000 Professional SP4 x86 32 EN, Microsoft Windows 2000 Professional SP4 x86 32 ES, Microsoft Windows 2000 Professional SP4 x86 32 FR, Microsoft Windows 2000 Professional SP4 x86 32 IT, Microsoft Windows 2000 Server SP4 x86 32 DE, Microsoft Windows 2000 Server SP4 x86 32 EN, Microsoft Windows 2000 Server SP4 x86 32 ES, Microsoft Windows 2000 Server SP4 x86 32 FR, Microsoft Windows 2000 Server SP4 x86 32 IT, Microsoft Windows Server 2003 Enterprise Edition SP1 x86 32 DE, Microsoft Windows Server 2003 Enterprise Edition SP1 x86 32 EN, Microsoft Windows Server 2003 Enterprise Edition SP1 x86 32 ES, Microsoft Windows Server 2003 Enterprise Edition SP1 x86 32 FR, Microsoft Windows Server 2003 Enterprise Edition SP1 x86 32 IT, Microsoft Windows Server 2003 Enterprise Edition SP2 x86 32 DE, Microsoft Windows Server 2003 Enterprise Edition SP2 x86 32 EN, Microsoft Windows Server 2003 Enterprise Edition SP2 x86 32 ES, Microsoft Windows Server 2003 Enterprise Edition SP2 x86 32 FR, Microsoft Windows Server 2003 Enterprise Edition SP2 x86 32 IT, Microsoft Windows Server 2003 Enterprise Edition x64 64 EN, Microsoft Windows Server 2003 SP2 Enterprise Edition x64 64 EN, Microsoft Windows Server 2003 SP2 Standard Edition x64 64 EN, Microsoft Windows Server 2003 Standard Edition SP1 x86 32 DE, Microsoft Windows Server 2003 Standard Edition SP1 x86 32 EN, Microsoft Windows Server 2003 Standard Edition SP1 x86 32 ES, Microsoft Windows Server 2003 Standard Edition SP1 x86 32 FR, Microsoft Windows Server 2003 Standard Edition SP1 x86 32 IT, Microsoft Windows Server 2003 Standard Edition SP2 x86 32 DE, Microsoft Windows Server 2003 Standard Edition SP2 x86 32 EN, Microsoft Windows Server 2003 Standard Edition SP2 x86 32 ES, Microsoft Windows Server 2003 Standard Edition SP2 x86 32 FR, Microsoft Windows Server 2003 Standard Edition SP2 x86 32 IT, Microsoft Windows Server 2003 Standard Edition x64 64 EN, Microsoft Windows Server 2003 Web Edition SP1 x86 32 DE, Microsoft Windows Server 2003 Web Edition SP1 x86 32 EN, Microsoft Windows Server 2003 Web Edition SP1 x86 32 ES, Microsoft Windows Server 2003 Web Edition SP1 x86 32 FR, Microsoft Windows Server 2003 Web Edition SP1 x86 32 IT, Microsoft Windows Server 2003 Web Edition SP2 x86 32 DE, Microsoft Windows Server 2003 Web Edition SP2 x86 32 EN, Microsoft Windows Server 2003 Web Edition SP2 x86 32 ES, Microsoft Windows Server 2003 Web Edition SP2 x86 32 FR, Microsoft Windows Server 2003 Web Edition SP2 x86 32 IT, Microsoft Windows XP Home Edition SP2 x86 32 DE, Microsoft Windows XP Home Edition SP2 x86 32 EN, Microsoft Windows XP Home Edition SP2 x86 32 ES, Microsoft Windows XP Home Edition SP2 x86 32 FR, Microsoft Windows XP Home Edition SP2 x86 32 IT, Microsoft Windows XP Home Edition SP3 x86 32 DE, Microsoft Windows XP Home Edition SP3 x86 32 EN, Microsoft Windows XP Home Edition SP3 x86 32 ES, Microsoft Windows XP Home Edition SP3 x86 32 FR, Microsoft Windows XP Home Edition SP3 x86 32 IT, Microsoft Windows XP Professional 64-Bit Edition x64 64 EN, Microsoft Windows XP Professional SP2 x86 32 DE, Microsoft Windows XP Professional SP2 x86 32 EN, Microsoft Windows XP Professional SP2 x86 32 ES, Microsoft Windows XP Professional SP2 x86 32 FR, Microsoft Windows XP Professional SP2 x86 32 IT, Microsoft Windows XP Professional SP3 x86 32 DE, Microsoft Windows XP Professional SP3 x86 32 EN, Microsoft Windows XP Professional SP3 x86 32 ES, Microsoft Windows XP Professional SP3 x86 32 FR, Microsoft Windows XP Professional SP3 x86 32 IT, Microsoft Windows XP SP2 Professional 64-Bit Edition x64 64 EN

pc teknik destekhttp://pcteknik.wordpress.com/2008/08/14/microsofts-august-patch-brings-11-security-fixes/ [pc teknik destek] Microsoft’s August Patch Brings 11 Security Fixes: The top important item will deal with a privately reported vulnerability in the way certain Windows Internet Protocol Security (IPsec) rules are applied to traffic flow. According to Redmond, the stated vulnerability could cause systems to inadvertently ignore IPsec policies and transmit network traffic in clear readable text, thus disclosing that info to hackers.

The Official Blog of Eric Lamhttp://ericlam.spaces.live.com/blog/cns!5D73BE0B4076E647!3564.entry [The Official Blog of Eric Lam] Microsoft Security Updates - August 2008: The monthly Microsoft Security patches for August 2008 (including the Microsoft Windows Malicious Software Removal Tool and Microsoft Junk Email filters) are now available for download.

Nessus.org Pluginshttp://www.nessus.org/plugins/index.php?view=single&id=33875 [Nessus.org Plugins] Vulnerability in Microsoft Windows Image Color Management System ...: Arbitrary code can be executed on the remote host through the Microsoft Color Management System (MSCMS) module of the Microsoft ICM componenents. Description : The remote host contains a version of the Color Management Module which .

Security Watch[Security Watch] 11 Patches From Microsoft: MS08-046 Vulnerability in Microsoft Windows Image Color Management System Could Allow Remote Code Execution (Critical): A vulnerability in ICM makes it possible for an attacker to cause remote code execution on a Windows client system .

Multi-State Information Sharing and Analysis Center (MS-ISAC)http://www.msisac.org/advisories/2008/2008-028.cfm [Multi-State Information Sharing and Analysis Center (MS-ISAC)] Vulnerability in Microsoft Windows Image Color Management System ...: A vulnerability has been discovered in the Microsoft Image Color Management System (ICM) that will possibly trigger a heap-based buffer overflow. The vulnerability is due to an error in memory handling when processing MetaFile content.

D' Technology Webloghttp://www.ditii.com/2008/08/13/microsoft-security-updates-aug-08/ [D' Technology Weblog] Microsoft Security Updates: Aug ”˜08: [...] post: Microsoft Security Updates: Aug â??08 ajax blogging computers disk domain hardware html internet storage technology tips tutorial web [...]

TrendLabs | Malware Blog - by Trend Microhttp://blog.trendmicro.com/microsofts-august-patch-tuesday-roundup/ [TrendLabs | Malware Blog - by Trend Micro] Microsoft’s August Patch Tuesday Roundup: For the month of August, Microsoft has released eleven (11) security bulletins: six (6) which are tagged as Critical and five (5) which are tagged as Important.

Bardissi Enterprises Bloghttp://bardissi.wordpress.com/2008/08/13/watchguardfive-windows-updates-only-one-critical/ [Bardissi Enterprises Blog] WatchGuard Live Secuirty:Five Windows Updates, Only One Critical: According to Microsoft, Messenger ships with an ActiveX control that is marked safe for scripting, which means web sites can runs scripts using this control. Unfortunately, this leads to an information disclosure vulnerability.

The PC Doctor's bloghttp://www.pcdoctor-guide.com/wordpress/?p=4820 [The PC Doctor's blog] August’s Patch Tuesday: MS08-041 - Vulnerability in the ActiveX Control for the Snapshot Viewer for Microsoft Access Could Allow Remote Code Execution (955617); MS08-043 - Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (954066) ...

softsecurity.com In focushttp://www.softsecurity.com/news_D2707_focus.html [softsecurity.com In focus] August 2008 Monthly Bulletin Release: Microsoft has heard from customers that the quality of updates is very important and, as part of the process at the Microsoft Security Response Center (MSRC), Microsoft tests these updates continuously until they are ready for distribution to customers through our regularly scheduled security bulletin release.

24/7 Live Malware Mixhttp://www.bestsecuritytips.com/modules/planet/view.article.php?15382 [24/7 Live Malware Mix] Microsoft Patch Tuesday for August 2008: Affects: Microsoft Windows 2000 SP4, Windows XP SP2 & SP3, Windows XP Professional x64 Edition, Windows XP Professional x64 Edition SP2, Windows Server 2003 SP1 and SP2, Windows Server 2003 x64 Edition, Windows Server 2003 x64 Edition SP2, and Windows Server 2003 with SP1 or SP2 for Itanium-based Systems

ASTALAVISTA - the hacking and security community - Blog Meldungenhttp://www.astalavista.com/index.php?section=blog&cmd=details&id=3473 [ASTALAVISTA - the hacking and security community - Blog Meldungen] Microsoft releases 11 security bulletins: If you want more information about these security bulletins do check out the TechNet Webcast that will present a brief overview of the technical details of the August security bulletins followed by an extensive Q&A session that will give you the opportunity to ask questions and get answers from Bill Sisk, Security Response Communications Manager and Adrian Stone, Lead Security Program Manager, Microsoft Corporation.

eSafe CSRT Bloghttp://www.aladdin.com/CsrtBlog/post.aspx?id=c97b38e9-cb0d-4f27-a23c-5bfbe3bae765 [eSafe CSRT Blog] Microsoft Security Bulletin Summary for August 2008: A vulnerability has been discovered in the Microsoft Image Color Management (ICM) system that could allow remote code execution in the context of the current user. If a user is logged on with administrative user rights, an attacker who .

billjr's Spacehttp://billjr.spaces.live.com/blog/cns!28CBD6442F406227!1009.entry [billjr's Space] Patch Tuesday - August 12, 2008: To add a comment, you must sign in with your Windows Live ID (a Microsoft account like Hotmail, Messenger, or MSN).

Reflected tags on Technorati: Blog, , , , , ,