Tag: FAX

  • Microsoft was aware of the WMF vulnerability “for years”

    Bugtraq has an interesting post which picks up on a note in Stephen Toulouse’s latest entry on the WMF vulnerability. When I first read the post I was more interested in the way he was responding to allegations of the flaw being an intentional backdoor, but the above bugtraq post points out and makes points on an implication that I missed….. (emphasis is mine…)

    “The potential danger of this type of metafile record was
    recognized
    and some applications (Internet Explorer, notably)
    will not process any metafile record of type META_ESCAPE,
    the overall type of the SetAbortProc record.”

    (more…)