[Esd-l] bmp, cur, ico, ani need mangling or scanning ?

Pierre Etchemaite petchema at concept-micro.com
Mon Jan 10 05:52:47 PST 2005


See advisory

http://www.securityfocus.com/archive/1/385342/2004-12-22/2004-12-28/0


By the way, it seems that many readers and decoding libraries contain
overflows. I think I've also seen advisories about .tga, or even *shrug*
.pdf.

Does something like a safe format exist ? :(

Best regards,
Pierre.


More information about the esd-l mailing list