Hi Guys,
Was just browsing a security website known as FrSIRT and discovered that there were exploits in LIBPNG and LIBTTF
references:
http://www.frsirt.com/english/advisories/2007/1894 - libTTF
http://www.frsirt.com/english/advisories/2007/1838 - libPNG
If anything can be done, it would be great!
LIBPNG / LIBTTF Exploits?
-
- Posts: 2
- Joined: Wed May 23, 2007 1:49 pm
-
- Posts: 2
- Joined: Wed May 23, 2007 1:49 pm
TTF will at most lead to an exploit in the browser and that will at most give user mode access. So that's not the best point to look for. The PNG exploit on the other side was labeled 'low risc', so I'm not sure if that will be useable at all.
<Don't push the river, it flows.>
http://wordpress.fx-world.org - my devblog
http://wiki.fx-world.org - VFPU documentation wiki
Alexander Berl
http://wordpress.fx-world.org - my devblog
http://wiki.fx-world.org - VFPU documentation wiki
Alexander Berl
User mode can lead to full access though anyway (As seen in the past)Raphael wrote:TTF will at most lead to an exploit in the browser and that will at most give user mode access. So that's not the best point to look for. The PNG exploit on the other side was labeled 'low risc', so I'm not sure if that will be useable at all.
And it would keep those people on 3.10 - 3.40 happy where they can run Nes or something without the need of access to the kernel..
its just a new chapter :P
Not unless another exploit in the kernel functions is found. And THAT is the real problem about it, so I'd rather first investigate for such exploits. But I'm not the man for that anyway, so I don't care really.Wally4000 wrote: User mode can lead to full access though anyway (As seen in the past)
<Don't push the river, it flows.>
http://wordpress.fx-world.org - my devblog
http://wiki.fx-world.org - VFPU documentation wiki
Alexander Berl
http://wordpress.fx-world.org - my devblog
http://wiki.fx-world.org - VFPU documentation wiki
Alexander Berl