January 9, 2008
3:58 pm

With all the hoopla about the remotely exploitable, kernel-level buffer overflow discussed in today's security bulletin MS08-0001, what is the actual bug that triggers this? The bulletin doesn't give all that much information. This movie (Flash required) goes through the process of examining the 'pre-patch' version of tcpip.sys and comparing it against the 'post-patch' version of tcpip.sys. This comparison yields the actual code that causes the overflow: A mistake in the calculation of the required size in a dynamic allocation.

Slashdot

Vulnerability, Buffer Overflow, Windows XP, Windows Vista, Microsoft, IGMP

Loading

Contextual Related Posts:

No followup yet

Leave a Response

Comment Preview
« Windows Server 2008 TCP/IP Protocols and ServicesUpdate for Windows Internal Database (WYukon SP2) »
Feed Icon

Subscribe via RSS or email: