Vulnerability Development mailing list archives

Re: IE without Images


From: De Velopment <devel () www2 kparker org>
Date: Fri, 12 Jul 2002 22:52:26 -0700 (PDT)


On Fri, 12 Jul 2002, Nexus wrote (in part):

It's an odd one - appears as a 1x1 jpg in Irfanview - if you run strings on
it, it's chock full of xml code, which seems odd for a jpg ;-)

   The bottom line here is if there are circumstances where
Internet Explorer will execute XML code in a JPG file.  If
so, that is a *serious* security hole, IMNSHO.

     Best regards,

        Ken Parker (devel () www2 kparker org)


Current thread: