View Single Post
  #2 (permalink)  
Old 12-08-2005, 04:15 PM
dadon's Avatar
dadon dadon is offline
Senior Member
 
Join Date: Nov 2005
Posts: 153
Points: 0.06
Donate
Quote:
Originally Posted by Twitch
OK

On pspupdates its been anounced that appearantly an exploit has been found in libungif, in versions below 4.1.4(released 10-19-2005)

Heres the link to the thread--->http://forums.qj.net/showthread.php?t=28627

Heres a link to Info about the exploit:
http://www.frsirt.com/english/advisories/2005/2295

..and some "proof-of-concept" GIFs
http://scary.beasts.org/misc/bad1.gif
http://scary.beasts.org/misc/bad2.gif
http://scary.beasts.org/misc/bad3.gif

Heres what is known:

GIFs "bad1" and "bad2" cause fw versions 2.01 and 2.5 to "freeze" and shut themselves down.

GIF "bad3" doesnt cause 2.01 to crash but once you select it you get error code 00000001(I dont know about 2.5)

These dont work on 2.6. That fw has been patched.

This exploit has led to code execution on computers.



Fanjita on pspupdates wrote this:



And this:




Just thought everyone should see this.......

-Peace
could anything be done with this then?
it looks legit
__________________
U either Ride wiv me or Collide wiv me- Kiss me, Tease me, u cud neva please me!!
""Ĉħųяĉħ Ĉяέω""

/ `--"""""""""""""""""| ]
/_==o ____ __|""
),---.(_(___) /
// (\) ),-----"
// //
'-----'
>>>"I Liv By Da Gun,<<<
>>>I Die By Da Gun"<<<
Reply With Quote