Re: [Declude.Virus] Patch Tuesday and graphic images

2005-07-12 Thread Nick Hayer
Thanks Andrew! -Nick Colbeck, Andrew wrote: Today is Microsoft Patch Tuesday for July 2005. One of the bulletins is: http://www.microsoft.com/technet/security/Bulletin/MS05-036.mspx Which fails to indicate which graphics formats are affected by this vulnerability. It does mention that abus

Re: [Declude.Virus] Patch Tuesday and graphic images

2005-07-12 Thread Scott Fisher
...and hope that Declude or the AV-Engine will catch this vulnerability as soon as possible. I completely agree. As a publishing company we receive lots of large jpeg files and the thought of having to virus scan all those, makes my mail server want to run and hide. I'd like to see a comment

RE: [Declude.Virus] Patch Tuesday and graphic images

2005-07-12 Thread Markus Gufler
Andrew thanks for the info > ...you will want > to remove these optimizations from your Declude virus.cfg file: > > SKIPEXT JPG > SKIPEXT JPEG > SKIPEXT PNG > SKIPEXT TIF > SKIPEXT TIFF ... and hope that Declude or the AV-En

Re: [Declude.Virus] Patch Tuesday and graphic images

2005-07-12 Thread Matt
They really didn't give enough information that would allow one to figure out the extent of the vulnerability here. Only RGB and CMYK images should have ICC profiles, but the programs that open such images will also open up images that have set pallets such as GIF's and BMP's. I don't know wh

[Declude.Virus] Patch Tuesday and graphic images

2005-07-12 Thread Colbeck, Andrew
Today is Microsoft Patch Tuesday for July 2005. One of the bulletins is: http://www.microsoft.com/technet/security/Bulletin/MS05-036.mspx Which fails to indicate which graphics formats are affected by this vulnerability. It does mention that abuse thereof is indeed in the wild. Presumably on w