JPEG vulnerability and image-based attacks

MS04-028 disclosed a vulnerability in Windows JPEG processing. A specially-crafted JPEG image can produce a buffer overflow when displayed.

Why this matters

Images are everywhere. Web pages, email, documents, file shares — JPEGs are pervasive. A vulnerability that triggers on image display means almost every internet-connected user is potentially exposed.

What operators should do

Apply the patch. Update browsers. Update mail clients.

More as the situation develops.


Back to all writing