Re: BMP Processor overflow by Roger
Roger
Fri Jul 29 09:13:19 CDT 2005
You probably should gather more info from your IPS and then
block that origin IP in your firewall. At least, you should if you
trust the signatures in use in your IPS. There were some exploits
based on graphics processing overflow and some based on
embedding in what are passed as bmp. The ones I am thinking
of have had patches released - not sure if there are actively used
unpatched variant out today.
--
Roger Abell
Microsoft MVP (Windows Security)
MCSE (W2k3,W2k,Nt4) MCDBA
"Nathan Weldon" <nweldon@usaarchitects.com> wrote in message
news:%235b0ql5kFHA.3316@TK2MSFTNGP14.phx.gbl...
> I'm getting the following alert from my firewall's IPS:
>
> WEB-CLIENT Internet Explorer BMP Processing Overflow.
> I spoke to the user and told them to stop going to what ever site they
are,
> but I keep getting the alert. should I be worried about this person's
> workstation? My IPS is blocking the threat, but the 100 alerts I'm getting
a
> day are starting to bother me.
>
> Thanks.
>
>