Release date: 2012-04-23
Updated on: 2012-04-24
Affected Systems:
Microsoft. NET Framework 3.5
Microsoft. NET Framework 3.0
Microsoft. NET Framework 2.0
Microsoft. NET Framework 4
Description:
--------------------------------------------------------------------------------
Bugtraq id: 53204
ASP. NET is a set of systems distributed by Microsoft to help developers build WEB applications.
. NET Framework has the remote integer overflow vulnerability in the EncoderParameter class implementation. After the heap buffer is incorrectly allocated, the buffer provided by one or more users will be copied to the new buffer, cause heap damage. After successful exploitation, applications with the Partial Trust permission may escape the CLR sandbox and execute arbitrary code with the Full Trust permission.
<* Source: Yorick Koster
Link: http://www.akitasecurity.nl/advisory.html? Id = AK20110801
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Microsoft
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.microsoft.com/technet/security/