by Nortonesque » Mon Feb 06, 2006 9:19 pm
Sorry about that -- the patch I linked to is the WMF patch. WMF is a graphics format, and there was a bug in the rendering engine.
Basically, an attacker would just have to post a malicious WMF graphic on a web page, and anyone who viewed the web page would then be running whatever code the attacker put in the WMF.