2007-05-29 16:20:00 by
Niels Provos in
Google Online Security Blog
...flaws, such as buffer overflows, in emulated hardware devices. One example of this is missing bounds checking in bitblt routines , which are used for moving rectangular blocks of data around the display. If exploited, by specifying pathological parameters for the operation, this could lead to an attacker compromising the virtual machine...