Another new MS04-028 variant exploiting malformed JPEG files surfaced overnight. This trojan is not widespread and mainly shows that work continues on GDI+ exploitation.
MS04-028: Ducky.C Trojan - GDI+ exploit for JPEG files
http://www.symantec.com/avcenter/venc/data...an.ducky.c.html
Trojan.Ducky.C is a Trojan horse program that exploits the Microsoft GDI+ Library JPEG Segment Length Integer Underflow vulnerability (described in the Microsoft Security Bulletin MS04-028)