[<prev] [next>] [day] [month] [year] [list]
Message-ID: <B676F24303764FEDA4908EA68F8F2B87@localhost>
Date: Sat, 2 Jan 2010 04:36:47 +0100
From: "Stefan Kanthak" <stefan.kanthak@...go.de>
To: <bugtraq@...urityfocus.com>
Cc: "Microsoft Security Response Center" <secure@...rosoft.com>,
<secure@...el.com>
Subject: Latest Intel Pro/10* ethernet adaptor drivers contain vulnerable MSVC runtime!
Hi @ll,
Intel just released updated drivers for their ethernet network adaptors,
see
<http://downloadcenter.intel.com/Detail_Desc.aspx?agr=Y&DwnldID=17906&ProdId=3025&lang=eng>
and
<http://downloadcenter.intel.com/Detail_Desc.aspx?agr=Y&DwnldID=18518&ProdId=3025&lang=eng>
for example.
Unfortunately ALL these driver packages but contain an outdated and
unsupported "Microsoft Visual C++ 2008 Runtime", repackaged as
VC90_CRT_{x86,ia64,x64}.msi and violating Microsofts redistribution
rules, which installs VULNERABLE runtime DLLs.
See <http://support.microsoft.com/kb/973551>,
<http://support.microsoft.com/kb/973552> and
<http://www.microsoft.com/technet/security/bulletin/MS09-035.mspx>
Stefan Kanthak
Powered by blists - more mailing lists