[<prev] [next>] [thread-next>] [day] [month] [year] [list]
From: psz at maths.usyd.edu.au (Paul Szabo)
Subject: MS02-065 vulnerability
Microsoft security bulletin
http://www.microsoft.com/technet/security/bulletin/ms02-065.asp
contains the caveat "a patched system could be made vulnerable again [by]
visit a web site or open an HTML mail". We have a execute-any-code
vulnerability, exploitable by a Web page or email; the patch can be undone
by a Web page or email. Just as exploitable after the patch.
Is this what Microsoft calls "responsible disclosure"?
Cheers,
Paul Szabo - psz@...hs.usyd.edu.au http://www.maths.usyd.edu.au:8000/u/psz/
School of Mathematics and Statistics University of Sydney 2006 Australia
PS: The above applies to IE only; I know that the patch is needed also for
IIS and maybe others. Do not let details get in the way of a good story.
Powered by blists - more mailing lists