lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <402A57D6.3060502@drippingdead.com>
From: cdowns at drippingdead.com (cdowns)
Subject: EEYE: Microsoft ASN.1 Library Length	Overflow
 Heap Corruption

I agree, there is a problem with that because most Microsoft patches are 
updating a dll. So if your are not looking for both you dont have an 
accurate check.

I know this first hand from writing crappy Microcrap perl patch auditing 
tools.

~!>D

Joao Gouveia wrote:

>I can't say about Retina, but nessus only seams to check the existence
>of the hotifx by looking at the registry. 
>
>JG
>
>On Wed, 2004-02-11 at 09:02, Philippe wrote:
>  
>
>>Note that nessus or retina should (not tested) detect remotely that flaw.
>>
>>See nessus pluging source for exploit ;-):
>>- http://cgi.nessus.org/plugins/dump.php3?id=12052
>>
>>Or update your security scanners
>>- http://www.nessus.org
>>- http://www.eeye.com/html/Products/Retina/index.html
>>
>>Hope this helps
>>Regards
>>
>>_______________________________________________
>>Full-Disclosure - We believe in it.
>>Charter: http://lists.netsys.com/full-disclosure-charter.htm
>>
>l
>  
>


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ