lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <432304273.20071011144853@Zoller.lu>
Date: Thu, 11 Oct 2007 14:48:53 +0200
From: Thierry Zoller <Thierry@...ler.lu>
To: bugtraq@...urityfocus.com, full-disclosure@...ts.grok.org.uk
Subject: Re: URI handling woes in Acrobat Reader, Netscape,
	Miranda, Skype

Dear All,

....Hi everyone.  This is Jonathan from the SWI team in the MSRC.  We’ve just released
Security Advisory 943521 regarding a vulnerability affecting Windows Server 2003 and
Windows XP with Internet Explorer 7 installed.  As you have probably noted there’s
been a fair amount of discussion on this issue. One of the reasons we are releasing
this Advisory is due to increased risk given recent discussions about how this
vulnerability could be used in attacks.  Another reason is to clear up the
confusion we see between the URI issue covered in today’s Advisory and the
protocol handler issue we documented in July in this IE Blog.  The final reason
is we actually contributed to some of the confusion by providing an incorrect
set of talking points to Heise.  Because these issues look very similar we’re
going to have some deep discussion on how Windows handles URIs.

To help explain the difference in detail, my co-workers Dave and Chen have helped
me put together some information...

http://blogs.technet.com/msrc/archive/2007/10/10/msrc-blog-additional-details-and-background-on-security-advisory-943521.aspx



-- 
http://secdev.zoller.lu
Thierry Zoller
Fingerprint : 5D84 BFDC CD36 A951 2C45  2E57 28B3 75DD 0AC6 F1C7

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ