[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-Id: <201009082113.o88LDvqF010596@bari.maths.usyd.edu.au>
Date: Thu, 9 Sep 2010 07:13:57 +1000
From: paul.szabo@...ney.edu.au
To: lists@...g.net, uuf6429@...il.com
Cc: full-disclosure@...ts.grok.org.uk, bugtraq@...urityfocus.com
Subject: Re: KeePass version 2.12 <= Insecure DLL
Hijacking Vulnerability (dwmapi.dll)
Christian Sciberras <uuf6429@...il.com> wrote:
> ... the approach to fixing it is not practical ...
> ... it is [the fault of] the underlying dll loading mechanism.
Do you mean that the practical solution would be for MS to set
sensible defaults? It took them many years for SafeDllSearchMode,
expect just as many for CWDIllegalInDllSearch.
In the meantime, let us get all apps fixed. Or install Ubuntu.
Cheers, Paul
Paul Szabo psz@...hs.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics University of Sydney Australia
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists