Bugtraq mailing list archives
Latest Intel Pro/10* ethernet adaptor drivers contain vulnerable MSVC runtime!
From: "Stefan Kanthak" <stefan.kanthak () nexgo de>
Date: Sat, 2 Jan 2010 04:36:47 +0100
Hi @ll, Intel just released updated drivers for their ethernet network adaptors, see <http://downloadcenter.intel.com/Detail_Desc.aspx?agr=Y&DwnldID=17906&ProdId=3025&lang=eng> and <http://downloadcenter.intel.com/Detail_Desc.aspx?agr=Y&DwnldID=18518&ProdId=3025&lang=eng> for example. Unfortunately ALL these driver packages but contain an outdated and unsupported "Microsoft Visual C++ 2008 Runtime", repackaged as VC90_CRT_{x86,ia64,x64}.msi and violating Microsofts redistribution rules, which installs VULNERABLE runtime DLLs. See <http://support.microsoft.com/kb/973551>, <http://support.microsoft.com/kb/973552> and <http://www.microsoft.com/technet/security/bulletin/MS09-035.mspx> Stefan Kanthak
Current thread:
- Latest Intel Pro/10* ethernet adaptor drivers contain vulnerable MSVC runtime! Stefan Kanthak (Jan 04)