Full Disclosure mailing list archives

Re: NSFOCUS SA2003-05: Microsoft IIS ssinc.dll Over-long Filename Buffer Overflow Vulnerability


From: Georgi Guninski <guninski () guninski com>
Date: Fri, 30 May 2003 19:14:03 +0300

NSFOCUS Security Team wrote:
Vendor Status:
==============

2002.11.05  Inform vendor about the issue
2003.05.28  Microsoft has issued a Security Bulletin(MS03-018) and the related patch.


More than six months to fix a buffer overflow - few can achieve this.
This is trustworthy indeed.

georgi

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: