Full Disclosure mailing list archives

Re: MSA-2524375 fraudulent digital certification updates on Windows Phone


From: アドリアンヘンドリック <unixfreaxjp22 () gmail com>
Date: Sat, 26 Mar 2011 04:05:08 +0900

Followingly I read article in the below url:
http://www.winrumors.com/microsoft-working-on-new-windows-phone-7-update-to-patch-fraudulent-ssl-certificates/

which quoted Microsoft statement as per below:
“Fraudulent digital certificates are not a Microsoft security vulnerability”
explained Microsoft Trustworthy Computing manager Bruce Cowper. “We have
been working to develop a mitigation update for Windows Phones,” added
Cowper. Microsoft has not provided a specific time-line for the update
saying it will provide “additional guidance as it comes available.”

Which means that,
1. the smartphone updates for fraudulent digital certification is not
included in the MSA-2524375.
2. Microsoft agreed that until the update released smartphone platform/
windows phone browser still have the fraudulent digital certificates
problem.
----
best regards,
Hendrik ADRIAN
http://0day.jp

2011/3/25 アドリアンヘンドリック <unixfreaxjp22 () gmail com>

Please help to advise the clarification of the MSA-2524375 updates, it may
related to the zeroday.
Regarding to the fraudulent digital certification on March 23rd, 2011
Microsoft was releasing Microsoft Security Advisory 2524375 as per below
url:
http://www.microsoft.com/technet/security/advisory/2524375.mspx

which describing "..An update is available for all supported versions of
Windows to help address this issue.."
I was reviewing the updates described my Micorosoft is the below url:
http://support.microsoft.com/kb/2524375

..and found that Windows Phone a.k.a Windows Mobile wasn't included into
the updates. Does it mean that Microsoft stated that smartphone browser is
not affected by the fraudulent digital certification? Please kindly explain
if I was wrong.
----
best regards,
Hendrik ADRIAN
http://0day.jp
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: