funsec mailing list archives
RE: [Full-disclosure] WMF round-up, updates and de-mystification
From: "Larry Seltzer" <larry () larryseltzer com>
Date: Tue, 3 Jan 2006 06:49:53 -0500
I have tested and confirmed that this patch only works in specific
scnenarios and does not mitigate the entire issue. Variations still work.I have tested and confirmed that this patch only works in specific scnenarios and does not mitigate the entire issue. Variations still work. Oh really? Do you have any more information on this or do you just like to throw bricks? I have a hard time believing you're right, because it would mean that there are variations of the attack that don't use its fundamental mechanism. All that said, it's clear to me that the rush to adopt this patch is precipitous. For instance, it's largely unnecessary on Windows 9x, NT, and 2K, unless you rely on a specifically vulnerable app, like Notes. Larry Seltzer eWEEK.com Security Center Editor http://security.eweek.com/ http://blog.ziffdavis.com/seltzer Contributing Editor, PC Magazine larryseltzer () ziffdavis com _______________________________________________ Fun and Misc security discussion for OT posts. https://linuxbox.org/cgi-bin/mailman/listinfo/funsec Note: funsec is a public and open mailing list.
Current thread:
- RE: [Full-disclosure] WMF round-up, updates and de-mystification Larry Seltzer (Jan 03)
- <Possible follow-ups>
- RE: [Full-disclosure] WMF round-up, updates and de-mystification Richard M. Smith (Jan 03)
- Message not available
- Re: [Full-disclosure] WMF round-up, updates and de-mystification Paul Schmehl (Jan 05)
- Re: Re: [Full-disclosure] WMF round-up, updates and de-mystification Gadi Evron (Jan 05)
- Re: Re: [Full-disclosure] WMF round-up, updates and de-mystification Blue Boar (Jan 05)
- Re: Re: [Full-disclosure] WMF round-up, updates and de-mystification Gadi Evron (Jan 05)
- Message not available
- Re: Re: [Full-disclosure] WMF round-up, updates and de-mystification Gadi Evron (Jan 05)
- Re: Re: [Full-disclosure] WMF round-up, updates and de-mystification dudevanwinkle () gmail com (Jan 05)
- Re: Re: [Full-disclosure] WMF round-up, updates and de-mystification Gadi Evron (Jan 05)