MS02-064 fix time
From: David Litchfield (david@ngssoftware.com)Date: 11/14/02
- Previous message: securma massine: "IISPop remote DOS"
- Next in thread: Steven M. Christey: "Re: MS02-064 fix time"
- Reply: Steven M. Christey: "Re: MS02-064 fix time"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: "David Litchfield" <david@ngssoftware.com> To: <bugtraq@securityfocus.com> Date: Thu, 14 Nov 2002 13:41:53 -0000
MS02-064 discusses a vulnerability where clicking on start->run can lead to
an unsuspecting user running another (malicious) user's trojan.
I warned MS of this back in on September 6th 1999 whilst 2k was still in
BETA (See the bottom of the following mail)
http://security-archive.merton.ox.ac.uk/bugtraq-199909/0145.html
I wonder if this is the longest time it has taken for a "fix" to be made
public after disclosure?
David Litchfield
- Previous message: securma massine: "IISPop remote DOS"
- Next in thread: Steven M. Christey: "Re: MS02-064 fix time"
- Reply: Steven M. Christey: "Re: MS02-064 fix time"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|