Re: Re: Begs a question: AV in Linux (correction)

Is a little misleading:
wine - Just because a windows exploit exists in windows, does not mean it exists in wine.
For example - if windows has a buffer exploit somewhere in its dlls,
True for buffer overflows.

that does not mean it will exist in wine (and vice-versa). This is
because the wine team is re-implementing the windows API without
looking at the windows code, and the implementations will differ.
The code will differ but the interface won't (or shouldn't) and if the
virus uses that interface to get its hooks, it will still work:
"the same vulnerability as CVE-2005-4560 but in a different codebase."

Not correct in the least - openoffice can't run word macros (although
you can chose to preserve them).
I think the point was about the potential danger of macros in general
and the fact that an AV will spot them quite easily.


