AplusWebMaster
Topic Starter
FYI…
- http://secunia.com/advisories/17024/
"Release Date: 2005-10-04
Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Unpatched …
…The vulnerability has been reported in version 5.0.20.0. Other versions may also be affected.
Solution: Filter malicious CAB files at the perimeter…
Original Advisory: http://www.rem0te.com/public/images/kaspersky.pdf …"
- http://www.techweb.com/article/printableAr…_section=700028
October 04, 2005
"…Kaspersky confirmed the vulnerability in an e-mail to TechWeb, it also said it had already stymied possible exploits by building and releasing a package of signatures that detect possible exploits. "This set of signatures was added to the anti-virus databases of Kaspersky Anti-Virus on September 29, significantly reducing the chances of successful use of the .cab vulnerability exploits," spokesman Alexey Zernov said in the e-mail. He also noted that Wheeler did not publish exploit code, a fact that would make it more difficult for attackers to leverage the vulnerabilities. Zernov also said that company developers were working on an emergency update that would include changes to the .cab scanning module. Kaspersky will release the fix Wednesday, Oct. 5…"

- http://secunia.com/advisories/17024/
"Release Date: 2005-10-04
Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Unpatched …
…The vulnerability has been reported in version 5.0.20.0. Other versions may also be affected.
Solution: Filter malicious CAB files at the perimeter…
Original Advisory: http://www.rem0te.com/public/images/kaspersky.pdf …"
- http://www.techweb.com/article/printableAr…_section=700028
October 04, 2005
"…Kaspersky confirmed the vulnerability in an e-mail to TechWeb, it also said it had already stymied possible exploits by building and releasing a package of signatures that detect possible exploits. "This set of signatures was added to the anti-virus databases of Kaspersky Anti-Virus on September 29, significantly reducing the chances of successful use of the .cab vulnerability exploits," spokesman Alexey Zernov said in the e-mail. He also noted that Wheeler did not publish exploit code, a fact that would make it more difficult for attackers to leverage the vulnerabilities. Zernov also said that company developers were working on an emergency update that would include changes to the .cab scanning module. Kaspersky will release the fix Wednesday, Oct. 5…"