AplusWebMaster
Topic Starter
FYI…
- http://www.avertlabs.com/research/blog/?p=253
April 10, 2007 ~ "Some of these flaws may allow for remote code execution. McAfee Avert Labs is investigating all these zero-days. Today is Patch Tuesday for April. So, yes: this is yet another time that zero-day flaws have been published around a Patch Tuesday, possibly to maximize the public’s exposure to these flaws until the next month’s Patch Tuesday.
Update, 2pm PST
Further research by Avert Labs indicates that all but one of the Office zero-days reported yesterday result in denial of service. There is one heap-overflow flaw that might be exploited for code execution. We’ll keep you updated.
Update, 5pm PST
Avert Labs has been analyzing proof-of-concept code for a zero-day vulnerability in Microsoft Windows’s handling of HLP files. This is another heap-overflow flaw that might be exploited for code execution. Stay tuned."
- http://news.com.com/2102-1002_3-6175011.ht…g=st.util.print
Apr 10 2007 ~ "… McAfee is still investigating the security vulnerabilities. They may not actually all be new, said Dave Marcus, security research and communications manager at (McAfee). "Sometimes what people claim to be zero-days may in fact be related to something that's already known," he said. Should the three Office bugs be new, the tally of zero-day vulnerabilities in the productivity suite waiting for a fix would jump to five. Microsoft did not deliver any patches for Office on Tuesday*…"
* See: http://forums.tomcoyote.org/index.php?s=&a;…st&p=367363

- http://www.avertlabs.com/research/blog/?p=253
April 10, 2007 ~ "Some of these flaws may allow for remote code execution. McAfee Avert Labs is investigating all these zero-days. Today is Patch Tuesday for April. So, yes: this is yet another time that zero-day flaws have been published around a Patch Tuesday, possibly to maximize the public’s exposure to these flaws until the next month’s Patch Tuesday.
Update, 2pm PST
Further research by Avert Labs indicates that all but one of the Office zero-days reported yesterday result in denial of service. There is one heap-overflow flaw that might be exploited for code execution. We’ll keep you updated.
Update, 5pm PST
Avert Labs has been analyzing proof-of-concept code for a zero-day vulnerability in Microsoft Windows’s handling of HLP files. This is another heap-overflow flaw that might be exploited for code execution. Stay tuned."
- http://news.com.com/2102-1002_3-6175011.ht…g=st.util.print
Apr 10 2007 ~ "… McAfee is still investigating the security vulnerabilities. They may not actually all be new, said Dave Marcus, security research and communications manager at (McAfee). "Sometimes what people claim to be zero-days may in fact be related to something that's already known," he said. Should the three Office bugs be new, the tally of zero-day vulnerabilities in the productivity suite waiting for a fix would jump to five. Microsoft did not deliver any patches for Office on Tuesday*…"
* See: http://forums.tomcoyote.org/index.php?s=&a;…st&p=367363