AplusWebMaster
Topic Starter
FYI…
- http://preview.tinyurl.com/2zawqm
September 05, 2007 (Computerworld) - "… According to two advisories published by the U.S. Computer Emergency Readiness Team (US-CERT), the ActiveX control that enables Intuit Inc.'s QuickBooks Online Edition contains flaws that attackers can exploit simply by getting users to view an HTML e-mail message or visit a malicious Web site. Of the two bugs discovered and reported by US-CERT researcher Will Dormann, the one spelled out here* is the most dangerous. Not only could attackers seed a vulnerable Windows PC with malware, said Dormann, but "an attacker can also retrieve arbitrary files from a victim's computer"… According to Dormann, Version 9, and possibly those prior to that, contain the ActiveX vulnerabilities. US-CERT recommended that users update to Version 10 as soon as possible…"
* http://www.kb.cert.org/vuls/id/979638
Last Updated: 09/04/2007 - "…Solution: Apply an update:
This issue is addressed in version 10 of the QuickBooks Online Edition ActiveX control. The fixed version of the QuickBooks Online Edition ActiveX control can be installed from the QuickBooks Online Edition web site…"
Also: http://www.kb.cert.org/vuls/id/907481
> http://secunia.com/advisories/26659/
> http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-0322
Last revised: 9/6/2007
.
- http://preview.tinyurl.com/2zawqm
September 05, 2007 (Computerworld) - "… According to two advisories published by the U.S. Computer Emergency Readiness Team (US-CERT), the ActiveX control that enables Intuit Inc.'s QuickBooks Online Edition contains flaws that attackers can exploit simply by getting users to view an HTML e-mail message or visit a malicious Web site. Of the two bugs discovered and reported by US-CERT researcher Will Dormann, the one spelled out here* is the most dangerous. Not only could attackers seed a vulnerable Windows PC with malware, said Dormann, but "an attacker can also retrieve arbitrary files from a victim's computer"… According to Dormann, Version 9, and possibly those prior to that, contain the ActiveX vulnerabilities. US-CERT recommended that users update to Version 10 as soon as possible…"
* http://www.kb.cert.org/vuls/id/979638
Last Updated: 09/04/2007 - "…Solution: Apply an update:
This issue is addressed in version 10 of the QuickBooks Online Edition ActiveX control. The fixed version of the QuickBooks Online Edition ActiveX control can be installed from the QuickBooks Online Edition web site…"
Also: http://www.kb.cert.org/vuls/id/907481
> http://secunia.com/advisories/26659/
> http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-0322
Last revised: 9/6/2007
.