Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [ISN] eEye spots another gaping hole in Outlook and Explorer |
|---|---|
| Date: | Thu, 8 Sep 2005 01:38:19 -0500 (CDT) |
http://www.techworld.com/security/news/index.cfm?NewsID=4353 By Matthew Broersma Techworld 07 September 2005 Microsoft says it is investigating a new high-risk security flaw affecting Outlook and Internet Explorer, adding to the growing number of serious bugs that have been reported to the vendor but remain unfixed. eEye Digital Security disclosed the new bug, a buffer-overflow flaw potentially allowing attackers to execute malicious code on a system, last week. The bug affects default installations of Outlook, Outlook Express and Internet Explorer on Windows 2000 and Windows XP with Service Pack 1 installed, although eEye said additional versions of Windows may also be affected. Microsoft said it is investigating the problem, and may issue a fix in the future. The company said it isn't aware of any exploits using the flaw. In order to minimise the danger from unpatched bugs, eEye doesn't disclose more than the bare minimum of information on a flaw until it has been patched or the vendor has tested a workaround. However, the number of unpatched high-risk flaws eEye and other vendors have reported to Microsoft products is substantial, with some dating back several months. Security researchers usually urge vendors to patch flaws within a few weeks of the initial report, arguing that bugs can be detected by potential attackers just as easily as by legitimate researchers. eEye alone says it has nine bug reports awaiting patches from Microsoft, the oldest of which dates from the end of March. Most are high-risk, affecting software such as Internet Explorer, Outlook and system-level software. Software from Macromedia and RealNetworks also has a total of three unpatched, high-risk flaws, according to eEye. _________________________________________ Attend ToorCon Sept 16-18th, 2005 Convention Center San Diego, California www.toorcon.org
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [ISN] Bug hunters, software firms in uneasy alliance, InfoSec News |
|---|---|
| Next by Date: | [ISN] Security consortium offers C&A credential, InfoSec News |
| Previous by Thread: | [ISN] Bug hunters, software firms in uneasy alliance, InfoSec News |
| Next by Thread: | [ISN] Security consortium offers C&A credential, InfoSec News |
| Indexes: | [Date] [Thread] [Top] [All Lists] |