|
|
ru.linux- RU.LINUX --------------------------------------------------------------------- From : Sergey_Afonin 2:5057/29.13 13 Feb 2002 12:31:14 To : Victor Wagner Subject : Re: процент линукса на рынке ПО -------------------------------------------------------------------------------- Victor Wagner wrote: > KT> пользуешься. Как приходит какой-нибудь нераспознаваемый > KT> аттачмент - значит, оутлук принял новый стандарт. > > Hу я не пользуюсь, а у меня в конторе народ поровну пользуется > мышью и аутлуком. С последним хлопот до последнего времени > (до последней эпидемии nimda) было меньше. Hадо бы патчик поставить. Будет еще больше: [ GFISEC04102001 ] Internet Explorer and Access allow macros to be executed automatically Date: Tue, 12 Feb 2002 12:24:00 +0100 From: "Sandro Gauci" <sandro@gfi.com> To: <bugtraq@securityfocus.com> GFI Security Labs Advisory http://www.gfi.com/ ----[Title: [ GFISEC04102001 ] Internet Explorer and Access allow macros to be executed automatically ----[Published: 12.FEB.2002 ----[Vendor Status: Microsoft has been informed and we have worked with them to release a patch. ----[Systems Affected: Windows machines with : * Microsoft Access and * Internet Explorer version 5 till version 6. Older versions may be vulnerable as well. * Outlook Express 2000, * Outlook Express 98, * Outlook 2000, * Outlook 98 * possibly other HTML and/or Javascript enabled email clients. ----[The problem: GFI, developer of email content checking & network security software, has recently discovered a security flaw within Internet Explorer which allows a malicious user to run arbitary code on a target machine as it attempts to view a website or an HTML email. The problem is exploited by embedding a VBA code within a Access database file (.mdb) within an Outlook Express email file or Multipart HTML (mht) file. If the email file is accessed using Internet Explorer, the attachment may be automatically executed without triggering any security alerts. The exploit will work regardless of the security level (in our labs, we also tested it with High Security and Restricted Zone). И так далее. -- С уважением, Сергей Афонин. asy@kraft-s.ru --- ifmail v.2.15dev5 * Origin: Kraft-S (2:5057/29.13@fidonet) Вернуться к списку тем, сортированных по: возрастание даты уменьшение даты тема автор
Архивное /ru.linux/102776c35ae90.html, оценка из 5, голосов 10
|