BugTraq
First vulnerabilities in the SP2 - XP ?... Aug 16 2004 01:58PM
Jérôme ATHIAS (jerome athias caramail com) (4 replies)
Re: First vulnerabilities in the SP2 - XP ?... Aug 19 2004 03:57AM
Robert Decker (rdecker esbsystems com)
Re: First vulnerabilities in the SP2 - XP ?... Aug 18 2004 07:41AM
Radoslav DejanoviÄ? (radoslav dejanovic opsus hr)
Re: First vulnerabilities in the SP2 - XP ?... Aug 17 2004 05:02PM
Colin Alston (karnaugh karnaugh za net)
Re: First vulnerabilities in the SP2 - XP ?... Aug 17 2004 04:29PM
Oliver Schneider (Borbarad gmxpro net) (1 replies)
Hi,

> http://www.heise.de/security/artikel/50051
I also read this yesterday (the German version) and I think it's not a
vulnerability. It's IMO a misconception in the way how SP2 treats alien
executables. And on the other hand it does not actually lower the value of
SP2 concerning security - because the rest of SP2 already boosted security
(this time despite compatibility issues - thanks to MS for finally skipping
compatibility in favor of security). But I agree with the author that MS
should fix this anyway!

Can someone please check if ShellExecute()/ShellExecuteEx() behave different
from the CreateProcess-functions *)? Could that be the reason?
Where is the information stored, that a file was downloaded - ADS? - EAs?
... some arcane new feature?

Oliver

*) CreateProcess, CreateProcessAsUser, CreateProcessWithLogonW,
CreateProcessWithTokenW

--
---------------------------------------------------
May the source be with you, stranger ... ;)

[ reply ]
RE: First vulnerabilities in the SP2 - XP ?... Aug 18 2004 06:04PM
Larry Seltzer (larry larryseltzer com)


 

Privacy Statement
Copyright 2010, SecurityFocus