|
|||||||||||
|
RE: Question: Buffer Overrun in Microsoft Data Access Components Coul d Lead to Code Execution (Q329414)
From: Stefan Lister <SLister(at)ariba.com>
Date: Sat Nov 30 2002 - 00:35:08 EST
One concern I have is that the MDAC version now shows up as version 2.7 GOLD when hfnetchk is run against an upgraded server. Further, there is a recommendation to upgrade to MDAC 2.7 sp1 which, as far as I can tell, cannot be downloaded from Microsoft's site.
-----Original Message-----
I have the same concerns with the message contained in the security bulletin. When I read between the lines, it seems to me that the "more permanent" solution referred to will be the one Microsoft already has in their back pocket... upgrade to 2.7. It is possible to prevent users from adding entries to the trusted publishers list, but when combined with removing Microsoft from the Trusted Publishers, it results in an unacceptable browser configuration for us. We are, therefore, focusing our resources on a 2.7 upgrade for our systems. I'd like to hear from others about their reaction/solution to the bulletin. While Microsoft categorizes the vulnerability as critical, our representative was surprised we were calling for any info about it. Apparently we were the only ones. > -----Original Message-----
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:25 EDT |
||||||||||
|
|||||||||||