Full Disclosure mailing list archives

Re: Excel 0-day?


From: "ad () heapoverflow com" <ad () heapoverflow com>
Date: Sun, 18 Jun 2006 15:25:57 +0200

there will be much more 0day spreading like this in the futur I think because idefense pays such bug a really really ridiculous price , Zdi is the one only very good but they are very strict for accepting a bug. It looks like some dudes are taking much profits of this weakness selling to blackhats regarding the 2 office's threats actually hitting....

Denis Jedig wrote:
Paul Szabo wrote:

Ideas (PoC, workaround) anyone?

As often, the information policy is more than unfortunate. No details
are given, the administrators are just advised to "update antivirus",
hole up in some dark corner and chew on a piece of blanket out of fear.
It's the same kind of ignorance regarding customer needs we have seen in
the case of the WMF vulnerability.

Anybody any idea if the problem somehow relates to the Excel
vulnerability offered on eBay in Dec 05?
http://www.securityfocus.com/news/11363

Regards,

Denis

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


__________ NOD32 1.1606 (20060617) Information __________

This message was checked by NOD32 antivirus system.
http://www.eset.com




Attachment: ad.vcf
Description:

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: