[VulnDiscuss] Trend Vulns Rev 2.0 Reply from Trend Micro

Rod Boron <[email protected]>
Newsgroups gmane.comp.security.vulnerabilities.watch.general
Message-ID <[email protected]>
Date:  Wed, 22 Jan 2003 14:41:02 +0100
From: "herbert tenhagen"
<[email protected]>
To: [email protected]
Subject: RE: Assorted Trend Vulns Rev 2.0

Rod:

 > *******Trend Officescan password
change/bypass*******
Trend Micro developed an adminstration tool called
"CGI_NTFS". This 
Tool 
is part of the toolbox which gets installed by default
during the 
OfficeScan installation. Since Officescan Version 5.02
this toolbox is 
also available via the administration web interface.
For deeper 
detailed 
information please look into solution id#13353 in the
solutionbank of 
Trend Micro 
(http://kb.trendmicro.com/solutions/solutionDetail.asp?solutionId=13353).

 > *******Trend Scanmail Password Bypass*******
Trend Micro is aware of this vulnerability and
provides workarounds and
fixes at: 
http://kb.trendmicro.com/solutions/solutionDetail.asp?solutionId=13352

ScanMail for Exchange v3.81 (for Microsoft Exchange
Server 5.5) and
ScanMail for Exchange v6.1 (for Microsoft Exchange
Server 2000) are not
affected by this vulnerability.

 > *******Trend Micro TVCS IIS Dos*******
 > *******Trend Micro TVCS Log Collector*******
TVCS has been replaced through TMCM (Trend Micro
Control Manager). This 
product is not affected.

see also:
http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0021.html

regards
	Herbert Tenhagen

__________________________________________________
Do you Yahoo!?
Yahoo! Mail Plus - Powerful. Affordable. Sign up now.
http://mailplus.yahoo.com
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.