Re: [SECURITY] [DSA 2324-1] wireshark security update

Giovanni Mascellani <[email protected]>
Newsgroups gmane.linux.debian.curiosa
Organization Debian
Message-ID <[email protected]>
On 21/10/2011 09:38, A Mennucc wrote:
> On Thu, Oct 20, 2011 at 09:45:59PM +0200, Moritz Muehlenhoff wrote:
>> Package        : wireshark
>> Vulnerability  : programming error
>> Problem type   : remote
>> Debian-specific: no
>> CVE ID         : CVE-2011-3360 
>>
>> The Microsoft Vulnerability Research group discovered that insecure
>> load path handling could lead to execution of arbitrary Lua script code.
> 
> How comes that Microsoft invests money in auditing open-source 
> software?

Just to say that they found (thus there are) more vulnerabilities in
FLOSS software than in their proprietary products...

:-P

Gio.
-- 
Giovanni Mascellani <[email protected]>
Pisa, Italy

Web: http://poisson.phc.unipi.it/~mascellani
Jabber: [email protected] / [email protected]
signature.asc (application/pgp-signature, 1 KB)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iQIcBAEBCgAGBQJOoWBrAAoJEEP4TcYIk4DkKhAQALUxqh3EZajLPsKXmJvgAxrq
l8cJX4FRHZwYzV+o7/GnrOSotVBEqNSA+EPLM3phSR5JBPIoEXmBogfPBpYxSdN8
1xnot9e7lrF/2RdbtyJWGwBWcbj1k/1p16PlWZTlKDua4cwTL9iqKi06YG40HNS2
hyyv1v/tcRDskhkDp3g07FgYS60MrIGdhNp+FoyzxycQpwq8VQ05DW7+VqpzNb2U
k7gWFNrUsJErWYrXlILPA1Wo7S2lnCR3H8ffjmvpOGdeKg/M8ED+vC+fv7LNKT0y
Zp81fVCLiVzDgnrv3HZPyAamTC/esDwlD52ULi3EnNLeuuGVJvWNWKgeAB2jPhY4
LMv7zXPss7GUQ3h/Vz4FaaRMIMg0TYa7KFxY3+2myAWD6jcJwGulaQ0ar+Rk2ExZ
b3wiQgbbYxlPToQd9Do7pSpO/pE1203fHUzJN3r7YD9bKM08wRq03gLipmkg0WR7
jnTNA9kJocoYw6+Nqstw4C7mHP38mBlcMURupRcYldLeV/qBvd6lUspCLNsRj1kL
pSK6TqlkcFQyR+TyVUsaoKVb2kyz5J1Z6CCaw4FYJPYXnnTEYbsVGB3uyxXLrI5K
dbOtBfZd3PrMMZohTbEv43CPAakVhM5DMAuYG3uvpG2C/AREydm/FWijH09qVLAV
7CctW4j1gT3qhdavRm9MiF4EAREKAAYFAk6hYGsACgkQBIoTAU7n/+MnmgD+JrEI
CVjzMRua+X2eL05JnoOc/BsXLBmrhY4nenRFFPwA/jqT7/7QDERF/C7Sbv9y9oOl
KAQeo0HxP9cosD73g6Ac
=whkx
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.