|
|
 |
| New User, Welcome! Login |
Latest Intel Pro/10* ethernet adaptor drivers contain vulnerable MSVC runtime!
| From: |
"Stefan Kanthak" <stefan kanthak nexgo de> |
| To: |
<bugtraq securityfocus com> |
| Cc: |
"Microsoft Security Response Center" <secure microsoft com>, <secure intel com> |
| Subject: |
Latest Intel Pro/10* ethernet adaptor drivers contain vulnerable MSVC runtime! |
| Date: |
Fri - Jan 01, 2009 07:47 PM |
Hi @ll,
Intel just released updated drivers for their ethernet network adaptors,
see
<http://downloadcenter.intel.com/Detail_Desc.aspx?agr=Y&DwnldID=17906&ProdId=3025&lang=eng>
and
<http://downloadcenter.intel.com/Detail_Desc.aspx?agr=Y&DwnldID=18518&ProdId=3025&lang=eng>
for example.
Unfortunately ALL these driver packages but contain an outdated and
unsupported "Microsoft Visual C++ 2008 Runtime", repackaged as
VC90_CRT_{x86,ia64,x64}.msi and violating Microsofts redistribution
rules, which installs VULNERABLE runtime DLLs.
See <http://support.microsoft.com/kb/973551>,
<http://support.microsoft.com/kb/973552> and
<http://www.microsoft.com/technet/security/bulletin/MS09-035.mspx>
Stefan Kanthak
|
|
|
Copyright © 1995-2012 LinuxRocket.net. All rights reserved.
Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!