New User, Welcome!     Login

Latest Intel Pro/10* ethernet adaptor drivers contain vulnerable MSVC runtime!

Related Terms:
Visual C ethernet network
From: "Stefan Kanthak" <stefan kanthak nexgo de>
To: <bugtraq securityfocus com>
Cc: "Microsoft Security Response Center" <secure microsoft com>, <secure intel com>
Subject: Latest Intel Pro/10* ethernet adaptor drivers contain vulnerable MSVC runtime!
Date: Fri - Jan 01, 2009 07:47 PM


Hi @ll,

Intel just released updated drivers for their ethernet network adaptors,
see
<http://downloadcenter.intel.com/Detail_Desc.aspx?agr=Y&DwnldID=17906&ProdId=3025&lang=eng>
and
<http://downloadcenter.intel.com/Detail_Desc.aspx?agr=Y&DwnldID=18518&ProdId=3025&lang=eng>
for example.

Unfortunately ALL these driver packages but contain an outdated and
unsupported "Microsoft Visual C++ 2008 Runtime", repackaged as
VC90_CRT_{x86,ia64,x64}.msi and violating Microsofts redistribution
rules, which installs VULNERABLE runtime DLLs.

See <http://support.microsoft.com/kb/973551>,
<http://support.microsoft.com/kb/973552> and
<http://www.microsoft.com/technet/security/bulletin/MS09-035.mspx>

Stefan Kanthak




Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!