Tom: This is a *new* exploit. No patch has been issued at this time.
| Microsoft Security Advisory (912840): Vulnerability in Graphics
| Rendering Engine Could Allow Remote Code Execution
|
http://www.microsoft.com/technet/sec...ry/912840.mspx
--
===
Tom [Pepper] Willett
Microsoft MVP - FrontPage
---
FrontPage Support:
http://www.frontpagemvps.com/
About FrontPage 2003:
http://office.microsoft.com/home/off...tid=FX01085802
===
"Thomas A. Rowe" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
| FYI:
|
| The WMF remote security exploit was discovered on November 8th:
|
http://www3.ca.com/securityadvisor/v....aspx?id=33579
|
| A patch for the WMF remote security exploit was issues by MS on November
9th:
|
http://support.microsoft.com/?kbid=896424
|
http://www.microsoft.com/athome/secu...ns/200511.mspx
|
http://www.microsoft.com/technet/sec.../ms05-053.mspx
|
| --
| ==============================================
| Thomas A. Rowe (Microsoft MVP - FrontPage)
| ==============================================
| If you feel your current issue is a results of installing
| a Service Pack or security update, please contact
| Microsoft Product Support Services:
|
http://support.microsoft.com
| If the problem can be shown to have been caused by a
| security update, then there is usually no charge for the call.
| ==============================================
|
| "Ratatooie" <(E-Mail Removed)> wrote in message
news:43b40e84$(E-Mail Removed)...
| >
| > "Joe Rohn" <(E-Mail Removed)> wrote in message
| > news:(E-Mail Removed)...
| >> Hi Rick,
| >>
| >> One thing that concerns me about OSCommerce (Or any open source cart)
are the potential security
| >> risks. It would seem to me that by their very nature open source
applications would make easier
| >> targets for hacking.
| >
| > So, what you selling? Your opinion about open source is BS.
| >
| > (Hey, I love FP myself, but don't spout BS.)
| >
| > Want examples? Check Slashdot today for the WMF remote security exploit
that has been in the wild
| > taking over windows computers for three months (unpatched as of yet by
microsoft with no
| > workaround that doesnt break the computer or involve "dont get on the
net"). One of my users ran
| > into this thing and we had to format the drive to get control of it
again just because she went to
| > a web page that had an AD IMAGE that was infected with the thing. That's
CLOSED SOURCE for you.
| >
| > Open vs. Closed is meaningless as far as "hackability". Bad code is bad
code. At least with open
| > source, there is someone looking at it, and when something is found
there is a larger community of
| > people helping to fix. Right now, you are at the mercy of what micrsoft
decides to do and risk
| > getting put in jail if you make your own patch to fix their copyrighted
closed source OS.
| >
| > OP needs to get a 3rd party host experienced in eCommerece sites.
Hosting on his own PC is just
| > about the best way to get shut down by the CC company, lose all
customers and end up owing the
| > Russian mafia protection fees. It's frightening that he's even
considering it. (Not that everybody
| > shouldn't but a guy asking his friends about FrontPage certainly
shouldn't.)
| >
|
|