[32077] in bugtraq

home help back first fref pref prev next nref lref last post

Microsoft got it wrong

daemon@ATHENA.MIT.EDU (Richard M. Smith)
Wed Oct 15 17:34:28 2003

From: "Richard M. Smith" <rms@computerbytesman.com>
To: "'Giovanni Campagnoli'" <bioia@yahoo.com>, <bugtraq@securityfocus.com>
Date: Wed, 15 Oct 2003 16:51:29 -0400
Message-ID: <009901c3935e$1bf7f630$550ffea9@rms>
MIME-Version: 1.0
Content-Type: text/plain;
	charset="us-ascii"
In-Reply-To: <20031015191009.44506.qmail@web13601.mail.yahoo.com>
Content-Transfer-Encoding: 8bit

Only last month in USA Today, Microsoft was claiming that Windows Messenger
didn't represent a security hazard:

   Pop-ups assail through Windows
   http://www.usatoday.com/tech/news/2003-09-24-popups_x.htm

   Microsoft views pop-up boxes as a benign nuisance 
   that does "not pose a security risk," says Greg Sullivan, 
   product manager for Windows. 

Looks like Microsoft crystal ball is pretty fuzzy.  Windows Messsenger is
just the sort of seldom-used feature that should be turned off by default in
Windows XP.

Richard M. Smith
http://www.ComputerBytesMan.com

-----Original Message-----
From: Giovanni Campagnoli [mailto:bioia@yahoo.com] 
Sent: Wednesday, October 15, 2003 3:10 PM
To: bugtraq@securityfocus.com
Subject: Microsoft Windows Security Bulletin Summary October

Microsoft Security Bulletin MS03-043 - Buffer Overrun
in Messenger Service Could Allow Code Execution
(828035)


home help back first fref pref prev next nref lref last post