[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Full-disclosure] Excel 0-day?



there will be much more 0day spreading like this in the futur I think because idefense pays such bug a really really ridiculous price , Zdi is the one only very good but they are very strict for accepting a bug. It looks like some dudes are taking much profits of this weakness selling to blackhats regarding the 2 office's threats actually hitting....

Denis Jedig wrote:
Paul Szabo wrote:

Ideas (PoC, workaround) anyone?

As often, the information policy is more than unfortunate. No details
are given, the administrators are just advised to "update antivirus",
hole up in some dark corner and chew on a piece of blanket out of fear.
It's the same kind of ignorance regarding customer needs we have seen in
the case of the WMF vulnerability.

Anybody any idea if the problem somehow relates to the Excel
vulnerability offered on eBay in Dec 05?
http://www.securityfocus.com/news/11363

Regards,

Denis

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


__________ NOD32 1.1606 (20060617) Information __________

This message was checked by NOD32 antivirus system.
http://www.eset.com




begin:vcard
fn:Arnaud Dovi / Ind. Security Researcher
n:Dovi;Arnaud
email;internet:ad@xxxxxxxxxxxxxxxx
tel;work:Independent Security Researcher
version:2.1
end:vcard

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/