A DLL is canned functionality, so if you include a vulnerable DLL in an application, that application is by default vulnerable. |
Even though Windows Media Player is not something generally used to render images, it has the capability of doing that. It's not difficult to create a Web page that uses Windows Media Player to display an image instead of the default application. I think it's a ripe target for exploitation if we see public exploit code for it. |
He wasn't even drinking or anything. Never drank before. |
I would certainly recommend that users implement the vendor workarounds until a patch is made available, ... We feel that exploit code can and will be created. |
I would certainly recommend that users implement the vendor workarounds until a patch is made available. We feel that exploit code can and will be created. |
In 2005, we were credited with reporting 3 'critical' vulnerabilities to Microsoft, and we want to encourage our contributors to keep looking in that direction. |
It seems like there is some flaky code in portions of the libraries that handle the WMF files. It wouldn't surprise me if we see more vulnerabilities emerge, which I am sure will be followed by more media coverage. |
It was definitely a surprise to see Cisco's reaction. I don't think that's the best approach. I do feel that it is happening less and that vendors are realizing that we don't want to work against them, but with them. |
Many of our most valuable contributors consistently identify significant vulnerabilities that may never make the front page, but both avert major exploitation and secure considerable compensation through our rewards program. |
Ocean Champions has the potential to be one of the most transformative things we've ever done in the whole conservation movement. |
Orders are slow right now. |
Patching is very urgent, ... We expect public exploit code to become available, especially for the MSDTC issue. |
Patching is very urgent. We expect public exploit code to become available, especially for the MSDTC issue. |
The attraction is that we are not bogged down in tremendous bureaucracies and processes that make it difficult to get the transactions done. |
The nice thing is that a third party that has nothing to do with [the VCP] is deciding what the criticality is. We're still signing the contract with the researcher and we're still paying the fee for the specific contributor, but we're saying that if it results in a critical bulletin, there's a $10,000 bonus on the table. |