Re: More information on ZERT patch for ANI 0day

2007-04-04 Thread Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP]
And there's a patch for that Realtek already to go on the download site. (read the caveat section). So far all I've seen/heard is that one. This is patching 7 graphics items not just the one. ...that's 6 more things the folks that throw at me from those Metasploit modules ;-) Jason Frisvold

Re: More information on ZERT patch for ANI 0day

2007-04-04 Thread Jason Frisvold
On 4/3/07, Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] <[EMAIL PROTECTED]> wrote: the community need that they are reacting to. Gadi and the crew work hard and have my respect for their efforts. Agreed. Previous patches worked as advertised with no adverse side effects here. If you are w

Re: More information on ZERT patch for ANI 0day

2007-04-04 Thread Jason Frisvold
On 4/3/07, Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] <[EMAIL PROTECTED]> wrote: And there's a patch for that Realtek already to go on the download site. (read the caveat section). So far all I've seen/heard is that one. Yes, I forgot to mention the patch. This is patching 7 graphics it

Re: [Full-disclosure] More information on ZERT patch for ANI 0day

2007-04-03 Thread Matthew Murphy
On 4/3/07, Stefan Kelm <[EMAIL PROTECTED]> wrote: Has anyone actually checked what this patch does? Who are ZERT and ISOTF respectively ("About ISOTF" at http://www.isotf.org/?page_value=0 says a lot...)? ...or is this an April Fool's joke? The patch is 100% real and it is effective. I've see

Re: More information on ZERT patch for ANI 0day

2007-04-03 Thread Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP]
Hardly. Don't remember that last Zero day in 2006 do you? http://www.eweek.com/article2/0,1895,2019162,00.asp The Zert folks have coded up zero day patches before (VML and WMF anyone?) and are folks actively out in the community. While I'm not ready yet to install third party patches on syste

Re: More information on ZERT patch for ANI 0day

2007-04-03 Thread Stefan Kelm
> Hi, more information about the patch released April 1st can be found here: > > http://zert.isotf.org/ > > Including: > 1. Technical information. > 2. Why this patch was released when eeye already released a third party > patch. Has anyone actually checked what this patch does? Who are ZERT and

More information on ZERT patch for ANI 0day

2007-04-02 Thread Gadi Evron
Hi, more information about the patch released April 1st can be found here: http://zert.isotf.org/ Including: 1. Technical information. 2. Why this patch was released when eeye already released a third party patch. The newly discovered zero-day vulnerability in the parsing of animated cursors is