OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [Full-Disclosure] EEYE: Microsoft ASN.1 Library Length Overflow Heap Corruption

From: Joao Gouveia (tharbadkaotik.org)
Date: Wed Feb 11 2004 - 09:33:53 CST


I can't say about Retina, but nessus only seams to check the existence
of the hotifx by looking at the registry.

JG

On Wed, 2004-02-11 at 09:02, Philippe wrote:
> Note that nessus or retina should (not tested) detect remotely that flaw.
>
> See nessus pluging source for exploit ;-):
> - http://cgi.nessus.org/plugins/dump.php3?id=12052
>
> Or update your security scanners
> - http://www.nessus.org
> - http://www.eeye.com/html/Products/Retina/index.html
>
> Hope this helps
> Regards
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.netsys.com/full-disclosure-charter.html

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQBAKkthBhvB6ogSmsoRAi6eAJ9SonqMG7x7QlpfU9uRebl6ZXBsAgCeMcVQ
HSenL+HvHv+EbR2OsaH7HR0=
=T8HD
-----END PGP SIGNATURE-----

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html