<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>zencurity</title>
	<atom:link href="http://zencurity.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://zencurity.wordpress.com</link>
	<description>security by reason / less information, more knowledge</description>
	<lastBuildDate>Wed, 17 Nov 2010 08:43:43 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='zencurity.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>zencurity</title>
		<link>http://zencurity.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://zencurity.wordpress.com/osd.xml" title="zencurity" />
	<atom:link rel='hub' href='http://zencurity.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Red Hat update for freetype</title>
		<link>http://zencurity.wordpress.com/2010/11/17/red-hat-update-for-freetype-2/</link>
		<comments>http://zencurity.wordpress.com/2010/11/17/red-hat-update-for-freetype-2/#comments</comments>
		<pubDate>Wed, 17 Nov 2010 08:43:43 +0000</pubDate>
		<dc:creator>michaelburger</dc:creator>
				<category><![CDATA[Moderate]]></category>
		<category><![CDATA[DoS]]></category>
		<category><![CDATA[from remote]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[system access]]></category>

		<guid isPermaLink="false">http://zencurity.wordpress.com/2010/11/17/red-hat-update-for-freetype-2/</guid>
		<description><![CDATA[CRITICAL: Moderately critical IMPACT: DoS, System access WHERE: From remote DESCRIPTION: Red Hat has issued an update for freetype. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library. SOLUTION: Updated packages are available via Red Hat Network. http://rhn.redhat.com [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=zencurity.wordpress.com&amp;blog=13287981&amp;post=770&amp;subd=zencurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>CRITICAL:<br />
Moderately critical</p>
<p>IMPACT:<br />
DoS, System access</p>
<p>WHERE:<br />
From remote</p>
<p>DESCRIPTION:<br />
Red Hat has issued an update for freetype. This fixes a<br />
vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.</p>
<p>SOLUTION:<br />
Updated packages are available via Red Hat Network.<br />
<a href="http://rhn.redhat.com">http://rhn.redhat.com</a></p>
<p>ORIGINAL ADVISORY:<br />
RHSA-2010:0889-1:<br />
<a href="https://rhn.redhat.com/errata/RHSA-2010-0889.html">https://rhn.redhat.com/errata/RHSA-2010-0889.html</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/zencurity.wordpress.com/770/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/zencurity.wordpress.com/770/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/zencurity.wordpress.com/770/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/zencurity.wordpress.com/770/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/zencurity.wordpress.com/770/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/zencurity.wordpress.com/770/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/zencurity.wordpress.com/770/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/zencurity.wordpress.com/770/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/zencurity.wordpress.com/770/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/zencurity.wordpress.com/770/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/zencurity.wordpress.com/770/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/zencurity.wordpress.com/770/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/zencurity.wordpress.com/770/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/zencurity.wordpress.com/770/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=zencurity.wordpress.com&amp;blog=13287981&amp;post=770&amp;subd=zencurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://zencurity.wordpress.com/2010/11/17/red-hat-update-for-freetype-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/39564c54e8be656175d5bc2382b17f19?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">zencurity</media:title>
		</media:content>
	</item>
		<item>
		<title>OpenSSL TLS Server Extension Parsing Race Condition Vulnerability</title>
		<link>http://zencurity.wordpress.com/2010/11/17/openssl-tls-server-extension-parsing-race-condition-vulnerability/</link>
		<comments>http://zencurity.wordpress.com/2010/11/17/openssl-tls-server-extension-parsing-race-condition-vulnerability/#comments</comments>
		<pubDate>Wed, 17 Nov 2010 07:30:08 +0000</pubDate>
		<dc:creator>michaelburger</dc:creator>
				<category><![CDATA[Moderate]]></category>
		<category><![CDATA[DoS]]></category>
		<category><![CDATA[from remote]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Mac OS]]></category>
		<category><![CDATA[system access]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://zencurity.wordpress.com/2010/11/17/openssl-tls-server-extension-parsing-race-condition-vulnerability/</guid>
		<description><![CDATA[CRITICAL: Moderately critical IMPACT: DoS, System access WHERE: From remote DESCRIPTION: A vulnerability has been reported in OpenSSL, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise an application using the library. The vulnerability is caused due to a race condition within the TLS extension parsing code, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=zencurity.wordpress.com&amp;blog=13287981&amp;post=768&amp;subd=zencurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>CRITICAL:<br />
Moderately critical</p>
<p>IMPACT:<br />
DoS, System access</p>
<p>WHERE:<br />
From remote</p>
<p>DESCRIPTION:<br />
A vulnerability has been reported in OpenSSL, which can be exploited by malicious people to cause a DoS (Denial of Service) and<br />
potentially compromise an application using the library.</p>
<p>The vulnerability is caused due to a race condition within the TLS extension parsing code, which can be exploited to cause a heap-based buffer overflow.</p>
<p>Successful exploitation requires that the server is multi-threaded and uses the internal caching mechanism of OpenSSL. Multi-processed servers or servers with disabled internal caching session (e.g. Apache HTTP server, Stunnel) are not affected.</p>
<p>The vulnerability is reported in versions 0.9.8f through 0.9.8o and versions 1.0.0 and 1.0.0a.</p>
<p>SOLUTION:<br />
Update to version 0.9.8p and 1.0.0b or apply patches.</p>
<p>ORIGINAL ADVISORY:<br />
<a href="http://www.openssl.org/news/secadv_20101116.txt">http://www.openssl.org/news/secadv_20101116.txt</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/zencurity.wordpress.com/768/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/zencurity.wordpress.com/768/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/zencurity.wordpress.com/768/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/zencurity.wordpress.com/768/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/zencurity.wordpress.com/768/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/zencurity.wordpress.com/768/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/zencurity.wordpress.com/768/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/zencurity.wordpress.com/768/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/zencurity.wordpress.com/768/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/zencurity.wordpress.com/768/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/zencurity.wordpress.com/768/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/zencurity.wordpress.com/768/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/zencurity.wordpress.com/768/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/zencurity.wordpress.com/768/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=zencurity.wordpress.com&amp;blog=13287981&amp;post=768&amp;subd=zencurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://zencurity.wordpress.com/2010/11/17/openssl-tls-server-extension-parsing-race-condition-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/39564c54e8be656175d5bc2382b17f19?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">zencurity</media:title>
		</media:content>
	</item>
		<item>
		<title>Apple QuickTime Sorenson Video 3 Array-Indexing Vulnerability</title>
		<link>http://zencurity.wordpress.com/2010/11/11/apple-quicktime-sorenson-video-3-array-indexing-vulnerability/</link>
		<comments>http://zencurity.wordpress.com/2010/11/11/apple-quicktime-sorenson-video-3-array-indexing-vulnerability/#comments</comments>
		<pubDate>Thu, 11 Nov 2010 11:00:42 +0000</pubDate>
		<dc:creator>michaelburger</dc:creator>
				<category><![CDATA[High]]></category>
		<category><![CDATA[from remote]]></category>
		<category><![CDATA[Mac OS]]></category>
		<category><![CDATA[system access]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://zencurity.wordpress.com/2010/11/11/apple-quicktime-sorenson-video-3-array-indexing-vulnerability/</guid>
		<description><![CDATA[CRITICAL: Highly critical IMPACT: System access WHERE: From remote DESCRIPTION: Secunia Research has discovered a vulnerability in QuickTime, which can be exploited by malicious people to compromise a user&#8217;s system. The vulnerability is caused due to an array-indexing error when parsing Sorenson Video 3 content and can be exploited to corrupt memory during decompression via [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=zencurity.wordpress.com&amp;blog=13287981&amp;post=767&amp;subd=zencurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>CRITICAL:<br />
Highly critical</p>
<p>IMPACT:<br />
System access</p>
<p>WHERE:<br />
From remote</p>
<p>DESCRIPTION:<br />
Secunia Research has discovered a vulnerability in QuickTime, which can be exploited by malicious people to compromise a user&#8217;s system.</p>
<p>The vulnerability is caused due to an array-indexing error when parsing Sorenson Video 3 content and can be exploited to corrupt memory during decompression via a specially crafted file.</p>
<p>Successful exploitation may allow execution of arbitrary code.</p>
<p>The vulnerability is confirmed in versions 7.6.6 and 7.6.8. Other versions may also be affected.</p>
<p>SOLUTION:<br />
This will be addressed in an upcoming version for Windows. A fix is available for Mac OS X.</p>
<p>ORIGINAL ADVISORY:<br />
Apple:<br />
<a onclick="return mugicPopWin(this,event);" oncontextmenu="mugicRightClick(this);" href="http://support.apple.com/kb/HT4435">http://support.apple.com/kb/HT4435</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/zencurity.wordpress.com/767/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/zencurity.wordpress.com/767/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/zencurity.wordpress.com/767/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/zencurity.wordpress.com/767/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/zencurity.wordpress.com/767/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/zencurity.wordpress.com/767/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/zencurity.wordpress.com/767/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/zencurity.wordpress.com/767/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/zencurity.wordpress.com/767/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/zencurity.wordpress.com/767/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/zencurity.wordpress.com/767/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/zencurity.wordpress.com/767/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/zencurity.wordpress.com/767/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/zencurity.wordpress.com/767/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=zencurity.wordpress.com&amp;blog=13287981&amp;post=767&amp;subd=zencurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://zencurity.wordpress.com/2010/11/11/apple-quicktime-sorenson-video-3-array-indexing-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/39564c54e8be656175d5bc2382b17f19?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">zencurity</media:title>
		</media:content>
	</item>
		<item>
		<title>Apple Mac OS X ATSServer CFF Font Parsing Vulnerability</title>
		<link>http://zencurity.wordpress.com/2010/11/09/apple-mac-os-x-atsserver-cff-font-parsing-vulnerability/</link>
		<comments>http://zencurity.wordpress.com/2010/11/09/apple-mac-os-x-atsserver-cff-font-parsing-vulnerability/#comments</comments>
		<pubDate>Tue, 09 Nov 2010 09:01:27 +0000</pubDate>
		<dc:creator>michaelburger</dc:creator>
				<category><![CDATA[High]]></category>
		<category><![CDATA[from remote]]></category>
		<category><![CDATA[Mac OS]]></category>
		<category><![CDATA[system access]]></category>

		<guid isPermaLink="false">http://zencurity.wordpress.com/2010/11/09/apple-mac-os-x-atsserver-cff-font-parsing-vulnerability/</guid>
		<description><![CDATA[CRITICAL: Highly critical IMPACT: System access WHERE: From remote DESCRIPTION: A vulnerability has been reported in Apple Mac OS X, which can be exploited by malicious people to compromise a user&#8217;s system. The vulnerability is caused due to a signedness error in ATSServer when handling the CharStrings INDEX structure and can be exploited to cause [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=zencurity.wordpress.com&amp;blog=13287981&amp;post=766&amp;subd=zencurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>CRITICAL:<br />
Highly critical</p>
<p>IMPACT:<br />
System access</p>
<p>WHERE:<br />
From remote</p>
<p>DESCRIPTION:<br />
A vulnerability has been reported in Apple Mac OS X, which can be exploited by malicious people to compromise a user&#8217;s system.</p>
<p>The vulnerability is caused due to a signedness error in ATSServer when handling the CharStrings INDEX structure and can be exploited to cause a buffer overflow via e.g. a PDF file containing a specially crafted CFF font.</p>
<p>Successful exploitation may allow execution of arbitrary code.</p>
<p>The vulnerability is reported in version 10.5.</p>
<p>SOLUTION:<br />
Upgrade to version 10.6, which is reportedly not affected.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/zencurity.wordpress.com/766/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/zencurity.wordpress.com/766/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/zencurity.wordpress.com/766/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/zencurity.wordpress.com/766/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/zencurity.wordpress.com/766/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/zencurity.wordpress.com/766/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/zencurity.wordpress.com/766/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/zencurity.wordpress.com/766/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/zencurity.wordpress.com/766/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/zencurity.wordpress.com/766/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/zencurity.wordpress.com/766/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/zencurity.wordpress.com/766/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/zencurity.wordpress.com/766/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/zencurity.wordpress.com/766/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=zencurity.wordpress.com&amp;blog=13287981&amp;post=766&amp;subd=zencurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://zencurity.wordpress.com/2010/11/09/apple-mac-os-x-atsserver-cff-font-parsing-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/39564c54e8be656175d5bc2382b17f19?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">zencurity</media:title>
		</media:content>
	</item>
		<item>
		<title>Internet Explorer CSS Tag Parsing Code Execution Vulnerability</title>
		<link>http://zencurity.wordpress.com/2010/11/04/internet-explorer-css-tag-parsing-code-execution-vulnerability/</link>
		<comments>http://zencurity.wordpress.com/2010/11/04/internet-explorer-css-tag-parsing-code-execution-vulnerability/#comments</comments>
		<pubDate>Thu, 04 Nov 2010 09:09:51 +0000</pubDate>
		<dc:creator>michaelburger</dc:creator>
				<category><![CDATA[Extreme]]></category>
		<category><![CDATA[from remote]]></category>
		<category><![CDATA[system access]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://zencurity.wordpress.com/2010/11/04/internet-explorer-css-tag-parsing-code-execution-vulnerability/</guid>
		<description><![CDATA[CRITICAL: Extremely critical IMPACT: System access WHERE: From remote DESCRIPTION: A vulnerability has been reported in Internet Explorer, which can be exploited by malicious people to compromise a user&#8217;s system. The vulnerability is caused due to insufficient memory being allocated to store a certain combination of CSS (Cascading Style Sheets) tags. This can be exploited [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=zencurity.wordpress.com&amp;blog=13287981&amp;post=765&amp;subd=zencurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>CRITICAL:<br />
Extremely critical</p>
<p>IMPACT:<br />
System access</p>
<p>WHERE:<br />
From remote</p>
<p>DESCRIPTION:<br />
A vulnerability has been reported in Internet Explorer, which can be<br />
exploited by malicious people to compromise a user&#8217;s system.</p>
<p>The vulnerability is caused due to insufficient memory being<br />
allocated to store a certain combination of CSS (Cascading Style<br />
Sheets) tags. This can be exploited to overwrite a byte in a virtual<br />
table pointer and call into user-controlled data in memory via a<br />
specially crafted web page.</p>
<p>Successful exploitation allows execution of arbitrary code.</p>
<p>NOTE: The vulnerability is currently being actively exploited.</p>
<p>SOLUTION:<br />
Apply a custom CSS to override website CSS styles (please see the<br />
Microsoft advisory for details).</p>
<p>ORIGINAL ADVISORY:<br />
Microsoft:<br />
<a href="http://www.microsoft.com/technet/security/advisory/2458511.mspx">http://www.microsoft.com/technet/security/advisory/2458511.mspx</a><br />
<a href="http://blogs.technet.com/b/msrc/archive/2010/11/02/microsoft-releases-security-advisory-2458511.aspx">http://blogs.technet.com/b/msrc/archive/2010/11/02/microsoft-releases-security-advisory-2458511.aspx</a><br />
<a href="http://blogs.technet.com/b/srd/archive/2010/11/03/dep-emet-protect-against-attacks-on-the-latest-internet-explorer-vulnerability.aspx">http://blogs.technet.com/b/srd/archive/2010/11/03/dep-emet-protect-against-attacks-on-the-latest-internet-explorer-vulnerability.aspx</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/zencurity.wordpress.com/765/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/zencurity.wordpress.com/765/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/zencurity.wordpress.com/765/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/zencurity.wordpress.com/765/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/zencurity.wordpress.com/765/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/zencurity.wordpress.com/765/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/zencurity.wordpress.com/765/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/zencurity.wordpress.com/765/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/zencurity.wordpress.com/765/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/zencurity.wordpress.com/765/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/zencurity.wordpress.com/765/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/zencurity.wordpress.com/765/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/zencurity.wordpress.com/765/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/zencurity.wordpress.com/765/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=zencurity.wordpress.com&amp;blog=13287981&amp;post=765&amp;subd=zencurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://zencurity.wordpress.com/2010/11/04/internet-explorer-css-tag-parsing-code-execution-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/39564c54e8be656175d5bc2382b17f19?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">zencurity</media:title>
		</media:content>
	</item>
		<item>
		<title>Microsoft Windows DAO 3.6 Object Library Insecure Library Loading Vulnerability</title>
		<link>http://zencurity.wordpress.com/2010/10/29/microsoft-windows-dao-3-6-object-library-insecure-library-loading-vulnerability/</link>
		<comments>http://zencurity.wordpress.com/2010/10/29/microsoft-windows-dao-3-6-object-library-insecure-library-loading-vulnerability/#comments</comments>
		<pubDate>Fri, 29 Oct 2010 16:29:27 +0000</pubDate>
		<dc:creator>michaelburger</dc:creator>
				<category><![CDATA[High]]></category>
		<category><![CDATA[from remote]]></category>
		<category><![CDATA[system access]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://zencurity.wordpress.com/2010/10/29/microsoft-windows-dao-3-6-object-library-insecure-library-loading-vulnerability/</guid>
		<description><![CDATA[CRITICAL: Highly critical IMPACT: System access WHERE: From remote DESCRIPTION: A vulnerability has been discovered in Microsoft Windows, which can be exploited by malicious people to compromise a user&#8217;s system. The vulnerability is caused due to the Data Access Objects library (dao360.dll) loading libraries (e.g. msjet49.dll) in an insecure manner. This can be exploited to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=zencurity.wordpress.com&amp;blog=13287981&amp;post=764&amp;subd=zencurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>CRITICAL:<br />
Highly critical</p>
<p>IMPACT:<br />
System access</p>
<p>WHERE:<br />
From remote</p>
<p>DESCRIPTION:<br />
A vulnerability has been discovered in Microsoft Windows, which can<br />
be exploited by malicious people to compromise a user&#8217;s system.</p>
<p>The vulnerability is caused due to the Data Access Objects library<br />
(dao360.dll) loading libraries (e.g. msjet49.dll) in an insecure<br />
manner. This can be exploited to load arbitrary libraries by tricking<br />
a user into e.g. opening a file located on a remote WebDAV or SMB<br />
share via an application using the library.</p>
<p>Successful exploitation allows execution of arbitrary code.</p>
<p>The vulnerability is confirmed in fully patched versions of Windows<br />
XP Professional SP3, Windows Server 2003 R2 Enterprise Edition SP3,<br />
Windows Vista Business SP1, and Windows 7 Professional. Other<br />
versions may also be affected.</p>
<p>SOLUTION:<br />
Do not open untrusted files.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/zencurity.wordpress.com/764/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/zencurity.wordpress.com/764/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/zencurity.wordpress.com/764/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/zencurity.wordpress.com/764/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/zencurity.wordpress.com/764/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/zencurity.wordpress.com/764/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/zencurity.wordpress.com/764/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/zencurity.wordpress.com/764/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/zencurity.wordpress.com/764/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/zencurity.wordpress.com/764/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/zencurity.wordpress.com/764/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/zencurity.wordpress.com/764/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/zencurity.wordpress.com/764/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/zencurity.wordpress.com/764/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=zencurity.wordpress.com&amp;blog=13287981&amp;post=764&amp;subd=zencurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://zencurity.wordpress.com/2010/10/29/microsoft-windows-dao-3-6-object-library-insecure-library-loading-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/39564c54e8be656175d5bc2382b17f19?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">zencurity</media:title>
		</media:content>
	</item>
		<item>
		<title>Red Hat update for cups</title>
		<link>http://zencurity.wordpress.com/2010/10/29/red-hat-update-for-cups-3/</link>
		<comments>http://zencurity.wordpress.com/2010/10/29/red-hat-update-for-cups-3/#comments</comments>
		<pubDate>Fri, 29 Oct 2010 09:02:39 +0000</pubDate>
		<dc:creator>michaelburger</dc:creator>
				<category><![CDATA[Moderate]]></category>
		<category><![CDATA[from local]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[system access]]></category>

		<guid isPermaLink="false">http://zencurity.wordpress.com/2010/10/29/red-hat-update-for-cups-3/</guid>
		<description><![CDATA[CRITICAL: Moderately critical IMPACT: System access WHERE: From local network DESCRIPTION: Red Hat has issued an update for cups. This fixes some vulnerabilities, which can be exploited by malicious people to potentially compromise a vulnerable system. SOLUTION: Updated packages are available via Red Hat Network. http://rhn.redhat.com ORIGINAL ADVISORY: RHSA-2010-0811: https://rhn.redhat.com/errata/RHSA-2010-0811.html<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=zencurity.wordpress.com&amp;blog=13287981&amp;post=763&amp;subd=zencurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>CRITICAL:<br />
Moderately critical</p>
<p>IMPACT:<br />
System access</p>
<p>WHERE:<br />
From local network</p>
<p>DESCRIPTION:<br />
Red Hat has issued an update for cups. This fixes some<br />
vulnerabilities, which can be exploited by malicious people to<br />
potentially compromise a vulnerable system.</p>
<p>SOLUTION:<br />
Updated packages are available via Red Hat Network.<br />
<a href="http://rhn.redhat.com">http://rhn.redhat.com</a></p>
<p>ORIGINAL ADVISORY:<br />
RHSA-2010-0811:<br />
<a href="https://rhn.redhat.com/errata/RHSA-2010-0811.html">https://rhn.redhat.com/errata/RHSA-2010-0811.html</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/zencurity.wordpress.com/763/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/zencurity.wordpress.com/763/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/zencurity.wordpress.com/763/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/zencurity.wordpress.com/763/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/zencurity.wordpress.com/763/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/zencurity.wordpress.com/763/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/zencurity.wordpress.com/763/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/zencurity.wordpress.com/763/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/zencurity.wordpress.com/763/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/zencurity.wordpress.com/763/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/zencurity.wordpress.com/763/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/zencurity.wordpress.com/763/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/zencurity.wordpress.com/763/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/zencurity.wordpress.com/763/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=zencurity.wordpress.com&amp;blog=13287981&amp;post=763&amp;subd=zencurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://zencurity.wordpress.com/2010/10/29/red-hat-update-for-cups-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/39564c54e8be656175d5bc2382b17f19?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">zencurity</media:title>
		</media:content>
	</item>
		<item>
		<title>Red Hat update for thunderbird</title>
		<link>http://zencurity.wordpress.com/2010/10/29/red-hat-update-for-thunderbird-4/</link>
		<comments>http://zencurity.wordpress.com/2010/10/29/red-hat-update-for-thunderbird-4/#comments</comments>
		<pubDate>Fri, 29 Oct 2010 09:01:21 +0000</pubDate>
		<dc:creator>michaelburger</dc:creator>
				<category><![CDATA[Moderate]]></category>
		<category><![CDATA[from remote]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[system access]]></category>

		<guid isPermaLink="false">http://zencurity.wordpress.com/2010/10/29/red-hat-update-for-thunderbird-4/</guid>
		<description><![CDATA[CRITICAL: Moderately critical IMPACT: System access WHERE: From remote DESCRIPTION: Red Hat has issued an update for thunderbird. This fixes a vulnerability, which can be exploited by malicious people to compromise a user&#8217;s system. SOLUTION: Updated packages are available via Red Hat Network. http://rhn.redhat.com ORIGINAL ADVISORY: RHSA-2010:0812-1: http://rhn.redhat.com/errata/RHSA-2010-0812.html<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=zencurity.wordpress.com&amp;blog=13287981&amp;post=762&amp;subd=zencurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>CRITICAL:<br />
Moderately critical</p>
<p>IMPACT:<br />
System access</p>
<p>WHERE:<br />
From remote</p>
<p>DESCRIPTION:<br />
Red Hat has issued an update for thunderbird. This fixes a<br />
vulnerability, which can be exploited by malicious people to<br />
compromise a user&#8217;s system.</p>
<p>SOLUTION:<br />
Updated packages are available via Red Hat Network.<br />
<a href="http://rhn.redhat.com">http://rhn.redhat.com</a></p>
<p>ORIGINAL ADVISORY:<br />
RHSA-2010:0812-1:<br />
<a href="http://rhn.redhat.com/errata/RHSA-2010-0812.html">http://rhn.redhat.com/errata/RHSA-2010-0812.html</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/zencurity.wordpress.com/762/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/zencurity.wordpress.com/762/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/zencurity.wordpress.com/762/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/zencurity.wordpress.com/762/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/zencurity.wordpress.com/762/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/zencurity.wordpress.com/762/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/zencurity.wordpress.com/762/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/zencurity.wordpress.com/762/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/zencurity.wordpress.com/762/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/zencurity.wordpress.com/762/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/zencurity.wordpress.com/762/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/zencurity.wordpress.com/762/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/zencurity.wordpress.com/762/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/zencurity.wordpress.com/762/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=zencurity.wordpress.com&amp;blog=13287981&amp;post=762&amp;subd=zencurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://zencurity.wordpress.com/2010/10/29/red-hat-update-for-thunderbird-4/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/39564c54e8be656175d5bc2382b17f19?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">zencurity</media:title>
		</media:content>
	</item>
		<item>
		<title>Red Hat update for xulrunner</title>
		<link>http://zencurity.wordpress.com/2010/10/28/red-hat-update-for-xulrunner/</link>
		<comments>http://zencurity.wordpress.com/2010/10/28/red-hat-update-for-xulrunner/#comments</comments>
		<pubDate>Thu, 28 Oct 2010 13:15:18 +0000</pubDate>
		<dc:creator>michaelburger</dc:creator>
				<category><![CDATA[High]]></category>
		<category><![CDATA[from remote]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[system access]]></category>

		<guid isPermaLink="false">http://zencurity.wordpress.com/2010/10/28/red-hat-update-for-xulrunner/</guid>
		<description><![CDATA[CRITICAL: Highly critical IMPACT: System access WHERE: From remote DESCRIPTION: Red Hat has issued an update for xulrunner. This fixes a vulnerability, which can be exploited by malicious people to compromise a user&#8217;s system. SOLUTION: Updated packages are available via Red Hat Network. http://rhn.redhat.com ORIGINAL ADVISORY: RHSA-2010:0809-1: https://rhn.redhat.com/errata/RHSA-2010-0809.html<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=zencurity.wordpress.com&amp;blog=13287981&amp;post=761&amp;subd=zencurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>CRITICAL:<br />
Highly critical</p>
<p>IMPACT:<br />
System access</p>
<p>WHERE:<br />
From remote</p>
<p>DESCRIPTION:<br />
Red Hat has issued an update for xulrunner. This fixes a<br />
vulnerability, which can be exploited by malicious people to<br />
compromise a user&#8217;s system.</p>
<p>SOLUTION:<br />
Updated packages are available via Red Hat Network.<br />
<a href="http://rhn.redhat.com">http://rhn.redhat.com</a></p>
<p>ORIGINAL ADVISORY:<br />
RHSA-2010:0809-1:<br />
<a href="https://rhn.redhat.com/errata/RHSA-2010-0809.html">https://rhn.redhat.com/errata/RHSA-2010-0809.html</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/zencurity.wordpress.com/761/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/zencurity.wordpress.com/761/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/zencurity.wordpress.com/761/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/zencurity.wordpress.com/761/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/zencurity.wordpress.com/761/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/zencurity.wordpress.com/761/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/zencurity.wordpress.com/761/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/zencurity.wordpress.com/761/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/zencurity.wordpress.com/761/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/zencurity.wordpress.com/761/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/zencurity.wordpress.com/761/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/zencurity.wordpress.com/761/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/zencurity.wordpress.com/761/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/zencurity.wordpress.com/761/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=zencurity.wordpress.com&amp;blog=13287981&amp;post=761&amp;subd=zencurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://zencurity.wordpress.com/2010/10/28/red-hat-update-for-xulrunner/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/39564c54e8be656175d5bc2382b17f19?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">zencurity</media:title>
		</media:content>
	</item>
		<item>
		<title>Microsoft Windows Environment Variable Expansion Library Loading Vulnerability</title>
		<link>http://zencurity.wordpress.com/2010/10/28/microsoft-windows-environment-variable-expansion-library-loading-vulnerability/</link>
		<comments>http://zencurity.wordpress.com/2010/10/28/microsoft-windows-environment-variable-expansion-library-loading-vulnerability/#comments</comments>
		<pubDate>Thu, 28 Oct 2010 12:12:03 +0000</pubDate>
		<dc:creator>michaelburger</dc:creator>
				<category><![CDATA[Moderate]]></category>
		<category><![CDATA[from remote]]></category>
		<category><![CDATA[system access]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://zencurity.wordpress.com/2010/10/28/microsoft-windows-environment-variable-expansion-library-loading-vulnerability/</guid>
		<description><![CDATA[CRITICAL: Moderately critical IMPACT: System access WHERE: From remote DESCRIPTION: A vulnerability has been discovered in Microsoft Windows, which can be exploited by malicious people to potentially compromise a user&#8217;s system. The vulnerability is caused due to Windows not properly expanding certain values in environment variables (e.g. &#34;%APPDATA%&#34; in the &#34;PATH&#34; environment variable), leading to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=zencurity.wordpress.com&amp;blog=13287981&amp;post=760&amp;subd=zencurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>CRITICAL:<br />
Moderately critical</p>
<p>IMPACT:<br />
System access</p>
<p>WHERE:<br />
From remote</p>
<p>DESCRIPTION:<br />
A vulnerability has been discovered in Microsoft Windows, which can<br />
be exploited by malicious people to potentially compromise a user&#8217;s<br />
system.</p>
<p>The vulnerability is caused due to Windows not properly expanding<br />
certain values in environment variables (e.g. &quot;%APPDATA%&quot; in the<br />
&quot;PATH&quot; environment variable), leading to the unexpanded value being<br />
used as relative search path when loading resources. This can be<br />
exploited to load arbitrary resources by tricking a user into opening<br />
a file located on a remote WebDAV or SMB share with certain<br />
applications.</p>
<p>Successful exploitation allows execution of arbitrary code.<br />
Currently, known applications presenting valid attack vectors are<br />
e.g. Apple iTunes and Safari.</p>
<p>The vulnerability is confirmed in a fully patched Windows XP<br />
Professional SP3 and is also reported in Windows Vista Business, and<br />
Windows 7 Professional. Other versions may also be affected.</p>
<p>SOLUTION:<br />
Do not open untrusted files.</p>
<p>ORIGINAL ADVISORY:<br />
Windows KB32908:<br />
<a href="http://support.microsoft.com/kb/329308">http://support.microsoft.com/kb/329308</a></p>
<p>EXTENDED SOLUTION:<br />
Install the tool available from Microsoft and change the search path<br />
for the application:<br />
<a href="http://support.microsoft.com/kb/2264107">http://support.microsoft.com/kb/2264107</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/zencurity.wordpress.com/760/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/zencurity.wordpress.com/760/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/zencurity.wordpress.com/760/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/zencurity.wordpress.com/760/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/zencurity.wordpress.com/760/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/zencurity.wordpress.com/760/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/zencurity.wordpress.com/760/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/zencurity.wordpress.com/760/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/zencurity.wordpress.com/760/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/zencurity.wordpress.com/760/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/zencurity.wordpress.com/760/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/zencurity.wordpress.com/760/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/zencurity.wordpress.com/760/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/zencurity.wordpress.com/760/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=zencurity.wordpress.com&amp;blog=13287981&amp;post=760&amp;subd=zencurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://zencurity.wordpress.com/2010/10/28/microsoft-windows-environment-variable-expansion-library-loading-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/39564c54e8be656175d5bc2382b17f19?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">zencurity</media:title>
		</media:content>
	</item>
	</channel>
</rss>
