
Not One But Two Critical Vulnerabilities
As an update to our earlier news post, eEye have discovered another vulnerability in the same Microsoft DLL, meaning there are now two critical vulnerabilities to be dealt with. According to the eEye team, the dll is 'rife with buffer overrun conditions'. Btw I also noticed this airing on the BBC, but without any real details given. Apparently this vulnerability has been known about since at least September 2003.
CERT has released a security alert