GoA, 19.10.2005 18:50:
Windows-puolella on sellainen ikävä juttu että tavallisen käyttäjän kone saastuu aivan liian helposti, ellei joku osaava käyttäjä sitä ensin paikkaa. Joten älä syytä itseäsi vaan bill catesiä. ;)
Itse asiassa Secunian haavoittuvuuslistaa katsellessa syntyy vähän toisenlainen kuva...
Vulnerabilities Summary Listing / Week 41
Windows:
[SA17172] Avaya Various Products Multiple Vulnerabilities
[SA17167] Microsoft Collaboration Data Objects Buffer Overflow Vulnerability
[SA17160] Microsoft Windows DirectShow AVI Handling Vulnerability
[SA17168] Microsoft Windows Shell and Web View Three Vulnerabilities
[SA17163] Microsoft Windows FTP Client Filename Validation Vulnerability
[SA17117] aeNovo Cross-Site Scripting and SQL Injection Vulnerabilities
[SA17091] aspReady FAQ Manager Login SQL Injection Vulnerability
[SA17166] Microsoft Windows Plug-and-Play Service Arbitrary Code Execution
[SA17165] Microsoft Windows Client Service for NetWare Buffer Overflow
[SA17161] Microsoft Windows MSDTC and COM+ Vulnerabilities
[SA17136] GFI MailSecurity HTTP Management Interface Buffer Overflow
[SA17096] CheckMark Payroll DUNZIP32.dll Buffer Overflow Vulnerability
UNIX/Linux:
[SA17149] Ubuntu update for mozilla-thunderbird
[SA17090] Red Hat update for thunderbird
[SA17179] Mandriva update for xine-lib
[SA17171] Ubuntu update for koffice-libs/kword
[SA17162] Debian update for xine-lib
[SA17145] KOffice KWord RTF Importer Buffer Overflow Vulnerability
[SA17144] F-Secure Anti-Virus for Linux CHM File Parsing Buffer Overflow
[SA17135] SGI Advanced Linux Environment Multiple Updates
[SA17132] Slackware update for xine-lib
[SA17127] SUSE update for realplayer
[SA17116] Gentoo update for realplayer / helixplayer
[SA17111] Gentoo update for xine
[SA17102] Debian update for ethereal
[SA17099] xine-lib CDDB Client Format String Vulnerability
[SA17097] Ubuntu update for libxine1
[SA17177] Mandriva update for squid
[SA17156] Ubuntu update for sqwebmail
[SA17152] Gentoo update for uw-imap
[SA17148] Debian update for uw-imap
[SA17147] Red Hat update for ruby
[SA17143] Fedora update for xloadimage
[SA17140] Debian update for xloadimage
[SA17139] Debian update for xli
[SA17129] Debian update for ruby
[SA17124] xli NIFF Image Title Handling Buffer Overflow
[SA17120] Debian update for up-imapproxy
[SA17108] Debian update for dia
[SA17103] Debian update for openvpn
[SA17100] imapproxy "ParseBannerAndCapability" Format String Vulnerability
[SA17098] Ubuntu update for ruby1.8
[SA17095] Gentoo update for dia
[SA17094] Gentoo update for ruby
[SA17088] HP-UX Apache mod_ssl "SSLVerifyClient" Security Bypass Security Issue
[SA17087] Xloadimage NIFF Image Title Handling Buffer Overflow
[SA17128] OpenVMPS Logging Functionality Format String Vulnerability
[SA17106] Debian update for py2play
[SA17092] Sun Java System Directory Server HTTP Admin Interface Unspecified Vulnerability
[SA17180] Gentoo update for openssl
[SA17178] Mandriva update for openssl
[SA17169] Sun Solaris OpenSSL SSL 2.0 Rollback Vulnerability
[SA17153] Red Hat update for openssl
[SA17146] FreeBSD update for openssl
[SA17123] Debian update for cpio
[SA17118] Debian update for tcpdump
[SA17101] Debian update for tcpdump
[SA17114] Linux Kernel Potential Denial of Service and Information Disclosure
[SA17113] Ubuntu update for shorewall
[SA17112] Gentoo update for weex
[SA17110] Debian update for shorewall
[SA17154] Red Hat update for util-linux/mount
[SA17142] Ubuntu update for cfengine
[SA17131] SGI IRIX "runpriv" Arbitrary Shell Command Injection Vulnerability
[SA17125] Debian update for graphviz
[SA17121] Graphviz "dotty.lefty" Insecure Temporary File Creation
[SA17109] Debian update for masqmail
[SA17107] Mandriva update for hylafax
[SA17093] Ubuntu update for texinfo
[SA17141] Ubuntu update for kernel
[SA17133] Sun Java Desktop System umount "-r" Re-Mounting Security
Issue
...mutta Secunia luokittelee kyllä sivuillaan esim. Linux Kernel 2.6.x:n "Less critical":ksi Windows XP Home Editionin napatessa luokituksen "Highly Critical" (molemmissa kaikki jälleenmyyjän patchit asennettuna). Ota tuosta nyt sitten selvää. x)