[Full-Disclosure] EEYE: Microsoft RPC Heap Corruption Vulnerability - Part II

Chris DeVoney cdevoney at u.washington.edu
Wed Sep 10 23:36:10 BST 2003


On Wednesday, September 10, 2003 1:26 PM, Jeff.Urnaza at averydennison.com
wrote:

> The version number in eEye's supposed *new* scanner is the 
> same version number  as the one they release for the previous 
> RPC exploit, v1.0.4.

Pardon my interuption, but the version I downloaded about noon-ish PDT has
version 1.1.0 in both its Help-About and its file properties. It does report
vulnerabilities to MS03-026 and -039.


cdv

------------------------
Chris DeVoney
Clinical Research Center Informatics
University of Washington
cdevoney at u.washington.edu
206-598-6816 
------------------------




Full-Disclosure is hosted and sponsored by Secunia.