[Full-disclosure] Different Claims by ZoneLabs on the "Bypassing PersonalFirewall (Zone Alarm Pro) Using DDE-IPC" issue

Paul Laudanski zx at castlecops.com
Mon Oct 3 16:36:18 BST 2005


On Mon, 3 Oct 2005, Debasis Mohanty wrote:

> Paul, 
> 
> >> This does not include the version 3.7.159 you are testing.  
> 
> Didn't get the meaning by what you mean by "This does not include". Do u
> mean whether or not version 3.7.159 is vulnerable it shouldn't be
> conscidered??

What I'm saying is that the vendor never claimed ZAP versions prior to 5 
are not vulnerable in the report.  So you're comment is redundant.  Simply 
upgrade your version.  Ciao.

-- 
Paul Laudanski, Microsoft MVP Windows-Security
CastleCops(SM), http://castlecops.com




Full-Disclosure is hosted and sponsored by Secunia.