The Son of Cuartango Hole

From: condorat_private
Date: Thu Nov 19 1998 - 07:51:49 PST

  • Next message: Aleph One: "Microsoft Security Bulletin (MS98-017)"

    ---------- Forwarded message ----------
    Date: Wed, 18 Nov 1998 17:08:40 +0100
    From: Juan Carlos Garcia Cuartango <cuartangojcat_private>
    To: NTBUGTRAQat_private
    Subject: The Son of Cuartango Hole
    
    Gentlemen,
    I have discovered a new Internet Explorer 4 vulnerability, I have called It "The Son of Cuartango Hole".
    It is in fact a variant of the Cuartango Hole issue (Microsoft called It the Untrusted Scripted Paste, USP vulnerability) .
    I reported this new hole to Microsoft one week ago and they have released an "updated security bulletin" http://www.microsoft.com/security/bulletins/ms98-015.asp and an "updated USP patch
    Risks involved are exactly the same that in the Cuartango Hole.
    Your computer files can be stolen when you visit a malicious WEB page or if you receive an e-mail with the malicious script.
    Technical details are available in my site :
    http://pages.whowhere.com/computers/cuartangojc/
    Regards,
    Juan Carlos G. Cuartango
    
    
    -condor
    www.sekure.org
     s e k u r e
    
    pgp key available at: http://condor.sekure.org/condor.asc
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:24:01 PDT