MS15-034 | Vulnerability in HTTP.sys Could Allow Remote Code Execution (3042553)
Cantor, Scott
cantor.2 at osu.edu
Thu Apr 16 15:06:47 EDT 2015
Apropos of nothing, I guess, but since this seems to be primarily a DOS in its current exploited state, it might be worth noting that anybody running an SP on RH7 or newer SUSE versions is trivially crashable too since neither vendor [1][2] has bothered to ship the Xerces patch I worked my butt off to release a month ago (I don't actually know for certain about SUSE, their bug tracker is down right now).
-- Scott
[1] https://bugzilla.redhat.com/show_bug.cgi?id=1199103
[2] https://bugzilla.opensuse.org/show_bug.cgi?id=920810
More information about the users
mailing list