• # aucun risque !

    Posté par . En réponse au journal grave faille de sécuritée dans toutes les versions de windows. Évalué à 6.

    http://www.microsoft.com/technet/security/advisory/912840.ms(...)

    Mitigating Factors:

    In a Web-based attack scenario, an attacker would have to host a Web site that contains a Web page that is used to exploit this vulnerability. An attacker would have no way to force users to visit a malicious Web site. Instead, an attacker would have to persuade them to visit the Web site, typically by getting them to click a link that takes them to the attacker's Web site.

    In an E-mail based attack involving the current exploit, customers would have to be persuaded to click on a link within a malicious e-mail or open an attachment that exploited the vulnerability. At this point, no attachment has been identified in which a user can be attacked simply by reading mail.


    Ho, bah y a aucun risque alors. Microsoft nous explique que c'est pas si dangereux que ca en fait. Tout le monde sait qu'il est très dur de faire afficher à quelqu'un une image dans une page web ou dans un email.

    Et contrairement à ce qu'ils disent, il semblerait qu'il soit possible de se faire avoir simplement en lisant un email contenant une image.