|
|
|
View Notes By
|
|
|
|
Other Documents
|
|
|
|
|
Husdawg Information for VU#166651
| Date Notified: | 2008-04-21 |
| Date Updated: | 2008-10-14 |
| Statement Date: | |
| Status Summary: | Vulnerable |
Vendor StatementNo statement is currently available from the vendor regarding this vulnerability.Vendor InformationThe vendor has not provided us with any further information regarding this vulnerability.
AddendumThis vulnerability is addressed in version 3 of the System Requirements Lab software. This version is available on the systemrequirementlab.com web server. This version of the ActiveX control restricts which domains can call the methods provided by the control.
The primary ActiveX version of the software has also been disabled in Internet Explorer with the update for Microsoft Security Advisory (956391). Note that this update does not prevent the vulnerable Java version of the control from being used, nor does it disable every vulnerable version of the ActiveX control. Please see the CERT/CC Vulnerability Analysis Blog for more details about vulnerable Java applets.
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|
 |