[softwarelist] Re: OvnPro 2.77 type 5 errors

  • From: David Pilling <flist@xxxxxxxxxxxxxxxxxxx>
  • To: davidpilling@xxxxxxxxxxxxx
  • Date: Fri, 16 Jan 2009 12:07:40 +0000

Re-posted...

From Chris Hughes <chris@xxxxxxxxxxxxxxxxxxxx>

In message <67f3361e50.Alan.Adams@xxxxxxxxxxxxxxxxxxxxxxxxxxx>
          Alan Adams <alan@xxxxxxxxxxxxxxxx> wrote:


Make of that what you will.

Just some additional information, it adds an extra validation registry entry if using XP at least, this is not always automatically removed if you uninstalled the software patch. This will still impact transferred.

Further digging revealed the main issue is around ceratin types of file name used which apparently were not being validated correctly by the SMB server software, and creating a security hole in the file sharing.

Looks like LANMAN/LANMAN98 will need updating to handle the tighter security.


Chris Hughes
// eompost 4970650F:7AC3.1:qnivqcvyyvat

--
David Pilling
email: david@xxxxxxxxxxxxxxxxxxx
  web: http://www.davidpilling.net
 post: David Pilling P.O. Box 22 Thornton Cleveleys Blackpool. FY5 1LR UK
  fax: +44(0)870-0520-941


To unsubscribe or subscribe goto: //www.freelists.org/list/davidpilling

Other related posts: