5.5 Addendum

Note

Wednesday, September 17, 2008

The vulnerability is fixed and a new version of WebEx Meeting Manager is available, so I released a detailed security advisory on my website today.[56] The bug was assigned CVE-2008-3558. Figure 5-12 shows the timeline of the vulnerability fix.

Timeline from discovery of the WebEx Meeting Manager vulnerability until the release of the security advisory

Figure 5-12. Timeline from discovery of the WebEx Meeting Manager vulnerability until the release of the security advisory

Notes

[45]

[46]

[47]

[48]

[49]

[50]

[51]

[52]

[53]

[54]

[55]

[56]

[45] COMRaider from iDefense is a great tool to enumerate and fuzz COM object interfaces. See http://labs.idefense.com/software/download/?downloadID=23.

[46] For more information, consult “Safe ...

Get A Bug Hunter's Diary now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.