Roemer Software Products NCTAudioFile2 ActiveX Control Buffer Overflow
TITLE:
Roemer Software Products NCTAudioFile2 ActiveX Control Buffer
Overflow
SECUNIA ADVISORY ID:
SA23546
VERIFY ADVISORY:
http://secunia.com/advisories/23546/
CRITICAL:
Highly critical
IMPACT:
System access
WHERE:
From remote
SOFTWARE:
Easy Hi-Q Converter 1.x
http://secunia.com/product/7769/
Easy Hi-Q Recorder 2.x
http://secunia.com/product/13043/
FREE Hi-Q Recorder 1.x
http://secunia.com/product/13044/
DESCRIPTION:
Secunia Research has discovered a vulnerability in various Roemer
Software products, which can be exploited by malicious people to
compromise a user's system.
For more information:
SA23475
The vulnerability is confirmed in the following versions:
* FREE Hi-Q Recorder 1.9
* Easy Hi-Q Recorder 2.0
* Easy Hi-Q Converter 1.7
SOLUTION:
Set the kill-bit for the ActiveX control.
Use another product.
PROVIDED AND/OR DISCOVERED BY:
Carsten Eiram, Secunia Research.
ORIGINAL ADVISORY:
Secunia Research:
http://secunia.com/secunia_research/2007-17/
OTHER REFERENCES:
SA23475:
http://secunia.com/advisories/23475/
Microsoft Re-Releases Security Bulletin MS07-002 for Excel 2000
Microsoft has released a new version of Security Bulletin MS07-002 to address an issue with security update for Excel 2000. The new version corrects the problem described in Microsoft Knowledge Base Article 931183 and in the Microsoft Security Response Center Blog. According to Microsoft, there was a flaw in the way the previous update processed the phonetic information that is embedded in files that are created by using Excel in the Korean, Chinese, or Japanese executable mode. Users who created Excel documents in one of these modes had difficulty opening some files after installing the update. The Microsoft re-release of MS07-002 resolves this issue.
More: http://www.us-cert.gov/current/current_activity.html#rerelxcl2000

Chowhound
Comic Vine
GameFAQs
GameSpot
Giant Bomb
TechRepublic