Actually, August. The underlying issue is CVE-2010-0248 [ http://www.zerodayinitiative.com/advisories/ZDI-10-014/ ]. They knew about the underlying refcount issue then, and there are many ways to exploit it, only one of which is CVE-2010-0249. It was first discovered by Peter Vruegdenhil.

They may not even all be patched now.

Reply

The content of this field is kept private and will not be shown publicly.

 

Copyright © 2010 threatpost.com | Terms of Service | Privacy