AOL Time Warner Affected

Notified:  March 05, 2002 Updated: March 29, 2002

Status

Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

In testing, the CERT/CC found that AOL 7.0 software may install a customized version of Internet Explorer 5.5 (5.50.4134.600IS). This version of Internet Explorer does not seem to be vulnerable. However, AOL 7.0 software on a system running Internet Explorer 5.5 SP2 (5.50.4807.2300) does appear to be vulnerable.

Cyrusoft Not Affected

Notified:  February 22, 2002 Updated: February 25, 2002

Status

Not Affected

Vendor Statement

Our email client Mulberry does not use the core HTML rendering engine library for its HTML display, and so is not affected by the bug in that library. Having looked at the details of this alert I can also confirm that our own HTML rendering engine is not affected by this, as it ignores the relevant tags.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

The CERT/CC has no additional comments at this time.

Lotus Unknown

Notified:  February 22, 2002 Updated: February 25, 2002

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

The CERT/CC has no additional comments at this time.

Microsoft Affected

Notified:  December 20, 2001 Updated: March 05, 2002

Status

Affected

Vendor Statement

Microsoft has released Security Bulletin MS02-005 and Knowledge Base Article Q317731.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

Internet Explorer for Macintosh and Internet Explorer for Unix are not vulnerable.

QUALCOMM Unknown

Notified:  February 22, 2002 Updated: February 25, 2002

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

The CERT/CC has no additional comments at this time.