![]() |
![]() |
![]() |
|
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
![]() |
![]() |
| Register | Home | Forums | Active Topics | Insurance | Photo Gallery | Garage | Search | Today's Posts | Mark Forums Read |
![]() |
|
|
LinkBack | Thread Tools | Rate Thread |
|
|
#1 (permalink) |
|
Super Senior Member
![]() ![]() ![]() ![]() ![]() Join Date: Nov 2002
Location: US
Posts: 2,564
Feedback Score: 0 reviews
|
Might be old news by now, but I don't remember seeing it anywhere here...
_________________________________ http://news.zdnet.com/2100-1009_22-5366314.html Major graphics flaw threatens Windows PCs By Robert Lemos CNET News.com September 14, 2004, 1:24 PM PT Microsoft published on Tuesday a patch for a major security flaw in its software's handling of the JPEG graphics format and urged customers to use a new tool to locate the many applications that are vulnerable. The critical flaw has to do with how Microsoft's operating systems and other software process the widely used JPEG image format and could let attackers create an image file that would run a malicious program on a victim's computer as soon as the file is viewed. Because the software giant's Internet Explorer browser is vulnerable, Windows users could fall prey to an attack just by visiting a Web site that has affected images. The severity of the flaw had some security experts worried that a virus that exploits the issue may be on the way. "The potential is very high for an attack," said Craig Schmugar, virus research manager for security software company McAfee. "But that said, we haven't seen any proof-of-concept code yet." Such code illustrates how to abuse flaws and generally appears soon after a software maker publishes a patch for one of its products. The flaw affects various versions of at least a dozen Microsoft software applications and operating systems, including Windows XP, Windows Server 2003, Office XP, Office 2003, Internet Explorer 6 Service Pack 1, Project, Visio, Picture It and Digital Image Pro. The software giant has a full list of affected applications in the advisory on its Web site. Windows XP Service Pack 2, which is still being distributed to many customers' computers, is not vulnerable to the flaw. "The challenge is that (the flawed function) ships with a variety of products," said Stephen Toulouse, security program manager for Microsoft's incident response center. Because so many applications are affected, Microsoft had to create a separate tool to help customers update their computers. Users of Windows Update will also be directed to the software giant's Office Update tool and then to the tool that will find and update imaging and development applications. The tools are a preview of what may come from the company in the future, Toulouse said. "We know one of the most important things that we hear from customers is to make the software update process easier," he said. "A goal of a unified update mechanism is what we are looking at." Out of necessity, Linux distributions have already developed such unified update software, which not only updates the core operating system but also other applications created by the open-source community. The majority of Windows applications, however, are created by companies other than Microsoft, making such a unified update system more politically difficult to create. The JPEG processing flaw enables a program hidden in an image file to execute on a victim's system. The flaw is unrelated to another image vulnerability found in early August. That vulnerability, in a common code library designed to support the Portable Network Graphics, or PNG, format, affected applications running on Linux, Windows and Apple's Mac OS X. Both the JPEG, which stands for Joint Photographic Experts Group, and PNG formats are commonly used by Web sites. As part of a notification program that has been in place since April 2004, any customer that had signed a nondisclosure agreement with Microsoft received a three-day advance warning about the JPEG flaw. "Some customers wanted to get more information, for planning purposes," Toulouse said, responding to media reports that premium customers were getting advanced notice of security issues. He directed interested customers to their Microsoft sales representative to get more information on the program. The information given to participants in the program is limited to the number of flaws, the applications affected and the maximum threat level assigned to the flaws. The JPEG image-processing vulnerability is the latest flaw from Microsoft and the source of the company's 28th advisory this year. Microsoft frequently includes multiple issues in a single advisory; four advisories in April, for example, contained more than 20 vulnerabilities. A second patch released by Microsoft on Tuesday fixes a flaw in the WordPerfect file converter in Microsoft Office, Publisher, Word and Works. That flaw is rated "important," Microsoft's second-highest threat level, just below "critical." The vulnerability would let an attacker take control of the victim's PC, if that user opened a malicious WordPerfect document. More information on the second flaw can be found in the advisory on Microsoft's Web site. The software giant recommends that customers use Office Update to download the fix.
__________________
Hands free device = good Not buckling your kids = bad '06 Black EXL-Navi: autodim mirror, many cargo accessories, mud guards, ODB II, and wwong's console pads. '06 Black Volvo XC90 2.5T '03 Black EXL-RES: side steps, autodim mirror, many cargo accessories, roof rack, and mud guards. --> traded in '06 for XC90 |
|
|
|
| Sponsored Links | |||
Advertisement | |||
|
|
#2 (permalink) |
|
Registered User
Join Date: Apr 2003
Location: NY Panhandle(c)
Posts: 2,831
Feedback Score: 0 reviews
|
Yeah, I think that came out last week, but sometimes it's hard to tell. The flaws, bugs, vulnerabilities, exploits, and patches come along so fast and furious that it all seems like one indistinguishable continuous bug. Microsoft - the "gray goo" of software.
__________________
2003 EX-L, Sage Brush Pearl Side Steps • Rear Splash Guards • Cross Bars • Cargo Tray • Cargo Cover • All-Season Floor Mats • StreetPilot ColorMap • WeatherTech WeatherFlectors • Fortera TripleTreds |
|
|
|
|
|
#3 (permalink) |
|
Super Senior Member
![]() ![]() ![]() ![]() ![]() Join Date: Jan 2003
Location: Damascus, Maryland
Posts: 2,199
Feedback Score: 0 reviews
|
Boy, do I miss the "old days" of the 1990's when you didn't have to constantly worry about--and keep up with--this kind of %&#@!*^.
__________________
'03 Pilot Starlight Silver EX ~ Towing Package ~ Fog Lights w/ Lower Trim & Garnish ~ Running Boards, Rear Mud Guards ~ All-Weather Mats ~ Wheel Locks ~Cargo Area Accessories: Cover * Tray * Organizer * Net ~ Honda Pilot.org Accessories: License Plate Frame * Sticker |
|
|
|
|
|
#4 (permalink) | |
|
Registered User
Join Date: May 2002
Location: Chicago, NW Burbs
Posts: 13,555
Feedback Score: 0 reviews
|
Quote:
__________________
However beautiful the strategy, you should occasionally look at the results. Sir Winston Churchill |
|
|
|
|
|
|
#5 (permalink) | |
|
Super Senior Member
![]() ![]() ![]() ![]() ![]() Join Date: Jan 2003
Location: Damascus, Maryland
Posts: 2,199
Feedback Score: 0 reviews
|
Quote:
What I really mean is the whole ball of wax: The very fact we have to install protection programs and play the losing game of trying to stay one step ahead of all those freaks out there populating the Internet with all manner of attack mechanisms. Plus the ever-increasing flood of spam and spyware....trying to decide what to block, most effective program, etc. I'm just someone with a low tolerance level for this kind of stuff.
__________________
'03 Pilot Starlight Silver EX ~ Towing Package ~ Fog Lights w/ Lower Trim & Garnish ~ Running Boards, Rear Mud Guards ~ All-Weather Mats ~ Wheel Locks ~Cargo Area Accessories: Cover * Tray * Organizer * Net ~ Honda Pilot.org Accessories: License Plate Frame * Sticker |
|
|
|
|
|
|
#6 (permalink) | |
|
Registered User
Join Date: Apr 2003
Location: NY Panhandle(c)
Posts: 2,831
Feedback Score: 0 reviews
|
Quote:
__________________
2003 EX-L, Sage Brush Pearl Side Steps • Rear Splash Guards • Cross Bars • Cargo Tray • Cargo Cover • All-Season Floor Mats • StreetPilot ColorMap • WeatherTech WeatherFlectors • Fortera TripleTreds |
|
|
|
|
|
|
#7 (permalink) | |
|
Registered User
Join Date: May 2002
Location: Chicago, NW Burbs
Posts: 13,555
Feedback Score: 0 reviews
|
Quote:
As for me, I have home built PCs, mostly from used or bargain parts, but keep all my software up to date, and almost never have a crash. Seems a bit different experiance from many of the "experts" who seem to have a never ending list of problems (or at least "complaints") As for the good old days: I never had a program conflict issue before multitasking, and never had a driver problem when every program was writen to the hardware. Then again, I am sure the wooden wheeled wagons never had flat tire either!
__________________
However beautiful the strategy, you should occasionally look at the results. Sir Winston Churchill |
|
|
|
|
|
|
#8 (permalink) |
|
Rip Tide Dude!
Join Date: Nov 2003
Location: Southern Cal
Posts: 3,054
Feedback Score: 0 reviews
|
I change the start -up type in the administrative service for auto-update from automatic to manual. I manually check for some critical update at least once a week. Also get a good software/hardware base firewall and manually change the default setting to your need. I also use a free software SpywareBlaster to protect my system from malicious program /code and bad url.
__________________
2003 Honda Pilot EX Starlight Silver* OEM Full Nose Mask | Wheel Locks | Cross Bars | OEM Running Boards | Chrome Accent - OEM Running Board | Rear Splash Guard | OEM '04 Horn | Cloud-Rider Spectare Black Stainless Steel Grille Screen & Bumper Combo | Thule Ski Rack #725 | Thule Snowboard Carrier #575 |OEM All Season Floor Mats |OEM Cargo Tray | Pilot Motorsports #PM555 Stainless Steel Exhaust Tips | PowerStation Pro Portable Charger/Compressor/Emergency Light | Tire Step Ladder | Eurodezigns Blue Xenon H4 Bulbs & H3 Fog Light Bulbs | Infinity Kappa Speakers | Dynamat Original/Extreme | Complete Set of 3M Protector | 3M Metallic Tint | Covercraft Noah Custom Cover | Microtune #141X Antenna Amplifier | Dashmat Dash Cover | Full Size Spare Tire | Broadway Napolex BW-86 Wide Inside Rear View Mirror | Complete Sets of Dark Smoke WeatherTech WeatherFlectors | Westin Black Rear Bumper Guard | 3rd Brake Light Mod | 6 Disc CD Changer | ______________________________ The dawn of love would be the end of pleasure! |
|
|
|
| Sponsored Links | |
Advertisement | |
![]() |
| Thread Tools | |
| Rate This Thread | |
|
|