Microsoft reports another serious flaw

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • peloquin
    Till I Come!
    • Jun 2004
    • 8643

    Microsoft reports another serious flaw

    HERE

    Microsoft Warns of Critical JPEG Flaw

    Handling of images could allow an attacker to take over your PC.

    A security flaw in the way many Microsoft applications process JPEG images could allow an attacker to gain control over a computer running the software, Microsoft warned this week.

    Any program that processes JPEG images could be vulnerable, Microsoft says in Security Bulletin MS04-028. To take advantage of the flaw, an attacker would have to persuade a user to open a specially crafted image file. The image could be hosted on a Web site, included in an e-mail or Office document, or hosted on a local network, Microsoft says.

    A wide range of Microsoft software, including various versions of its Windows and Office products, is vulnerable. Additionally, applications created with Microsoft's Visual Studio developer tool or the .Net Framework and third-party applications that distribute their own copy of the vulnerable JPEG parsing engine may also be vulnerable, Microsoft says.

    Software updates to correct the flaw in its products are available from Microsoft. The software maker also offers a tool to scan a PC for certain installed products that are known to contain the vulnerable JPEG image processing engine.


    Ratings System
    Microsoft rates the flaw "important" for many of its products, but "critical" for Outlook versions 2002 and 2003, Internet Explorer 6 with Service Pack 1, Windows XP and Windows XP with Service Pack 1, Windows Server 2003, and the .Net Framework 1.0 with Service Pack 2 and .Net Framework 1.1, according to the Security Bulletin.

    In Microsoft's rating system for security issues, vulnerabilities that could allow a malicious Internet worm to spread without any action required on the part of the user are rated critical. Issues that will not lead to the spread of a worm without any action taken by the user, but could still expose user data or threaten system resources, are rated important.

    The JPEG flaw was reported privately to Microsoft and it was not disclosed prior to the release of the warning and patches, the software maker says. There have been no reports of the issue being exploited, Microsoft says.

    In addition to the JPEG issue, Microsoft this week, as part of its monthly security patch release cycle warned of a flaw in the WordPerfect 5.x Converter that it supplies as part of Office 2000, Office XP, Office 2003, and recent editions of its Works Suite.

    The WordPerfect converter flaw, which Microsoft rates "important," could allow an attacker to gain full control over a victim's PC, Microsoft says. A software patch is available for the vulnerable products to fix the problem.



    glad i dont use ms progs for my image manipulation
  • bloodl0ck
    Getting warmed up
    • Jun 2004
    • 52

    #2
    Re: Microsoft reports another serious flaw

    wonder if xp sp2 fixes this?

    Comment

    • peloquin
      Till I Come!
      • Jun 2004
      • 8643

      #3
      ^ probably makes it worse

      Comment

      • peloquin
        Till I Come!
        • Jun 2004
        • 8643

        #4
        the ms thing is way too long to post, but i recommend at least scanning it, check the link on the article

        Comment

        • Morgan
          Platinum Poster
          • Jun 2004
          • 2234

          #5
          Re: Microsoft reports another serious flaw

          Originally posted by bloodl0ck";p="
          wonder if xp sp2 fixes this?
          but "critical" for Outlook versions 2002 and 2003, Internet Explorer 6 with Service Pack 1, Windows XP and Windows XP with Service Pack 1, Windows Server 2003, and the .Net Framework 1.0 with Service Pack 2 and .Net Framework 1.1, according to the Security Bulletin.

          Pelo, do you even read your posts?
          "Pain is only weakness leaving the body."

          Comment

          • peloquin
            Till I Come!
            • Jun 2004
            • 8643

            #6
            ^ yes

            Comment

            • sjaracz2
              Getting Somewhere
              • Jun 2004
              • 137

              #7
              Re: Microsoft reports another serious flaw

              it doesn't say anything about sp2
              Nectar is to Bees As Money is to a Women

              Comment

              • beto
                Gold Gabber
                • Jun 2004
                • 964

                #8
                If I use Windows XP Service Pack 2 and use any of the affected software, what should I do?
                Windows XP Service Pack 2 does not contain a vulnerable version of the affected component. However, if you have installed any of the affected Office, Visio, or Project applications you should install the updates for those applications.


                It's in the MS Bulletin FAQ, scroll down... you'll find it

                Comment

                Working...