Sunday, November 23, 2014
Search
  
Submit your own News for
inclusion in our Site.
Click here...
Breaking News
Samsung Files ITC Complaint Against Nvidia
Europe To Ask Google Unlink Its Commercial And Search Services
Streaming TV Service Aereo Files for Bankruptcy
Square Launches Cash Register Service
Call of Duty: Advanced Warfare is the Biggest Entertainment Launch of 2014
Intel-Micron 3D NAND To Have 32 Layers, 256Gb Per Die
Intel To Release Chromecast-like Thumb-sized PCs
Google Contributor Lets You Pay And And See No Ads In Your Favorite Sites
Active Discussions
cdrw trouble
CDR for car Sat Nav
DVD/DL for Optiarc 7191S at 8X
Copied dvd's say blank in computer only
Made video, won't play back easily
New Features In Firefox 33
updated tests for dvd and cd burners
How to generate lots of different CDs quickly
 Home > News > General Computing > JPEG ha...
Last 7 Days News : SU MO TU WE TH FR SA All News

Wednesday, September 15, 2004
JPEG handling flaw threatens PCs, Microsoft warns


A security flaw in the way many Microsoft applications process JPEG images could allow an attacker to gain control over a computer running the software, Microsoft warned Tuesday.

Any program that processes JPEG images could be vulnerable, Microsoft said in Security Bulletin MS04-028. To take advantage of the flaw, an attacker would have to persuade a user to open a specially crafted image file. The image could be hosted on a Web site, included in an e-mail, Office document or hosted on a local network, Microsoft said.

A wide range of Microsoft software, including various versions of its Windows and Office products, is vulnerable. Additionally, applications created with Microsoft's Visual Studio developer tool or the.Net Framework and third-party applications that distribute their own copy of the vulnerable JPEG parsing engine may also be vulnerable, Microsoft said.

Along with the Security Bulletin, Microsoft made available software updates to correct the flaw in its products. The software maker also offers a tool to scan a PC for certain installed products that are known to contain the vulnerable JPEG image processing engine.

Microsoft rates the flaw "important' for many of its products, but "critical" for Outlook versions 2002 and 2003, Internet Explorer 6 with Service Pack 1, Windows XP and Windows XP with Service Pack 1, Windows Server 2003, and the .Net Framework 1.0 with Service Pack 2 and .Net Framework 1.1, according to the Security Bulletin.

In Microsoft's rating system for security issues, vulnerabilities that could allow a malicious Internet worm to spread without any action required on the part of the user are rated critical. Issues that will not lead to the spread of a worm without any action taken by the user, but could still expose user data or threaten system resources, are rated important.

The JPEG flaw was reported privately to Microsoft and it was not disclosed prior to the Tuesday release of the warning and patches, the software maker said. There have been no reports of the issue being exploited, Microsoft said.

In addition to the JPEG issue, Microsoft on Tuesday as part of its monthly security patch release cycle warned of a flaw in the WordPerfect 5.x Converter that it supplies as part of Office 2000, Office XP, Office 2003 and recent editions of its Works Suite.

The WordPerfect converter flaw, which Microsoft rates "important," could allow an attacker to gain full control over a victim's PC, Microsoft said. A software patch is available for the vulnerable products to fix the problem.

More information on the JPEG flaw is available at:
http://www.microsoft.com/technet/security/bulletin/ms04-028.mspx

More information on the WordPerfect converter issues is at:
http://www.microsoft.com/technet/security/bulletin/ms04-027.mspx

From Computerworld Australia



Previous
Next
Victor JVC Everio Tiny Digital Camcorder        All News        Asustek to launch half-height Combo drives
DivXNetworks partners with Plextor     General Computing News      2004 E-CrimeWatch Survey Summary Findings

Source Link Get RSS feed Easy Print E-Mail this Message

Related News
Microsoft Slashes Prices Of Xbox One, Surface 3 For Black Friday
Samsung Loses Bid Against Microsoft
Microsoft To Offer Digital Services To Real Madrid Soccer Fans
Microsoft Surface Pro 3 Update Fixes Bugs
Microsoft's 3D Soundscape Technology Research Helps Visually Impaired
Microsoft Buys Cloud-security Company Aorato
Microsoft Takes .NET Open Source and Cross-platform, Adds New Capabilities With Visual Studio 2015, .NET 2015 and Visual Studio Online
Microsoft Bundles Office, Xbox, Skype for $199, Introduces Skype for Business
Lumia 535 Is Official
Microsoft and Dropbox Announce Surprising Collaboration On Mobile
Microsoft Introduces The Microsoft Health And Band
Microsoft To Embrace Real-Time Browser-based Calls

Most Popular News
 
Home | News | All News | Reviews | Articles | Guides | Download | Expert Area | Forum | Site Info
Site best viewed at 1024x768+ - CDRINFO.COM 1998-2014 - All rights reserved -
Privacy policy - Contact Us .