Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Microsoft finds more glitches in XP and IE -Fifth security advisory this year
vnunet ^

Posted on 02/06/2003 4:01:18 PM PST by chance33_98



Microsoft finds more glitches in XP and IE

By Nick Farrell [06-02-2003]

Fifth security advisory this year warns of IE and XP bugs

Two more Microsoft security advisories have appeared concerning Windows XP and Internet Explorer (IE). The latest Windows XP bug brings the total number of Microsoft security advisories issued this year to five.

The XP vulnerability has been caused by an unchecked buffer in the Windows Redirector function on the operating system, Microsoft said.

The company explained that an attacker exploiting the vulnerability could crash the system or run their own code with system privileges.

This could allow them to take any desired action on the machine, such as adding, deleting, or modifying data on the system, and creating or deleting user accounts.

According to Microsoft the vulnerability cannot be exploited remotely as calls to the Windows Redirector can only be made locally. Attackers would therefore need to log on to the system using an interactive logon in order to attempt to exploit this vulnerability.

The IE glitch has been found in versions 5.01, 5.5 and 6.0. And Microsoft warned that since it no longer supports IE 5.0 and earlier versions, these could also be vulnerable.

The security issue that has been identified could enable an attacker to read files or run programs on a computer used to view the attacker's website.

In a recent interview, Mark Greatorex, director of .Net Developer Group in the UK, said the company had not experienced any new vulnerabilities in the past 10 months. Two thirds of the company's developers, he added, are actually involved in software testing, not development.

Security, he said, is an industry wide problem, and one where "stones cannot be continually thrown at Microsoft without dispassionately looking at what is happening elsewhere".


TOPICS: Business/Economy; Technical
KEYWORDS: computersecurityin; microsoft
Navigation: use the links below to view more comments.
first 1-2021-32 next last

1 posted on 02/06/2003 4:01:18 PM PST by chance33_98
[ Post Reply | Private Reply | View Replies]

To: chance33_98
FWIW, I'm happy with XP.
2 posted on 02/06/2003 4:02:24 PM PST by Oldeconomybuyer (Let's Roll)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Oldeconomybuyer
FWIW, I'm happy with XP.

Me too, but the "fix" for this latest took an abnormally long time to download and install. And I'm on cable Internet. Must have been a whopper.

3 posted on 02/06/2003 4:07:40 PM PST by jackbill
[ Post Reply | Private Reply | To 2 | View Replies]

To: *Microsoft; *Computer Security In
http://www.freerepublic.com/perl/bump-list
4 posted on 02/06/2003 4:09:05 PM PST by Libertarianize the GOP (Ideas have consequences)
[ Post Reply | Private Reply | To 1 | View Replies]

To: jackbill
I got a "notice" the first thing this morning that the security update was available, and the download only took a few seconds. I'm on a cable modem too...
5 posted on 02/06/2003 4:10:01 PM PST by Oldeconomybuyer (Let's Roll)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Oldeconomybuyer
FWIW, I'm happy with XP.

So's my wife, I am happy with 2000 server, solaris, and red hat. Wasn't bashing MS by posting, just an FYI to those who don't follow the security patches and such. I subscribe to a series of security lists myself.

6 posted on 02/06/2003 4:11:03 PM PST by chance33_98 (Freedom is not Free)
[ Post Reply | Private Reply | To 2 | View Replies]

To: All
XP was designed to have gaping holes, since it's a Big Brother app. You people will be in orgasmic glee when Palladium rolls around.
7 posted on 02/06/2003 4:37:15 PM PST by JoJo Gunn
[ Post Reply | Private Reply | To 6 | View Replies]

To: chance33_98
My hospital network was down today for six hours because Windows is such a steaming pile of crap. Yes, even the Windows 2000/XP server systems which are supposed to be more stable than the old DOS-based windows.

On the other hand, we have a Unix workstation that has run for four years without one single crash.

Windows is a toy operating system for soccer moms and kids. It should never be used for mission critical applications. I'll never use the $h!t again unless I have no choice.

-ccm

8 posted on 02/06/2003 5:39:39 PM PST by ccmay
[ Post Reply | Private Reply | To 1 | View Replies]

To: chance33_98
I got the update today and my puter is actually working better!

It boots faster, and loads even better.

9 posted on 02/06/2003 5:43:23 PM PST by Cold Heat
[ Post Reply | Private Reply | To 1 | View Replies]

To: ccmay
I manage about 400 servers (and growing almost daily). We use solaris, hp-ux, windows 2000 server, and NT 4 (and soon Redhat). I rarely have to work on the Solaris machines and usually the problem centers around Oracle, the most common problem though relates to when someone changed something on the system months ago and there was reboot - had quite a few systems where I had to go in and figure out what changed.

We routinely have problems with windows machines, mainly lock ups. The OS on the unix side is more stable, but windows does have a place in the enterprise and our windows servers outnumber the solaris 2-1. Most the problems too are on older systems and seem to be the same ones over and over (usually traced to a hardware fault).

I use all of the above at home, except hp-ux which I will probably be setting up shortly. I like a diversity in platforms.

It is worth noting that third party software often contributes to problems, a case in point is Gnome on Solaris. I have had multiple problems with it and have since discontinued using it (except on my redhat box where it works well).

10 posted on 02/06/2003 5:47:37 PM PST by chance33_98 (Freedom is not Free)
[ Post Reply | Private Reply | To 8 | View Replies]

To: chance33_98
No problem. Hit "Windows Update", and three security patches were all loaded and installed automatically. Nice.
11 posted on 02/06/2003 5:48:53 PM PST by PatrioticAmerican (Arm Up! They Have!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ccmay
"My hospital network was down today for six hours because Windows is such a steaming pile of crap."

What was the cause of the outage?
12 posted on 02/06/2003 5:50:39 PM PST by PatrioticAmerican (Arm Up! They Have!)
[ Post Reply | Private Reply | To 8 | View Replies]

To: jackbill
Where did you get the fix. I have XP version 6.0 cable run. I hate it it is always shutting me down something about a dll error all the time. How can I get the fix for the latest problem.
13 posted on 02/06/2003 5:53:02 PM PST by angcat
[ Post Reply | Private Reply | To 3 | View Replies]

To: chance33_98
What kind of issues are you having with Gnome on Solaris? I just installed the latest today. (First time I've ever had to reboot to load a software package on my Solaris box).

Can't say I'm a really big fan of Gnome, but anything is better than CDE. I've thought about putting KDE on that system, but just never have gotten around to it.

14 posted on 02/06/2003 7:10:44 PM PST by zeugma (If you use microsoft produts, you are feeding the beast.)
[ Post Reply | Private Reply | To 10 | View Replies]

To: zeugma
CDE Blows too. The Gnome problems are mainly slow, bulky, would not do file associtations even when I told it to, and recently it just crashed and burned. I am willing to try the new version, but most stuff I do is command line, and I usually write PERL scripts to do most my work.
15 posted on 02/06/2003 7:14:02 PM PST by chance33_98 (Freedom is not Free)
[ Post Reply | Private Reply | To 14 | View Replies]

To: PatrioticAmerican
What was the cause of the outage?

They are not certain but there is some kind of .NET authentication server that went down. No one could log in to their systems. Then like magic it began to work again. I sure hope they figure it out before it happens again.

-ccm

16 posted on 02/06/2003 8:20:03 PM PST by ccmay
[ Post Reply | Private Reply | To 12 | View Replies]

To: angcat
Where did you get the fix. I have XP version 6.0 cable run.

Apparently Bill Gates has control of my computer. Every once in a while I get this little thingy that pops up and tells me that my XP needs another fix and it asks me if I want to download it. I submit.

17 posted on 02/07/2003 3:37:12 PM PST by jackbill
[ Post Reply | Private Reply | To 13 | View Replies]

To: chance33_98
Microsoft finds more glitches in XP and IE -Fifth security advisory this year

Well, the year is young...

18 posted on 02/07/2003 3:39:55 PM PST by null and void
[ Post Reply | Private Reply | To 1 | View Replies]

To: ccmay
Windows is a toy operating system for soccer moms and kids. It should never be used for mission critical applications.

Simply not true. The Navy uses Windows NT on their ships...

19 posted on 02/07/2003 3:41:52 PM PST by null and void (Sleep well tonight, knowing that...)
[ Post Reply | Private Reply | To 8 | View Replies]

To: jackbill
my XP needs another fix

AHA! It's addicted...

20 posted on 02/07/2003 3:44:30 PM PST by null and void
[ Post Reply | Private Reply | To 17 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-32 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson