Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Microsoft Warns of Critical JPEG Flaw: Image Handling Could Allow Takeover of a PC.
IDG News - PC World ^ | 9.14.04 | Joris Ivers

Posted on 09/14/2004 7:38:39 PM PDT by IncPen

A security flaw in the way many Microsoft applications process JPEG images could allow an attacker to gain control over a computer running the software, Microsoft warned this week.

Any program that processes JPEG images could be vulnerable, Microsoft says in Security Bulletin MS04-028. To take advantage of the flaw, an attacker would have to persuade a user to open a specially crafted image file. The image could be hosted on a Web site, included in an e-mail or Office document, or hosted on a local network, Microsoft says.

A wide range of Microsoft software, including various versions of its Windows and Office products, is vulnerable. Additionally, applications created with Microsoft's Visual Studio developer tool or the .Net Framework and third-party applications that distribute their own copy of the vulnerable JPEG parsing engine may also be vulnerable, Microsoft says.

Software updates to correct the flaw in its products are available from Microsoft. The software maker also offers a tool to scan a PC for certain installed products that are known to contain the vulnerable JPEG image processing engine.

Ratings System

Microsoft rates the flaw "important" for many of its products, but "critical" for Outlook versions 2002 and 2003, Internet Explorer 6 with Service Pack 1, Windows XP and Windows XP with Service Pack 1, Windows Server 2003, and the .Net Framework 1.0 with Service Pack 2 and .Net Framework 1.1, according to the Security Bulletin.

In Microsoft's rating system for security issues, vulnerabilities that could allow a malicious Internet worm to spread without any action required on the part of the user are rated critical. Issues that will not lead to the spread of a worm without any action taken by the user, but could still expose user data or threaten system resources, are rated important.

The JPEG flaw was reported privately to Microsoft and it was not disclosed prior to the release of the warning and patches, the software maker says. There have been no reports of the issue being exploited, Microsoft says.

In addition to the JPEG issue, Microsoft this week, as part of its monthly security patch release cycle warned of a flaw in the WordPerfect 5.x Converter that it supplies as part of Office 2000, Office XP, Office 2003, and recent editions of its Works Suite.

The WordPerfect converter flaw, which Microsoft rates "important," could allow an attacker to gain full control over a victim's PC, Microsoft says. A software patch is available for the vulnerable products to fix the problem.

An old but related article... Bill Gates Says Users to Blame for Security Problems


TOPICS: Miscellaneous; News/Current Events; Technical; Unclassified
KEYWORDS: exploit; gates; getamac; internetexploiter; lowqualitycrap; microsoft; patch; securityflaw; thehorror; trojan; virus; windows; worm
Navigation: use the links below to view more comments.
first 1-2021-22 next last
Image Hosted by ImageShack.us

I'll drink to that...

1 posted on 09/14/2004 7:38:40 PM PDT by IncPen
[ Post Reply | Private Reply | View Replies]

To: Bush2000

So you'll know what your day will be like tomorrow...


2 posted on 09/14/2004 7:39:14 PM PDT by IncPen (Every Word From Kerry's Mouth is a Dishonorable Discharge...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker; Nailbiter; Forecaster; BartMan1; HAL9000

... ping ...


3 posted on 09/14/2004 7:39:52 PM PDT by IncPen (Every Word From Kerry's Mouth is a Dishonorable Discharge...)
[ Post Reply | Private Reply | To 2 | View Replies]

To: IncPen

Uh Oh! Ping!


4 posted on 09/14/2004 7:41:58 PM PDT by rdl6989 (<fontface="Rather Not">)
[ Post Reply | Private Reply | To 3 | View Replies]

To: IncPen

Gore looks really smashed in that picture. Look at those beady eyes.


5 posted on 09/14/2004 7:42:49 PM PDT by rdl6989 (<fontface="Rather Not">)
[ Post Reply | Private Reply | To 1 | View Replies]

To: IncPen

This story is about as valid as the CBS guard memo!


6 posted on 09/14/2004 7:43:20 PM PDT by z3n
[ Post Reply | Private Reply | To 1 | View Replies]

To: IncPen

Thanks, checking now to download.


7 posted on 09/14/2004 7:54:55 PM PDT by NavySEAL F-16 (Proud to be a Reagan Republican)
[ Post Reply | Private Reply | To 1 | View Replies]

To: IncPen

Now I've heard everything.


8 posted on 09/14/2004 8:00:29 PM PDT by sargon (How could anyone vote for the socialist, weak-on-defense fraud named John Kerry?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: IncPen
Keep getting Security updates all day from MS on the PC's I'm repairing. So far none have actually needed the patch. I guess it's the one here. Looks for MS Picture It and other photo type programs. There is a browser update too.
9 posted on 09/14/2004 8:01:27 PM PDT by BallyBill (John Kerry the Emir of Schmowland)
[ Post Reply | Private Reply | To 1 | View Replies]

To: IncPen
that's great IncPen!

10 posted on 09/14/2004 8:07:38 PM PDT by Archytekt
[ Post Reply | Private Reply | To 1 | View Replies]

To: IncPen

The new iMac G5 is out and its safe to view pictures on it, not like your PC! :P
11 posted on 09/14/2004 8:09:06 PM PDT by toupsie
[ Post Reply | Private Reply | To 1 | View Replies]

To: Tragically Single

Ping


12 posted on 09/14/2004 8:27:48 PM PDT by tuliptree76
[ Post Reply | Private Reply | To 1 | View Replies]

To: toupsie
Awesome machine.

It would be nice if more entertainment software (OK, games) were available for the Mac. There was plenty ten years ago, but the Mac game market is a shadow of its former self. That's a pity, because I like my computer to be able to play as well as work. Heck, my home box is primarily used for entertainment. Games & Freeping.

The usual response to my lament is "So get an XBox! Or a PS2!"

I would, but consoles seem to be dedicated mostly to first person shooters and platform run & jump games. Not my style. I like strategy (Europa Universalis II, Victoria, War in the Pacific) and realistic flight sims (MS FS2004, IL2 Forgotten Battles, Rowan's Battle of Britain, Jane's F/A-18, and the upcoming Wings over Vietnam and the IL2 sequel Pacific Fighters.) None run on the Mac.

Oh, sure, there are Windows emulators I could use. Some of the older strategy games I play (Bombing the Reich) might even run fast enough to be playable. Use an emulator for a frame rate intensive flight sim? No way. It might run, but it would be a pretty (and slow) screen shot generator.

If the Mac ever becomes a serious contender to replace my Windows PC as a gaming rig I'll consider one in a heartbeat. Until then it's like buying a beautiful high definition plasma TV only to find that all I can watch is Nova, Garrison Keillor, and the local community access channel. Sure, there are some good nuggets of entertainment there, but I want it all.

13 posted on 09/14/2004 8:43:23 PM PDT by Denver Ditdat (Ronald Reagan belongs to the ages now, but we preferred it when he belonged to us.)
[ Post Reply | Private Reply | To 11 | View Replies]

To: IncPen

Darn striking resemblance to Kirstie Alley


14 posted on 09/14/2004 8:45:52 PM PDT by Cboldt
[ Post Reply | Private Reply | To 1 | View Replies]

To: Denver Ditdat

Yea, the Mac games I play are like Railroad Tycoon 3. There really aren't that many compared to the PC but the best PC games generally make it to the Mac. I have a PC which I have just blanked and turned into a Gentoo Linux server which I used to play games on when it had Windows XP. I have an Xbox now and play Madden 2005.


15 posted on 09/14/2004 8:48:45 PM PDT by toupsie
[ Post Reply | Private Reply | To 13 | View Replies]

To: toupsie
I'd love to see a modern combat flight sim on a G5. The hardware for a smokin' experience is definitely there.

The market is probably too small for a developer to take the gamble. Even in the PC world flight simmers have become a small niche. The ROI for a Mac sim probably doesn't look very attractive.

The games that do get ported to the Mac look & run great. Maybe one of these days someone will take a wild risk, code up an OSX native flight sim, sock away a tidy profit from sim-hungry Mac folks, and start the ball rolling. It would sure be nice.

16 posted on 09/14/2004 9:03:00 PM PDT by Denver Ditdat (Ronald Reagan belongs to the ages now, but we preferred it when he belonged to us.)
[ Post Reply | Private Reply | To 15 | View Replies]

To: Denver Ditdat
X-Plane should pique your interest.
17 posted on 09/14/2004 9:29:11 PM PDT by toupsie
[ Post Reply | Private Reply | To 16 | View Replies]

To: Denver Ditdat

It looks like it has great graphics. I thought this was a photo! It's from their simulator.
18 posted on 09/14/2004 9:34:25 PM PDT by toupsie
[ Post Reply | Private Reply | To 16 | View Replies]

To: toupsie
Wow! I had X-Plane for the PC a couple versions back. 5.xx, I think. If that's what it is looking like these days I need to take it for another spin.

Thanks!

19 posted on 09/14/2004 9:49:29 PM PDT by Denver Ditdat (Ronald Reagan belongs to the ages now, but we preferred it when he belonged to us.)
[ Post Reply | Private Reply | To 18 | View Replies]

To: IncPen
Leave it to Micro$lop to screw up a perfectly innocuous function and turn it into a security vulnerability.

Fortunately, not all of us have to be Micro$erfs...


20 posted on 09/14/2004 9:58:10 PM PDT by Prime Choice (The Religion of Peace ISN'T.)
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-22 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson