Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Windows Security Flaw Is 'Severe'
Washington Post ^ | December 30, 2005 | By Brian Krebs

Posted on 12/30/2005 7:21:55 AM PST by zeugma

I don't think we can post articles from this slimy source, but it's a severe enough alert to make it important to be widely known.

Select the source above for some details.

(Excerpt) Read more at washingtonpost.com ...


TOPICS: Business/Economy; Crime/Corruption; Culture/Society; News/Current Events; Technical
KEYWORDS: defect; lowqualitycrap; microsoft; securitflaw; update; windows; wmf
Navigation: use the links below to view more comments.
first previous 1-2021-4041-54 next last
To: zeugma

> Best fix at the moment is Firefox and Thunderbird.

Agreed, and largely because Tbird has images disabled by
default in the preview pane, unlike Outlook, which by
default exposes you to the full power of the dark side.

Given that this was a WaPo article, I'm astonished that
it didn't have their trademarked tag line:
"... women and children hardest hit."


21 posted on 12/30/2005 7:41:15 AM PST by Boundless
[ Post Reply | Private Reply | To 17 | View Replies]

To: rdb3; chance33_98; Calvinist_Dark_Lord; Bush2000; PenguinWry; GodGunsandGuts; CyberCowboy777; ...

22 posted on 12/30/2005 7:41:44 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: zeugma

Outlook 2003 does not display images in the preview pane unless the recipient requests they be downloaded.


23 posted on 12/30/2005 7:47:29 AM PST by Doohickey (If you choose not to decide, you still have made a choice...I will choose freewill.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Boundless

Outlook 2003 has the same functionality.


24 posted on 12/30/2005 7:49:54 AM PST by Doohickey (If you choose not to decide, you still have made a choice...I will choose freewill.)
[ Post Reply | Private Reply | To 21 | View Replies]

To: AppyPappy

And what exactly is that supposed to mean? Are you impuning El Rushbo's sexual orientation?


25 posted on 12/30/2005 7:50:21 AM PST by The_Reader_David (And when they behead your own people in the wars which are to come, then you will know. . .)
[ Post Reply | Private Reply | To 15 | View Replies]

To: zeugma

Mac or Linux is fine by me: the FreeBDS kernel (underlies OS X) and Minux (a crippled version of Unix for Intel chips created as a basis for student exercises, and fleshed out by Linus Torvalds to create Linux) were both produced by category theorists, so I've got a guild-loyalty to both.


26 posted on 12/30/2005 7:53:26 AM PST by The_Reader_David (And when they behead your own people in the wars which are to come, then you will know. . .)
[ Post Reply | Private Reply | To 18 | View Replies]

To: HOTTIEBOY
>Bush's fault

It is hard to say
who gets blamed for more bad things,
George Bush or Bill Gates.

If we add WalMart,
we'd have the three-sectioned root
of all the world's BAD . . .

27 posted on 12/30/2005 7:54:25 AM PST by theFIRMbss
[ Post Reply | Private Reply | To 3 | View Replies]

To: The_Reader_David
Just about any unix works for me, as it suits the way I work better than anything else I've found. I just wish we could do better than X though.
28 posted on 12/30/2005 8:07:34 AM PST by zeugma (Warning: Self-referential object does not reference itself.)
[ Post Reply | Private Reply | To 26 | View Replies]

To: The_Reader_David
Minux (a crippled version of Unix for Intel chips created as a basis for student exercises, and fleshed out by Linus Torvalds to create Linux)

1. Minux is pretty good now, highly robust with a small footprint. 2. Linus didn't flesh it out to make Linux. Minux was his platform used to create Linux, and Linux used some ideas from Minix.

29 posted on 12/30/2005 8:17:59 AM PST by antiRepublicrat
[ Post Reply | Private Reply | To 26 | View Replies]

This advisory discusses the following software.
Related Software
...
Microsoft Windows Server 2003
Microsoft Windows Server 2003 for Itanium-based Systems
Microsoft Windows Server 2003 Service Pack 1
Microsoft Windows Server 2003 with SP1 for Itanium-based Systems
Microsoft Windows Server 2003 x64 Edition

People actually use Windows Server 2003 as a desktop O/S? (I would think that's not very cost-effective.)

Windows admins surf the web and do e-mail on a server box? (All of my servers stay in runlevel 3 precisely to prevent that.)

Hmmmm.

30 posted on 12/30/2005 8:20:56 AM PST by TechJunkYard
[ Post Reply | Private Reply | To 16 | View Replies]

To: theFIRMbss
It is hard to say who gets blamed for more bad things, George Bush or Bill Gates.

If we add WalMart, we'd have the three-sectioned root of all the world's BAD . . .

The Liberal's version of the "Axis of Evil"? i think you may be on to something there.

31 posted on 12/30/2005 8:52:16 AM PST by Calvinist_Dark_Lord (I have come here to kick @$$ and chew bubblegum...and I'm all outta bubblegum! ~Roddy Piper)
[ Post Reply | Private Reply | To 27 | View Replies]

To: zeugma

Three letters MAC.


32 posted on 12/30/2005 8:53:14 AM PST by Casloy
[ Post Reply | Private Reply | To 1 | View Replies]

To: zeugma

Question: Is this the same WMF vulnerability that was called a trojan on a thread yesterday, or is this something in addition? Symantec dealt with the trojan on the 28th. Will that take care of this?


33 posted on 12/30/2005 9:00:20 AM PST by Clara Lou (A conservative is a liberal who has been mugged by reality. --I. Kristol)
[ Post Reply | Private Reply | To 17 | View Replies]

To: Calvinist_Dark_Lord

Trouble is, 'tis not only liberals who dislike mr. gates.


34 posted on 12/30/2005 9:00:38 AM PST by zeugma (Warning: Self-referential object does not reference itself.)
[ Post Reply | Private Reply | To 31 | View Replies]

To: AppyPappy
hahahah...that's the joke around our office here where we do a lot of solid modeling....We use PC's running linux and BRLcad.
35 posted on 12/30/2005 9:17:24 AM PST by taxed2death (A few billion here, a few trillion there...we're all friends right?)
[ Post Reply | Private Reply | To 15 | View Replies]

To: Clara Lou
I don't know. There is a bulletin from MS farther up the page. (Post 16) That might help.
36 posted on 12/30/2005 9:18:07 AM PST by zeugma (Warning: Self-referential object does not reference itself.)
[ Post Reply | Private Reply | To 33 | View Replies]

To: TexasTransplant

"What troubled me was the part about simply visiting a site could infect your computer."

Happened to me once visiting of all things, a site about Japanese kitchen knives! Luckily my McAfee caught it and I cleansed it.





37 posted on 12/30/2005 10:10:03 AM PST by garyhope (Happy, healthy, prosperous New Year to all good Freepers and our brave military.)
[ Post Reply | Private Reply | To 12 | View Replies]

To: zeugma

This is news?

Once you go Mac, you never go back...


38 posted on 12/30/2005 10:10:54 AM PST by joonbug
[ Post Reply | Private Reply | To 1 | View Replies]

To: All
I was perusing the /. post on this and ran across this...

I agree with all of that. Hell, I still tend to think of it as gdi.exe, which is about the last time I cared what Windows internals really looked like. But this "bug" is even better than that - it's not in the image format parser, it's in the freakin' WMF API!!! Believe it or not, WMF files are allowed to have callback functions (user or kernel mode unknown by me) in them - in other words a (picture) data file can contain executable code to "help" Windows display it!! It gets better: change the file extension to "jgp" or "gif" or another image type, hell, probably any file type that has a custom icon/is previewable, and Windows will look at the file and go "oh - that's really a WMF file - I know what to do..." (I'm dyin' here). Even Windows Explorer (with thumbnails enabled) will execute the code if you look at a directory that contains one of these files.

If there ever was a smoking-gun lead-pipe indictment of Microsoft's sloppy love of whizzo features, security, stability, maintainability, administerability be damned; this has GOT to be it. If the filetype API is that flawed, we need to just get rid of .WMF files, period.

Yeah, I know take /. posts with a grain of salt, but, if true, it will be interesting to see what will be done about it. --

39 posted on 12/30/2005 10:46:02 AM PST by zeugma (Warning: Self-referential object does not reference itself.)
[ Post Reply | Private Reply | To 38 | View Replies]

To: zeugma
Some people use IE and Outlook?

Ick.

40 posted on 12/30/2005 10:47:28 AM PST by Hank Rearden (Never allow anyone who could only get a government job attempt to tell you how to run your life.)
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-54 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson