Register Members List Search Today's Posts Mark Forums Read

Reply
 
Thread Tools
  #1  
Old 19 Dec 2002, 20:23
Brad's Avatar
Brad Brad is offline
 
Join Date: Nov 2001
Real name: B-rad
XP Shell Vulnerability Threatens Systems.

Hate to do a copy/paste but im patching and things are slow.

A security vulnerability in the Windows XP shell could compromise user systems, letting attackers take over machines and run malicious code. The vulnerability affects all XP versions--XP Home Edition, XP Professional Edition (including the 64-bit version), XP Media Center Edition, and XP Tablet PC Edition--and takes advantage of an XP feature that lets the system extract information from audio files in MP3 and Windows Media Audio (WMA) formats.
"An unchecked buffer exists in one of the functions used by the Windows Shell to extract custom attribute information from audio files," a Microsoft security bulletin that describes the vulnerability reads. "A security vulnerability results because it is possible for a malicious user to mount a buffer overrun attack and attempt to exploit this flaw."

An attacker could use the vulnerability to create a bogus or compromised audio file that contains executable code that's accessible through the file's metadata information. A user can trigger the code by retrieving the file from a file-sharing service, through email, or from some other online location, then holding the cursor over the file in the Windows Explorer shell. Malicious code in the file could crash the shell or unleash an attack that creates, modifies, or deletes data; reconfigures the system; or reformats the hard disk. Although security researchers originally viewed this problem as a Windows Media Player (WMP) vulnerability, Microsoft says the vulnerability is in the XP shell, not in the player.

XP users who have enabled Auto Update are already protected against this vulnerability. Other XP users can download a fix from Windows Update.
Read more
__________________
Hi, I am Brad and I'm lost in my own head!

"C++ : Where friends have access to your private members." — Gavin Russell Baker.
Reply With Quote
  #2  
Old 19 Dec 2002, 20:32
Cypher720's Avatar
Cypher720 Cypher720 is offline
 
Join Date: Aug 2002
well....just downloaded the latest updates 30 mins ago! looks like im ahead fo the game
Reply With Quote
  #3  
Old 19 Dec 2002, 20:37
filburt1 filburt1 is offline
 
Join Date: Feb 2002
/me is happy he put Windows 2000 on instead of XP after formatting and that his iBook suffers from virtually no virus threats or security holes
Reply With Quote
  #4  
Old 19 Dec 2002, 20:40
Brad's Avatar
Brad Brad is offline
 
Join Date: Nov 2001
Real name: B-rad
Mac OS is lessed used so naturally your not ganna have as many bugs found .
__________________
Hi, I am Brad and I'm lost in my own head!

"C++ : Where friends have access to your private members." — Gavin Russell Baker.
Reply With Quote
  #5  
Old 19 Dec 2002, 20:57
assassingod's Avatar
assassingod assassingod is offline
 
Join Date: Jul 2002
Windows 2000 has more secruity holes than Courtney Love's Personalitly.
Reply With Quote
  #6  
Old 19 Dec 2002, 21:23
filburt1 filburt1 is offline
 
Join Date: Feb 2002
Originally posted by Anime-loo
Mac OS is lessed used so naturally your not ganna have as many bugs found .
OS X is Unix. Bow down!
Reply With Quote
  #7  
Old 19 Dec 2002, 23:17
Brad's Avatar
Brad Brad is offline
 
Join Date: Nov 2001
Real name: B-rad
Its not pure unix, and it begin unix in no way means it has more or less bugs then windows. Im no M$ fan myself, and the point of Mac OX X begin unix in no way effects that fact that it is less common. Thus less bugs will be found. Fact is that if more people used a Mac, there would be more bugs found.
__________________
Hi, I am Brad and I'm lost in my own head!

"C++ : Where friends have access to your private members." — Gavin Russell Baker.
Reply With Quote
Reply


Similar Threads
Thread Thread Starter Forum Replies Last Post
vB Telnet/ SSH Web Shell in Admin CP Erwin vBulletin 3.0 Full Releases 28 23 Oct 2008 22:24

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
Forum Jump


New To Site? Need Help?

All times are GMT. The time now is 18:36.

Layout Options | Width: Wide Color: