When is M$ meta file fix(just issued) not a fix?



With the recent "fix" of course it appears.

http://www.techweb.com/article/showArticle.jhtml?articleId=175802806&pgno
=1

ust days after Microsoft rushed out a patch for a bug in Windows
Metafile (WMF) image processing, a security company has warned customers
that multiple memory corruption vulnerabilities in the same rendering
engine could leave users open to attack.

"An attacker may leverage these issues to carry out a denial-of-service
attack or execute arbitrary code," Symantec said in a vulnerability
alert issued through its DeepSight Management System.

The bugs may be associated with the one patched Thursday by Microsoft,
but they involve different functions of the Windows WMF rendering
engine, added Symantec, which highlighted the various values and
structures within the engine which could be exploited.

"Reports indicate that these issues lead to a denial-of-service
condition, however, it is conjectured that arbitrary code execution is
possible as well," the Symantec alert went on.


There's more in the article, and before you winnuts get all sweaty and
worked up, I'm the messenger, and it's also not as simple as not opening
an attachment in an email.

--
Regards,
JP
"The measure of a man is what he will do while
expecting that he will get nothing in return!"
.



Relevant Pages

  • Re: Why RosAsm Breaks on a large number of symbols
    ... > Windows message loop is a good starting point. ... But of course this is not a genuine bug report, ... > preservation convention for Windows programing, ... You need to preserve register in callbacks - that's the only _rule_ about ...
    (alt.lang.asm)
  • Re: Warning. New Windows vulnerabilty.
    ... > In short - wmf files can carry viruses. ... > Infection will occur if your email application allows a *preview* of a ... It is carried on Windows Metafile images and automatically ... > vulnerability seems to be in gdi32.dll. ...
    (rec.audio.pro)
  • Re: bad experience with Suse 9.1 on Inspiron 8200
    ... > it is an M$ bug, such technicalities are irrelevant to the end user. ... :-) Windows has ... work as long as they work, trying to install a nitrous ... Linux are at least a *little* bit curious about how their computer works ...
    (alt.os.linux.suse)
  • I think I have been hijacked.
    ... I am running windows xp on my Compaq Presario and Toshiba laptop, ... An internet connection appears to have been added through a USB. ... R - Registry, StartPage/SearchPage changes ... Fixed crashing bug on certain Win2000 and WinXP systems at O23 listing ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Given Up on Linux1
    ... Once I had done enough work and investigated the existing bug reports on ... > dealt with thousands of computers, you should be lucky I'm even ... newbie to Linux. ... But there had not been a windows problem in 12 years I ...
    (alt.os.linux)

Loading