| | |
Microsoft Patches Critical Flaws in GDI+
Microsoft yesterday released a security update intended to fix eight critical vulnerabilities in as many as 42 Windows apps and components, including IE6, Media Player, Office, SQL Server and Visual Studio. The patch was made available before they could be discovered and exploited by malicious hackers, or at least before any were reported. The flaws were all found within GDI+, Microsoft's Graphics Device Interface subsystem.
The vulnerability could allow remote code execution "if a user [views] a specially crafted image file using affected software or [browses] a Web site that contains specially crafted content," according to Security Bulletin MS08-052, issued Sept.9. Many image file formats are affected, including bitmaps (.bmp), Windows Metafiles (.wmf), Enhanced Metafiles (.emf), Vector Markup Language (.vml) and .gif. A user need only view a Web page containing a malicious image to be infected. The exploit is particularly dangerous to users with administrative privileges, the bulletin said. GDI+, introduced with Windows XP, is also used in Vista and Windows server editions, and just about every Microsoft application and Windows component is affected. Therefore the company recommends that the patch be applied immediately.
The patches cover only Microsoft software, and not that of companies that have licensed GDI+ for their applications, which would need to issue patches of their own.
Microsoft also issued critical bulletins MS08-53, a patch for Microsoft Media Encoder 9, MS08-54, for Media Player, and MS-08-55, that repairs a flaw in Office OneNote 2007.
The vulnerability could allow remote code execution "if a user [views] a specially crafted image file using affected software or [browses] a Web site that contains specially crafted content," according to Security Bulletin MS08-052, issued Sept.9. Many image file formats are affected, including bitmaps (.bmp), Windows Metafiles (.wmf), Enhanced Metafiles (.emf), Vector Markup Language (.vml) and .gif. A user need only view a Web page containing a malicious image to be infected. The exploit is particularly dangerous to users with administrative privileges, the bulletin said. GDI+, introduced with Windows XP, is also used in Vista and Windows server editions, and just about every Microsoft application and Windows component is affected. Therefore the company recommends that the patch be applied immediately.
The patches cover only Microsoft software, and not that of companies that have licensed GDI+ for their applications, which would need to issue patches of their own.
Microsoft also issued critical bulletins MS08-53, a patch for Microsoft Media Encoder 9, MS08-54, for Media Player, and MS-08-55, that repairs a flaw in Office OneNote 2007.
Similar Threads
- News Story: Fewer flaws FUD wars as Microsoft paints misleading picture of Linux security (Novell)
- News Story: Microsoft to Release Seven Patches, and Maybe one for Safari (Windows Vista and Windows 7)
- News Story: Microsoft admits Word users are at risk from critical Jet vulnerability (Network Security)
- Find out the flaws in my website (Website Reviews)
- detecting flaws (Computer Science)
| Thread Tools | Search this Thread |
Tag cloud for bulletin, gdi+, microsoft, patch, security, vulnerability
advertising age amd apple avatar ballmer bing bluegene botnet browser business chips cloudcomputing crime data database development dos drawing economy email encryption energy enterprise exploit facebook firefox games gaming gdi+ google government hacker hacking hardware ibm ibm.news ie8 intelibm internet iphone ipod leopard linux mac malware mcafee medicine memory microsoft mobile mozilla news novell office openoffice opensource operatingsystem os pc phishing privacy ps3 recession redhat report russia search security software spam spyware sun supercomputer supercomputing survey technology tiger trends trojan twitter ubuntu unix upgrade virtualization virus vista vulnerability web windows windows7 working worm x86 xbox xbox360 xp yahoo yahoo! zune




