Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

security risk in jpegs FFS!

Thread Tools
 
Search this Thread
 
Old Sep 15, 2004 | 09:39 AM
  #1  
GaryK's Avatar
GaryK
Thread Starter
Scooby Regular
 
Joined: Sep 1999
Posts: 4,037
Likes: 0
From: Bedfordshire
Default security risk in jpegs FFS!

as per title http://news.zdnet.co.uk/0,39020330,39166677,00.htm completely unbelievable M$ need to pull their heads out of their *****!
Reply
Old Sep 15, 2004 | 10:08 AM
  #2  
Iain Young's Avatar
Iain Young
Scooby Regular
 
Joined: Sep 1999
Posts: 6,956
Likes: 0
From: Swindon, Wiltshire Xbox Gamertag: Gutgouger
Default

So what. A bug has been found, and they've already fixed it. As long as you keep your machine up to date, you shouldn't have a problem.
Reply
Old Sep 15, 2004 | 07:12 PM
  #3  
angrynorth's Avatar
angrynorth
Scooby Regular
 
Joined: Oct 2004
Posts: 2,689
Likes: 0
From: Was Manc now Camden
Default

...and for the millions of people who don't read tech news and don't update their systems, what do they do other than be susceptible to this flaw?
Reply
Old Sep 15, 2004 | 07:30 PM
  #4  
ChrisB's Avatar
ChrisB
Moderator
 
Joined: Dec 1998
Posts: 23,573
Likes: 0
From: Staffs
Default

Originally Posted by Iain Young
So what. A bug has been found, and they've already fixed it. As long as you keep your machine up to date, you shouldn't have a problem.
It's not that simple.

You need to visit Windows Update and Office Update to start with. The Office XP patch needs Office XP SP3 to start with.

However, the DLL in question (GDIPlus.dll) can also be shipped with 3rd party applications for JPEG 'display' (to put it simply). How do you know which application is patched? Which application uses which DLL?

MS have previously advised developers to install the .DLL into their Program Folder and not %SystemRoot%. Best start searching your whole PC for it.

I know of cases of the scan tool telling a user the PC is vulnerable but Windows Update and Office Update not offering the patch.

Nothing in the wild yet but...
Reply
Old Sep 15, 2004 | 08:58 PM
  #5  
SJ_Skyline's Avatar
SJ_Skyline
Scooby Senior
 
Joined: Apr 2002
Posts: 21,922
Likes: 2
From: Limbo
Default

IIRC Jpegs have a thumbnail of themselves included in their encoding. I guess that this exploit is something to do with this and the preview pane in explorer?
Reply
Old Sep 15, 2004 | 09:44 PM
  #6  
CTR's Avatar
CTR
Scooby Regular
 
Joined: Jun 2002
Posts: 348
Likes: 0
Default

Just a couple of questions.

How many people here write code?
If you do, how many people write code for a product that has as many lines as code in it as Windows and associated applications has in it?
So that will be none then
Just in case there are any people left, how many people write code for a product where thousands if not millions of people actively look for security flaws in it?
So that will definately be zero then

All the people who answered yes to the first question, can I buy your software with a guarantee of zero bugs, and zero security flaws. Thought not

Patch has been released, its upto people to keep their compooters patched properly.

Wasnt some other browser think it was called Opera having its praises sung on here, only for a load of security flaws to be found in it
Reply
Old Sep 16, 2004 | 10:18 AM
  #7  
JackClark's Avatar
JackClark
Scooby Senior
25 Year Member
Liked
Loved
Community Favorite
 
Joined: Dec 2000
Posts: 20,896
Likes: 53
From: Overdosed on LCD
Default

I'm with you CTR. This style of MS bashing is a bit like complaining to your builder because a burglar managed to break into your house.
Reply
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Pro-Line Motorsport
Car Parts For Sale
1
Nov 30, 2015 05:52 PM
Cpt Jack Sparrow
Was it you?
7
Oct 5, 2015 10:40 AM
Brumguy34
Subaru Parts
8
Oct 4, 2015 07:51 PM
Ganz1983
Subaru
5
Oct 2, 2015 09:22 AM
madmover
Member's Gallery
4
Sep 28, 2015 10:46 AM




All times are GMT +1. The time now is 12:10 AM.