Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

security risk in jpegs FFS!

Thread Tools
 
Search this Thread
 
Old 15 September 2004, 09:39 AM
  #1  
GaryK
Scooby Regular
Thread Starter
 
GaryK's Avatar
 
Join Date: Sep 1999
Location: Bedfordshire
Posts: 4,037
Likes: 0
Received 0 Likes on 0 Posts
Default security risk in jpegs FFS!

as per title http://news.zdnet.co.uk/0,39020330,39166677,00.htm completely unbelievable M$ need to pull their heads out of their *****!
Old 15 September 2004, 10:08 AM
  #2  
Iain Young
Scooby Regular
 
Iain Young's Avatar
 
Join Date: Sep 1999
Location: Swindon, Wiltshire Xbox Gamertag: Gutgouger
Posts: 6,956
Likes: 0
Received 0 Likes on 0 Posts
Default

So what. A bug has been found, and they've already fixed it. As long as you keep your machine up to date, you shouldn't have a problem.
Old 15 September 2004, 07:12 PM
  #3  
angrynorth
Scooby Regular
 
angrynorth's Avatar
 
Join Date: Oct 2004
Location: Was Manc now Camden
Posts: 2,689
Likes: 0
Received 0 Likes on 0 Posts
Default

...and for the millions of people who don't read tech news and don't update their systems, what do they do other than be susceptible to this flaw?
Old 15 September 2004, 07:30 PM
  #4  
ChrisB
Moderator
 
ChrisB's Avatar
 
Join Date: Dec 1998
Location: Staffs
Posts: 23,573
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by Iain Young
So what. A bug has been found, and they've already fixed it. As long as you keep your machine up to date, you shouldn't have a problem.
It's not that simple.

You need to visit Windows Update and Office Update to start with. The Office XP patch needs Office XP SP3 to start with.

However, the DLL in question (GDIPlus.dll) can also be shipped with 3rd party applications for JPEG 'display' (to put it simply). How do you know which application is patched? Which application uses which DLL?

MS have previously advised developers to install the .DLL into their Program Folder and not %SystemRoot%. Best start searching your whole PC for it.

I know of cases of the scan tool telling a user the PC is vulnerable but Windows Update and Office Update not offering the patch.

Nothing in the wild yet but...
Old 15 September 2004, 08:58 PM
  #5  
SJ_Skyline
Scooby Senior
 
SJ_Skyline's Avatar
 
Join Date: Apr 2002
Location: Limbo
Posts: 21,922
Likes: 0
Received 1 Like on 1 Post
Default

IIRC Jpegs have a thumbnail of themselves included in their encoding. I guess that this exploit is something to do with this and the preview pane in explorer?
Old 15 September 2004, 09:44 PM
  #6  
CTR
Scooby Regular
 
CTR's Avatar
 
Join Date: Jun 2002
Posts: 348
Likes: 0
Received 0 Likes on 0 Posts
Default

Just a couple of questions.

How many people here write code?
If you do, how many people write code for a product that has as many lines as code in it as Windows and associated applications has in it?
So that will be none then
Just in case there are any people left, how many people write code for a product where thousands if not millions of people actively look for security flaws in it?
So that will definately be zero then

All the people who answered yes to the first question, can I buy your software with a guarantee of zero bugs, and zero security flaws. Thought not

Patch has been released, its upto people to keep their compooters patched properly.

Wasnt some other browser think it was called Opera having its praises sung on here, only for a load of security flaws to be found in it
Old 16 September 2004, 10:18 AM
  #7  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Default

I'm with you CTR. This style of MS bashing is a bit like complaining to your builder because a burglar managed to break into your house.
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Pro-Line Motorsport
Car Parts For Sale
1
30 November 2015 05:52 PM
Cpt Jack Sparrow
Was it you?
7
05 October 2015 10:40 AM
Brumguy34
Subaru Parts
8
04 October 2015 07:51 PM
Ganz1983
Subaru
5
02 October 2015 09:22 AM
madmover
Member's Gallery
4
28 September 2015 10:46 AM



Quick Reply: security risk in jpegs FFS!



All times are GMT +1. The time now is 08:35 AM.