PDA

View Full Version : new WMF flaws


Ice Czar
01-10-2006, 03:25 PM
http://www.redherring.com/Article.aspx?a=15239&hed=More+Security+Bugs+Hit+Windows&sector=Industries&subsector=Computing

doesnt allow remote code execution, but something to be aware about anyway

Less than a week after Microsoft released a patch to fix a security breach in its Windows operating system, antivirus companies warned Tuesday about two additional bugs related to image files.

The newly discovered issues, while not as critical as the earlier flaws, can cause programs to crash and lead to what security experts call a denial-of-service attack.

“It is not quite the same vulnerability as last time,” said Craig Schmugar, virus research manager at McAfee AVERT Labs. “Code execution is not possible, so hackers cannot use it to install everything from spyware to viruses on a system. But they can still affect one or two programs on the machine.”

pxc
01-10-2006, 03:48 PM
Thanks for reminding me about patch Tuesday. I'm finally going to patch that "critical" (har har) WMF flaw right now.