To register for an Internet.com membership to receive newsletters and white papers, use the Register button ABOVE.
To participate in the message forums BELOW, click here


Virtual DR   Earthweb  
Events Premium Services Media Kit E-mail Offers Whitepapers Vendor Showcases

Go Back   Virtual Dr Forums-Computer Tech Support > Center For Disease Control > Security News / Warnings / Updates

Security News / Warnings / Updates Discussion about current Security and Privacy News from around the World including the latest threats and solutions.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old September 15th, 2004, 04:08 PM
SuperSparks's Avatar
SuperSparks SuperSparks is offline
Site Moderator
 
Join Date: Apr 2000
Location: Friern Barnet, London, England (51°37'01"N, 0°9'53"W)
Posts: 38,846
Security vulnerability in Jpegs

Info here:

http://www.theregister.co.uk/2004/09...dows_jpeg_bug/

http://www.theinquirer.net/?article=18446

http://www.wired.com/news/infostruct...w=wn_tophead_8

Windows Updates are available to fix this problem both in the OS and all affected apps:

http://v5.windowsupdate.microsoft.co....aspx?ln=en-us
__________________
Reply With Quote
  #2  
Old September 15th, 2004, 08:51 PM
Train Train is offline
Site Moderator
 
Join Date: Apr 2000
Location: Elma,Wa.
Posts: 41,784
I have sp2 installed and got the update. Even though those links I read said it was not needed.
__________________
SMILE
and post back. Let us know if it worked.
[ Book mark this post to find it again]
Reply With Quote
  #3  
Old September 15th, 2004, 09:07 PM
Nix's Avatar
Nix Nix is offline
Aka: Nix*, NNiixx, Nix23
 
Join Date: May 2001
Location: Sydney, Australia
Posts: 8,255
Yeah that's what my link in this post was about http://discussions.virtualdr.com/sho...186#post863186
Reply With Quote
  #4  
Old September 15th, 2004, 09:08 PM
SuperSparks's Avatar
SuperSparks SuperSparks is offline
Site Moderator
 
Join Date: Apr 2000
Location: Friern Barnet, London, England (51°37'01"N, 0°9'53"W)
Posts: 38,846
The Windows Hotfix for this does not take the usual form, it is in two parts. The second part takes you to a webpage that downloads an ActiveX control that checks other vulnerable apps. I discovered that if you download the .NET Framework SP1 update at the same time, which requires a reboot, then if you click yes to the reboot you'll lose the webpage part of the update. And it doesn't go into the browser history either for some reason.

Here is the URL, in case anyone needs it:

GDI+ Security Update


Only use the link if you need it, as far as I'm aware you need the first part of the update to be installed first before you can use that ActiveX control.


And I, like Train, also found that despite what those articles say, Windows Update still offers the patch after Service Pack 2 is installed.
__________________
Reply With Quote
  #5  
Old September 15th, 2004, 09:13 PM
Train Train is offline
Site Moderator
 
Join Date: Apr 2000
Location: Elma,Wa.
Posts: 41,784
Definately do this update by its self.
__________________
SMILE
and post back. Let us know if it worked.
[ Book mark this post to find it again]
Reply With Quote
  #6  
Old September 15th, 2004, 09:18 PM
Welshjim's Avatar
Welshjim Welshjim is offline
Virtual PC Specialist!!!
 
Join Date: Jun 2001
Location: Albuquerque, NM USA
Posts: 12,390
Went to Windows Update and surprisingly was told the update was available to me, even though the MSKB article says WinXP SP2 without Office does not need it.
"(Important Windows XP Service Pack 2 (SP2) is not affected by this issue. Windows XP SP2 users only need to update Office (if installed). )" I do not have Office.
So, being a good MS customer I downloaded it, anyway. More concerning I got message saying (best as I can remember) that I had some graphics on my PC that could pose a problem. So I followed the instructions and seeing nothing more specific, clicked the button on http://www.microsoft.com/security/bu...jpeg_tool.mspx to scan for "Click for affected Imaging Software". After agreeing to a hold harmless paragraph, nothing happened, except that that link changed into a notice that
"This tool is designed for computers running Windows 2000 and earlier. Windows XP, Windows XP SP1, and Windows Server 2003 users may update their computers by visiting the Windows Update Web site."
Pretty circuitous.
Oh, Well.
__________________
Jim
WIN XP Pro SP3, IE7, NTFS,
cable, Norton AV, Zone Alarm firewall
Reply With Quote
  #7  
Old September 15th, 2004, 09:24 PM
Nix's Avatar
Nix Nix is offline
Aka: Nix*, NNiixx, Nix23
 
Join Date: May 2001
Location: Sydney, Australia
Posts: 8,255
I followed WelshJim's link on a WinNT machine and clicked the [Check for Affected Imaging Software] followed by agreeing to the agreement.

Thw window changed to say
Quote:
No affected imaging software was found on this computer
Reply With Quote
  #8  
Old September 15th, 2004, 09:37 PM
Welshjim's Avatar
Welshjim Welshjim is offline
Virtual PC Specialist!!!
 
Join Date: Jun 2001
Location: Albuquerque, NM USA
Posts: 12,390
Maybe I spoke too soon. There is another link (#4) below #3 which leads you to a list of software affected.
http://www.microsoft.com/technet/sec.../MS04-028.mspx
Since I have none of those I wonder why Windows Update offered the patch to me. (Actually I had seen that list earlier, and so did nothing to get the patch until Windows Update offered it.)
__________________
Jim
WIN XP Pro SP3, IE7, NTFS,
cable, Norton AV, Zone Alarm firewall
Reply With Quote
  #9  
Old September 15th, 2004, 09:58 PM
frebo's Avatar
frebo frebo is offline
Virtual PC Specialist!!!
 
Join Date: Mar 2002
Location: sc,united states
Posts: 3,475
got this reply also


--------------------------------------------------------------------------------
No affected imaging software was found on this computer
__________________
If I Ain't Crappie Fishin', I'm Thinkin' About It
Reply With Quote
  #10  
Old September 15th, 2004, 10:02 PM
SuperSparks's Avatar
SuperSparks SuperSparks is offline
Site Moderator
 
Join Date: Apr 2000
Location: Friern Barnet, London, England (51°37'01"N, 0°9'53"W)
Posts: 38,846
That ActiveX control to check affected imaging software is for versions of Windows other than WinXP or Server 2003 BTW. It doesn't work at all on XP, I tried it.
__________________
Reply With Quote
  #11  
Old September 15th, 2004, 10:18 PM
Nix's Avatar
Nix Nix is offline
Aka: Nix*, NNiixx, Nix23
 
Join Date: May 2001
Location: Sydney, Australia
Posts: 8,255
Hmm from the list I can see that my hanging back with WinMe and Office2000 is now paying off. LOL
Reply With Quote
  #12  
Old September 15th, 2004, 10:36 PM
Train Train is offline
Site Moderator
 
Join Date: Apr 2000
Location: Elma,Wa.
Posts: 41,784
And the funny part is , a completely unpatched Office 2000 gets a clear OK. While the folks that have the Office updates get told to patch it. WIERD is right.
__________________
SMILE
and post back. Let us know if it worked.
[ Book mark this post to find it again]
Reply With Quote
  #13  
Old September 15th, 2004, 10:44 PM
Nix's Avatar
Nix Nix is offline
Aka: Nix*, NNiixx, Nix23
 
Join Date: May 2001
Location: Sydney, Australia
Posts: 8,255
That's me

Probably less that 10 Windows Updates installed and zero Office 2000 updates installed.

No firewall, just up to date NAV 2002 and Ad-Aware.

Seems the more secure you try to be the more at risk you seem to be ?

It's more challenging to break into Fort Knox than some small country bank in the back of beyond.
Reply With Quote
  #14  
Old September 17th, 2004, 04:22 PM
SuperSparks's Avatar
SuperSparks SuperSparks is offline
Site Moderator
 
Join Date: Apr 2000
Location: Friern Barnet, London, England (51°37'01"N, 0°9'53"W)
Posts: 38,846
There's some interesting commentary here:

http://news.bbc.co.uk/1/hi/technology/3666702.stm
__________________
Reply With Quote
  #15  
Old September 17th, 2004, 04:38 PM
SuperSparks's Avatar
SuperSparks SuperSparks is offline
Site Moderator
 
Join Date: Apr 2000
Location: Friern Barnet, London, England (51°37'01"N, 0°9'53"W)
Posts: 38,846
And if this is anything to go by, it won't be long to wait before this one is exploited:

http://www.theinquirer.net/?article=18510


Make sure that you are patched against this vulnerability, people.
__________________
Reply With Quote
Reply

Bookmarks
Go Back   Virtual Dr Forums-Computer Tech Support > Center For Disease Control > Security News / Warnings / Updates



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 11:51 PM.









Acceptable Use Policy

internet.comMediabistrojusttechjobs.comGraphics.com

WebMediaBrands Corporate Info


Advertise | Newsletters | Feedback | Submit News

Legal Notices | Licensing | Permissions | Privacy Policy

Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.