-
Security vulnerability in Jpegs
-
I have sp2 installed and got the update. Even though those links I read said it was not needed.
-
-
The Windows Hotfix for this does not take the usual form, it is in two parts. The second part takes you to a webpage that downloads an ActiveX control that checks other vulnerable apps. I discovered that if you download the .NET Framework SP1 update at the same time, which requires a reboot, then if you click yes to the reboot you'll lose the webpage part of the update. And it doesn't go into the browser history either for some reason.
Here is the URL, in case anyone needs it:
GDI+ Security Update
Only use the link if you need it, as far as I'm aware you need the first part of the update to be installed first before you can use that ActiveX control.
And I, like Train, also found that despite what those articles say, Windows Update still offers the patch after Service Pack 2 is installed.
-
Definately do this update by its self.
-
Went to Windows Update and surprisingly was told the update was available to me, even though the MSKB article says WinXP SP2 without Office does not need it.
"(Important Windows XP Service Pack 2 (SP2) is not affected by this issue. Windows XP SP2 users only need to update Office (if installed). )" I do not have Office.
So, being a good MS customer I downloaded it, anyway. More concerning I got message saying (best as I can remember) that I had some graphics on my PC that could pose a problem. So I followed the instructions and seeing nothing more specific, clicked the button on http://www.microsoft.com/security/bu...jpeg_tool.mspx to scan for "Click for affected Imaging Software". After agreeing to a hold harmless paragraph, nothing happened, except that that link changed into a notice that
"This tool is designed for computers running Windows 2000 and earlier. Windows XP, Windows XP SP1, and Windows Server 2003 users may update their computers by visiting the Windows Update Web site."
Pretty circuitous.
Oh, Well. :rolleyes:
-
I followed WelshJim's link on a WinNT machine and clicked the [Check for Affected Imaging Software] followed by agreeing to the agreement.
Thw window changed to say
Quote:
No affected imaging software was found on this computer
-
Maybe I spoke too soon. There is another link (#4) below #3 which leads you to a list of software affected.
http://www.microsoft.com/technet/sec.../MS04-028.mspx
Since I have none of those I wonder why Windows Update offered the patch to me. (Actually I had seen that list earlier, and so did nothing to get the patch until Windows Update offered it.)
-
got this reply also
--------------------------------------------------------------------------------
No affected imaging software was found on this computer
-
That ActiveX control to check affected imaging software is for versions of Windows other than WinXP or Server 2003 BTW. It doesn't work at all on XP, I tried it.
-
Hmm from the list I can see that my hanging back with WinMe and Office2000 is now paying off. LOL
-
And the funny part is , a completely unpatched Office 2000 gets a clear OK. While the folks that have the Office updates get told to patch it. WIERD is right.
-
That's me :D
Probably less that 10 Windows Updates installed and zero Office 2000 updates installed.
No firewall, just up to date NAV 2002 and Ad-Aware.
Seems the more secure you try to be the more at risk you seem to be ?
It's more challenging to break into Fort Knox than some small country bank in the back of beyond.
-
-
And if this is anything to go by, it won't be long to wait before this one is exploited:
http://www.theinquirer.net/?article=18510
Make sure that you are patched against this vulnerability, people.