BetaONE will rise again!


Reply
  #1  
Old 23rd Sep 05, 02:00 PM
NewsBot's Avatar
NewsBot NewsBot is offline
Senior Member
 
Join Date: Oct 2004
Posts: 30,379
NewsBot will become famous soon enough
Security Fix for DirectX 8 on 98/ME/W2K
DirectX consists of a set of low-level Application Programming Interfaces (APIs) used by Windows programs for multimedia support. Within DirectX, the DirectShow technology performs client-side audio and video sourcing, manipulation and rendering. There are two buffer overruns with identical effects in the function used by DirectShow to check parameters in a Musical Instrument Digital Interface (MIDI) file. A security vulnerability results because it would be possible for a malicious user to attempt to exploit these flaws and execute code in the security context of the logged on user.

An attacker could seek to exploit this vulnerability by creating a specially crafted MIDI file designed to exploit this vulnerability and then host it on a Web site or on a network share, or send it via an HTML email. In the case where the file was hosted on a web site or network share, the user would need to open the specially crafted file. If the file was embedded in a page, the vulnerability could be exploited when a user visited the Web page. In the HTML E-mail case, the vulnerability could be exploited when a user opened or previewed the HTML e-mail. A successful attack could have the effect of either causing DirectShow, or an application making use of DirectShow, to fail, or causing an attacker's code to run on the user's computer in the security context of the user.

Download: Security Fix for DirectX 8 on 98/ME/W2K (KB819696)
View: Knowledge Base ArticleRead full story...


News source: Full Story
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Microsoft's April Security Updates NewsBot NeoWin News 0 12th Apr 05 08:30 PM
Microsoft Security Bulletin Advance Notification NewsBot NeoWin News 0 8th Apr 05 06:00 PM
No new security updates from Microsoft for March NewsBot NeoWin News 0 4th Mar 05 12:00 AM
Neowin Talks Security with Microsoft NewsBot NeoWin News 0 7th Feb 05 01:00 AM
Microsoft Commits to Security NewsBot BetaONE News 0 4th Nov 04 02:00 PM


All times are GMT +1. The time now is 03:30 PM.


Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.