BetaONE will rise again!


 
Prev Previous Post   Next Post Next
  #1  
Old 19th Aug 03, 07:43 PM
Alpine's Avatar
Alpine Alpine is offline
Retired Crew
 
Join Date: Feb 2002
Location: Run Forest, RUN!!
Posts: 3,601
Alpine is on a distinguished road
Send a message via ICQ to Alpine Send a message via AIM to Alpine
Microsoft seems to have survived the MSBlast worm attack, but now the company is urging Windows users to patch their systems against a different, and potentially more dangerous, vulnerability in its software. Even though most businesses have installed the patch for MSBlast, there is another vulnerability that could overshadow last week's events. On July 23, Microsoft posted a security bulletin on its Web site that describes a "critical" vulnerability in DirectX. According to the company, unprotected systems could be at the mercy of an attacker by simply playing a midi file or visiting a malicious Web page.

The danger comes, says Microsoft, in a component of DirectX that relies on a library file called quartz.dll, which is used by a number of applications--including Internet Explorer--to play MIDI files. A specially designed MIDI file could cause a buffer overflow error and either pass control of the system to an attacker, cause damage to the system or use the system to set off another MSBlast-type attack. Russ Cooper, chief scientist at security company TruSecure, expects a worm or virus to take advantage of the vulnerability in the near future: "We are definitely afraid of the DirectX vulnerability."

The vulnerability, he said, is very widespread because few people have applied the patch for this. Cooper believes it could be exploited by a worm that uses several methods of spreading, similar to the way that MSBlast did.



Source:
http://zdnet.com.com/


Download: DirectX 9.0b End-User Runtime (includes fix):
http://download.microsoft.com/downlo...dxwebsetup.exe


Security Bulletin:
http://www.microsoft.com/technet/tre...n/ms03-030.asp
Reply With Quote
 


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT +1. The time now is 08:35 AM.


Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.