home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > General Tech Discussion
Ask a Tech Support Question (free)!

'Critical' flaw found in Windows

Reply
Get bargains at  »  Dealighted.com
 
Thread Tools Search this Thread
Currently Active Users: 1683
Discussions: 200,982, Posts: 2,379,841, Members: 246,341
Old July 24th, 2003, 12:43 PM   Digg it!   #1
Ultimate Member
 
shawshank62's Avatar
 
Join Date: Oct 2002
Location: southampton, pa
Posts: 4,791
Send a message via ICQ to shawshank62 Send a message via AIM to shawshank62
'Critical' flaw found in Windows

The flaw involves DirectX, an extensive collection of programming add-ons for Windows used by computer games.

If exploited, the flaw could allow a malicious hacker to run their own specially crafted computer code to plant a virus or even take over a machine.

Microsoft has given the flaw its highest severity rating.

Music mayhem

The flaw affects a large number of the versions of Microsoft Windows in use.

Embarrassingly for Microsoft one of the products affected is Windows Server 2003.

This was supposed to be much more secure as it was one of the first products to go through Microsoft's improved systems for weeding out bugs and security problems.

On Windows Server 2003 the bug is only rated as "important" by Microsoft because the default settings would not allow such a program to be run.

The vulnerability comes about because of the way that a part of DirectX, called DirectShow, handles MIDI or music files.

MIDI, or Musical Instrument Digital Interface, defines a standardised way of swapping music information between computers, music keyboards and synthesisers.

The flaw, found by eEye Security, would allow a specially crafted MIDI instruction to swamp the cache, or buffer, in DirectX and allow a hidden program within it to run on the target machine.

Such buffer overflow bugs are quite a common way for malicious programs to infect a machine.

Microsoft has issued an alert about the flaw and a patch to close the loophole. It said that currently there were no known exploits of the bug.

The instruction could get into a computer by being put on a webpage.

It can also be put into an e-mail message that uses web formatting.

The DirectX flaw is the latest in a series of security problems that Microsoft has warned about over the last few weeks.

Vulnerable Software
DirectX 5.2 on Windows 98
DirectX 6.1 on Windows 98 SE
DirectX 7.0a on Windows Me
DirectX 7.0 on Windows 2000
DirectX 8.1 on Windows XP
DirectX 8.1 on Windows Server 2003
DirectX 9.0a on Windows 2000
DirectX 9.0a on Windows XP
DirectX 9.0a on Windows Server 2003
DirectX 9.0a on Windows Me
NT 4.0 using Media Player 6.4 or Internet Explorer 6 Service Pack 1
NT 4.0 Terminal Server Edition using either Media Player 6.4 or Internet Explorer 6 Service Pack 1

Quote:
http://news.bbc.co.uk/

shawshank62 is offline   Reply With Quote
Old July 24th, 2003, 01:07 PM     #2
Ultimate Member
 
SeanC's Avatar
 
Join Date: Oct 2001
Location: Toronto Canada
Posts: 4,699
Forget embarrassing about it being in 2003 Svr. How about embarrasing that it's been in DirectX since version 5.2?

That's a long time for such a severe flaw to not be noticed by anyone, especially MS's programmers.

Sean
SeanC is offline   Reply With Quote
Old July 24th, 2003, 01:49 PM     #3
Member
 
Manfordjinsen's Avatar
 
Join Date: Jun 2003
Location: Canada, Beauty EH?
Posts: 137
That has to be the best avatar I have ever seen
__________________
In the beginning there was nothing, then God said "Let there be light", there was still nothing you could just see it better.
Manfordjinsen is offline   Reply With Quote
Old July 24th, 2003, 02:55 PM     #4
prexaspes
 
Posts: n/a
Doesn't mention DirectX 9.0b, which is available, and has passed my gaming tests on multiple systems. I'm assuming the recent release either adresses the issue, or wasn't included in the article.
  Reply With Quote
Old July 24th, 2003, 03:18 PM     #5
Ultimate Member
 
wju425's Avatar
 
Join Date: Jun 2002
Location: San Antonio Texas
Posts: 1,162
Jeez... 32megs download? Well, downloading Directx 9.0b now with my old zoltrix 56k. <sigh>

\o/ Billy
wju425 is offline   Reply With Quote
Old July 24th, 2003, 03:24 PM     #6
Ultimate Member
 
shawshank62's Avatar
 
Join Date: Oct 2002
Location: southampton, pa
Posts: 4,791
Send a message via ICQ to shawshank62 Send a message via AIM to shawshank62
i believe one of the main reasons for dx9.0b was because of the security issues.....i also have d/led it and it works good.
shawshank62 is offline   Reply With Quote
Old July 24th, 2003, 03:52 PM     #7
Ultimate Member
 
JohnE.'s Avatar
 
Join Date: Oct 2001
Location: Vancouver, BC Canada
Posts: 1,012
Send a message via ICQ to JohnE.
Where do you find DirectX 9.0b? The DirectX site still only shows DirectX 9.0a as being available on the main download page.
JohnE. is offline   Reply With Quote
Old July 24th, 2003, 04:10 PM     #8
norml.org
 
thekingofpain's Avatar
 
Join Date: Oct 2001
Location: SoCal
Posts: 5,436
thekingofpain is offline   Reply With Quote
Old July 24th, 2003, 04:12 PM     #9
Bringing Da Funk
 
Gait_Keeper's Avatar
 
Join Date: Feb 2003
Location: Da Bronx, NY
Posts: 3,985
Send a message via AIM to Gait_Keeper
WOW! since v 5.2 very funny and scary at the same time

Kudos to eEye

also where is 9b download?
Gait_Keeper is offline   Reply With Quote
Old July 24th, 2003, 04:26 PM     #10
norml.org
 
thekingofpain's Avatar
 
Join Date: Oct 2001
Location: SoCal
Posts: 5,436
Quote:
also where is 9b download?

Look at the post above yours---
thekingofpain is offline   Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Most Active Discussions
Charges against non-tippers dropped.. (20)
Is It Just Me? (3063)
Health Care Rationing (9)
Delete an OS (16)
Nvidia GTX 260 problem (9)
Laptop with wireless problem. (12)
Wireless Televisions. (12)
CPU fan stops spinning randomly (11)
windows vista security holes (18)
Regular Build (11)
Point and Shoot Camera Suggestions. (7)
windows 7 problem (7)
Internet Lost (5)
Multiple Restarts Required at Boot (5)
Recent Discussions
New Server Configuration Suggestions (0)
Desktop Calendar Application (0)
updating BIOS via winflash, claims fi.. (0)
cheap gaming laptop? (12)
Unallocated Space (2)
help me pls laptop just stopped worki.. (1)
C# + LINQ Help (7)
windows vista security holes (18)
[F@H SPAM 11/16/09] ! 1/2 months to r.. (38)
Nvidia GTX 260 problem (9)
Dynex DX E-402 (3)
EVGA 9800 gtx help with finding a goo.. (12)
Multiple Restarts Required at Boot (5)
Point and Shoot Camera Suggestions. (7)
Delete an OS (16)
cell phone won't work (0)
Is the PSU I received dead? (15)
Can't open Word (12)
Steam ID's, Gamertags etc... (4)
Games, Cables, PCI cards, and more fo.. (6)
Dept. of HS: NSA 'Helped' Develop Vis.. (17)
Linksys WMP54GS wireless card problem.. (5)
Help getting around port 80 for camer.. (5)
Skillsoft Network+ Study Software Que.. (10)
Browsers wont load websites (3)


All times are GMT -4. The time now is 01:58 AM.
TechIMO Copyright 2009 All Enthusiast, Inc.