Technology news and Jobs arrow Information Technology News arrow Patch frenzy erupts after August Patch Tuesday
Patch frenzy erupts after August Patch Tuesday E-mail
by Stephen Withers   
Wednesday, 13 August 2008
Three PowerPoint vulnerabilities are spread across Office 2000, XP, 2003, 2004, 2007 and the associated viewers. The bulletin is rated critical for Office 2000, and important for the other software.

All three vulnerabilities allow maliciously crafted files to trigger remote code execution with the same rights as the user.

The final Office bulletin covers the EPS, PICT, BMP and WPG file filters for Office 2000, XP and 2003, as well as Project 2002, Works 8 and the Office Converter Pack. Again, they are classified as critical for Office 2000, and important for the other software.

The vulnerabilities can be exploited with maliciously crafted files if a user can be persuaded to import them into an Office document or to open or import a document containing a malformed image.
 
Microsoft says it is unaware of any public exploits or proofs of concept
for any of the Office-related issues. Possible attack vectors include sending malicious documents with interesting names as spam attachments in the hope that recipients will be tempted to open them.

Now, on to the important vulnerabilities, starting with those for Windows itself.

Microsoft's latest and greatest operating systems - Vista and Server 2008 - are affected by an embarrassing bug that can result in supposedly encrypted IPsec network traffic being transmitted in plain text and therefore open to sniffing.

Data collected from such packets could be of immediate interest to an eavesdropper, or might reveal information that could help attempts to compromise the system.

The update ensures IPsec rules are correctly processed.

Fixes for more Windows flaws on page five.



 
< Next story in category   Previous story in the category >
iTWire user statistics Visitors last 30 days
Suscribers
904,266
13,751
#1 independent technology news advertise here
  •   *  
  • Search
  • AdvSeach
  • Login
  • Events
  • FreeStuff
Subscribe to our free e-newsletter