Technology news and Jobs arrow Information Technology News arrow September Patch Tuesday: a critical day for media files at Microsoft
September Patch Tuesday: a critical day for media files at Microsoft E-mail
by Stephen Withers   
Wednesday, 10 September 2008
The developer tools listed are not of themselves vulnerable to the issue, but are provided so that applications developed with them can be rebuilt without the flaw.

Not only does the update install a new version of the gdiplus.dll file, it also includes a Windows Side by Side Cache rule to prevent applications requesting and receiving an older version that still contains the flaw.

The Side by Side Cache is designed to accommodate applications that request a particular version of a DLL, but such rules allow the normal behaviour to be overridden when it is determined that previous versions include a significant vulnerability. While this does open the possibility that an application might fail if it really does depend on a specific version of a DLL, the old saying "better safe than sorry" is applied.

The second vulnerability involves audio files played by Windows Media Player.

It can be exploited by streaming a maliciously crafted file from a Windows Media server to Windows Media Player. It's probably a little harder to tempt victims to listen to a particular playlist than it is to get them to visit a web page, so in one sense this is probably less serious than the GDI+ issue. However, it still has a critical rating.

The flaw is present in Windows Media Player 11. Earlier versions are not affected. Once again. an exploit only has the same rights as the user, so running as an administrator increases the scope of a successful exploit.

Vulnerabilities in Office and Windows Media Encoder - see page three .



 
< Next story in category   Previous story in the category >
iTWire user statistics Visitors last 30 days
694,279
Subscribers 15,210
#1 independent technology news advertise here
  •   *  
  • Search
  • AdvSeach
  • Login
  • Events
  • FreeStuff

- Advertisement -

Featured Whitepapers

Follow iTWire on Twitter

About iTWire

iTWire is all about technology news, information, jobs and community for the IT and telecommunications industry professional. Subscribe to our free ICT daily newsletter