KezNews.com
DownloadsOther NewsForumBlogsWallpapersJokewareSearch

News letter:


Enter Your E-mail:

Windows XP SP3 Gets Its First Taste of Vulnerabilities


section: windows, for your questions: KezNews forum, 7.4.2008

The third and final service pack for Windows XP is not even out the door, and security company Symantec has already warned of a security vulnerability impacting XP SP3.




With the advent of Windows Vista, Microsoft has started beating the drum of the increased security of its latest Windows client in comparison to XP SP2. Throughout 2007, the Redmond company has offered ample proof of the fact that Vista RTM was affected by less than half the volume of vulnerabilities in contrast to XP RTM. This trend seems to continue with Vista Service Pack 1 and XP SP3. The proof of concept of a new bug impacting Windows Explorer is now available in the wild, with potential exploits affecting XP SP3. "The bug affects the code that parses Word documents in order to extract and display summary information (for example, document type, author, title, etc.). A malformed property record in the DocumentSummaryInformation stream of the Word document will cause Explorer to access an invalid pointer when parsing the file, causing the process to crash because of a memory access violation. In our tests we found that Microsoft Word XP, currently updated with SP3 and the latest patches, seems to be vulnerable to this bug, which causes Word to crash due to a 'divide by zero' exception," revealed Andrea Lelli, Symantec Security Response Engineer. According to Symantec, the bug is not Critical as it only allows for denial-of-service (DoS) attacks. Users browsing in Windows Explorer or attempting to open a malformed Word document will trigger the DoS exception, causing both applications to crash. Lelli stated that it is highly unlikely that an attacker will be able to execute malicious code on an affected system via exploiting the bug. "We took a look at the problem in the crafted proof-of-concept .doc and we think that the problem lies in the DocumentSummaryInformation container of a Word document stream. This object contains information about the document, such as the title and the author, and Windows Explorer will display this information when needed. For example, when we select a document from Explorer with the status bar visible, this information will be displayed on the status bar. This means that Explorer parses the document, reads the DocumentSummaryInformation, and parses the information stored inside," Lelli said." Windows XP Service Pack 3 Release Candidate 2 Refresh can be downloaded from here.

source: news.softpedia.com

send email Send link 2 friend  |  Permalink
<< previouse article
MS: Using Vista Loophole Is Cheating
next article >>
Google App Engine: When will Microsoft field a competitor?

MORE RELATED ARTICLES:
Want a Taste of Windows XP SP3 RC? How About Some Screenshots? || It's Time to Face the Ugly Truth, SP3 or No SP3, the Clock Is Ticking for Windows XP || XP SP3 Does Not Support Windows XP || Microsoft Is Cooking New Vista Reliability Packages – Another Taste of SP1 in Advance || The Only Way for Windows XP SP3 Is Down

Comments(16)

let see if they get it right

By owned on 08.04.2008 - 02:04
great now let ms keep the sp3 for it self and release xp-sp4 instead

with dx11 support of course lool .

A pc open to attack. Never.

By luminar on 08.04.2008 - 02:04
any computer running any os connected to a phone line is vulnerable to hacks, viruses, malware etc. etc.
why is this news?

re :pc open to ......

By ownage on 08.04.2008 - 10:04
because this site are called oldnews btw !!!!

Use a firewall

By Stargate on 08.04.2008 - 12:04
gee fucking whiz use a firewall and microsoft fix the fucker

Thats it, I am upgradeing to Vista

By JJ on 08.04.2008 - 12:04
i am installing vista right now.

well...

By banjo on 08.04.2008 - 16:04
get a room
you kids sound like a married couple

That's why there's no credibility whatsoever on the commens here!

By Any Name on 08.04.2008 - 19:04
and this shit doesn't require registration for posting!

hahahaha

By Codyp on 08.04.2008 - 20:04
i just came in here to read the article and noticed a fight already started between me and jj. don't worry, someone else is doing that, i don't have to resort to changing names. infact i thought that was something you we're doing.

Oh yeah

By Codyp on 08.04.2008 - 20:04
this site really needs a registration system. i am all for the bickering, but it gets confusing when people do this.

Hi all!

By True JJ on 08.04.2008 - 21:04
i'm just gay.

Wow this is just great

By os x86 on 08.04.2008 - 22:04
hackint0sh is the best os ever. period

NOTHING TO TALK ABOUT MAC, LINUX? ARE THEY CRAPS?

By Mao on 08.04.2008 - 22:04
of course, not enough market share

How is gay make love? I saw how dog do it

By Mao on 08.04.2008 - 22:04
but dog do it right way not gay (ox head??!)

im using windows 3.11

By parish on 09.04.2008 - 07:04
windows 3.11 powns

i s.uck horse c.ock

By JJ on 10.04.2008 - 22:04
im upgrading to windows 3.1 to get a taste of the future. i also plan on jerkiong off soon

windoz 3point1 rulz

By hot on 11.04.2008 - 19:04
anybody know if vista runs off of 5 1/4 in floppyz?


No new comments are allowed for this article.

For your questions use our KezNews Forum