KezNews.com
DownloadsOther NewsForumBlogsWallpapersJokewareSearch

News letter:


Enter Your E-mail:

The First XP SP3 Security Vulnerability


section: windows, for your questions: KezNews forum, 14.4.2008

The third and final service pack for Windows XP is not even out, and Microsoft is already hammering away at it plugging security soles.




Although it debuted in full development alongside Windows Vista SP1, Windows XP Service Pack 3 is yet to be finalized with the delivery planned by mid-2008. Since the end of March 2008, Microsoft managed to sweep XP SP3 under the rug, but until the past month, the service pack was very much still a work in progress.

Case in point the first security vulnerability affecting XP SP3, fixed even before the service pack was finalized. Sometime between late February and the end of March, the Redmond company solved an issue in the Windows graphics device interface. When it released Microsoft Security Bulletin MS08-021 labeled with a maximum severity rating of Critical, Microsoft stated that despite the fact that all Widows operating system, either on the server or on the client's side were affected, XP SP3 was not.

The reason for this, spotted by ComputerWorld over on the Microsoft Forum is the fact that update 948590 had already been integrated into XP SP3 when the company released Release Candidate 2 Build 5508. Microsoft's Shashank Bansal, answering to an user report of failed integration of KB948590 with XP SP3, revealed that the "issue happens with 3311 build of XP SP3. RC2 Refresh build 5508 does not encounter this issue. It happens because KB948590 stops installation of SP3 version of gdi32.dll on the system due to file version differences."

The security bulletin designed to patch the GDI vulnerabilities affected a wide array of Windows operating systems including Vista SP1 and Windows Server 2008. Also XP SP3 RC2 Build 3311 seems to have been vulnerable, but the issue was solved with the release of XP SP3 RC2 Refresh Build 5508. "The KB mentioned was released post 3311. As 3311 build carried updated released till the date it went public, the new KB was not included. The KB carried a version of gdi32 higher than 3311 (as it was released later). This caused the difference," Bansal added.

source: news.softpedia.com

send email Send link 2 friend  |  Permalink
<< previouse article
Silverlight 2, Microsoft's Flash Killer, Gets DRM, Just Like Vista
next article >>
Users fight to save Windows XP

MORE RELATED ARTICLES:
Latest Vulnerability Attacks Steer Clear of Vista SP1, but Not XP SP3 || Vista Still Breathing as XP Chokes on Latest Vulnerability || It's Time to Face the Ugly Truth, SP3 or No SP3, the Clock Is Ticking for Windows XP || Vista SP1 RC Leaves XP SP2 in the Dust, but What About XP SP3? || Microsoft Makes Its Own Vista SP1 vs. XP SP2, Leaves XP SP3 Out

Comments(5)

THERE IS NO PERFECT SOFTWARE SO EITHER SP3, SP4 OR NOTHING

By Mao on 15.04.2008 - 01:04
common sense

micro$oft is just pushing sp3 DOWN

By john on 15.04.2008 - 02:04
and yes there is no perfect software

Still it's more perfect than Vista SP1 :)

By Peter on 15.04.2008 - 15:04
ohhh yeahhh

XP is vintage OS for old P2 P3 Computers

By IQ on 15.04.2008 - 16:04
xp is fast because it is an old os, that was released on older pc's

when xp was first released, it was buggy and slow and people winged about xp, just like what they’re doing with vista now...


Fuck M$

By YETI on 15.04.2008 - 18:04
people didn't moan about xp for anywhere near the time they are about vista.

vista is a shithouse of an os, so face it!


Add a Comment



Subject:
Your name (nick):
Text:
HTML, BBCode disabled in comments