Slashdot Mirror


Flaw in Microsoft JPEG Parsing

KDan writes "As reported by numerous sources, a new vulnerability has been disclosed (and patched) by Microsoft. This one concerns the parsing of JPEGs in XP Microsoft applications. A buffer overflow can be used to execute arbitrary code. So all those times you told your parents/friends that looking at images was safe - well, not anymore."

2 of 555 comments (clear)

  1. Re:If you think looking at images is safe... by kabloom · · Score: 5, Informative

    What is goatse? Look it up on wikipedia. The entry is goatse.cx. You'll be glad you didn't have to see the image.

  2. Re:Not the problem by Carnildo · · Score: 5, Informative

    The full list of affected programs, from Microsoft's site:

    * Windows XP
    * Windows XP Service Pack 1 (SP1)
    * Windows Server 2003
    * Internet Explorer 6 SP1
    * Office XP SP3
    Note Office XP SP3 includes Word 2002, Excel 2002, Outlook 2002, PowerPoint 2002, FrontPage 2002, and Publisher 2002.
    * Office 2003
    Note Office 2003 includes Word 2003, Excel 2003, Outlook 2003, PowerPoint 2003, FrontPage 2003, Publisher 2003, InfoPath 2003, and OneNote 2003.
    * Digital Image Pro 7.0
    * Digital Image Pro 9
    * Digital Image Suite 9
    * Greetings 2002
    * Picture It! 2002 (all versions)
    * Picture It! 7.0 (all versions)
    * Picture It! 9 (all versions, including Picture It! Library)
    * Producer for PowerPoint (all versions)
    * Project 2002 SP1 (all versions)
    * Project 2003 (all versions)
    * Visio 2002 SP2 (all versions)
    * Visio 2003 (all versions)
    * Visual Studio .NET 2002
    Note Visual Studio .NET 2002 includes Visual Basic .NET Standard 2002, Visual C# .NET Standard 2002, and Visual C++ .NET Standard 2002.
    * Visual Studio .NET 2003
    Note Visual Studio .NET 2003 includes Visual Basic .NET Standard 2003, Visual C# .NET Standard 2003, Visual C++ .NET Standard 2003, and Visual J# .NET Standard 2003.
    * .NET Framework 1.0 SP2
    * .NET Framework 1.0 SDK SP2
    * .NET Framework 1.1
    * Platform SDK Redistributable: GDI+

    --
    "They redundantly repeated themselves over and over again incessantly without end ad infinitum" -- ibid.