Slashdot Mirror


Flaw in Microsoft JPEG Parsing

KDan writes "As reported by numerous sources, a new vulnerability has been disclosed (and patched) by Microsoft. This one concerns the parsing of JPEGs in XP Microsoft applications. A buffer overflow can be used to execute arbitrary code. So all those times you told your parents/friends that looking at images was safe - well, not anymore."

3 of 555 comments (clear)

  1. As reported by numerous sources by BestNicksRTaken · · Score: 0, Offtopic

    So why did you have to start a thread about it too?

    Jees, I've got turned down so many times for relevant articles on here, how come this crap that we've all already read elsewhere, that isn't even that interesting, still gets let through?!

    Jees, next there will be reposts about a map of the Simpsons town, oh wait....

    --
    #include <sig.h>
  2. MODS!!! by darkmeridian · · Score: 0, Offtopic

    This is not off-topic. It is an Anonymous Coward, but he asks a legitimate question. I'm not going to answer it, nor am I sure whether it should be answered, but it is not off-topic to this thread. It in fact, would clarify the conversation.

    And while you're looking here, go through my previous messages and mod them up. You can be kind of like a "cold-case" squad.

    --
    A NYC lawyer blogs. http://www.chuangblog.com/
  3. Completely OT but...airpwn? by BillX · · Score: 0, Offtopic

    Not aimed at the original poster, just another kiddy rant.

    From the top Google result for the airpwn project:

    HTTP javascript alert boxes, letting people know just how pwned they were

    Pwned? What kind of kiddies come up with this stuff; that's not even pronounceable. If you're going to make up some l33t term for kiddying somebody's box, at least make it pronounceable so that you can tell your friends what you did without sounding like a complete dumbass (you know...in person...you do talk to people in person, right?)

    E.g.: "Haha, dude, I went to this coffeeshop, and everyone was on their like wireless thingamabobs, right? So I set up an injector node so that every image in the pages they loaded had little goatse's on them. I totally narfed them! I even popped up little boxes telling them how narfed they were."

    --
    Caveat Emptor is not a business model.