Mitigating Factors:
Internet Explorer 8 is not affected and Protected Mode in Internet Explorer 7 in Windows Vista limits the impact of the vulnerability.
UAC is NOT poorly implemented. UAC implementation is much better than Linux's sudo.
The programs are poorly implemented assuming administrative privileges for everything!
what these hackers just discovered is a way to make sure the flaw is exploited "successfully" even under vista which was supposed to prevent every buffer overflows exploits with the help of DEP and ASLR. (as opposite to windows xp where these kind of flaw could always be successfully exploited)
People still use Internet Exploder? yes, I use Internet Explorer in Windows Vista that is the safest browser because it runs with the lowest privileges possibile in a sandbox (IE7 Protected mode).
In fact IE7 under Vista is not affected by this flaw i.e. remote code execution is not possible (yet another reason to use Vista and UAC).
This is proof of what I've said from the beginning -- the whole concept 'zones' in IE is stupid and pointless. IE's zones is a very good thing because it gives different level of security based on zones, "internet zone" has an higher security, "local zone" has a lower security, "restricted zone" has the maximum security.
Scripts should be allowed only what you allow them, period. "allow or cancel" question for each site you visit? are you crazy???? scripting is not dangerous unless there's a flaw in javascript.
You should be able to give permissions down to the individual site you can do it with IE by putting the sites into the different zones. If you want block a site, just put it in "restricted sites" zone.
(ala NoScript) or even down to the individual script. "allow or cancel" question for each site you visit? are you crazy???? scripting is not dangerous unless there's a flaw in javascript.
Microsoft is NOT planning to release Windows 7 in 2009 !
Contrary to all that is being said on the net, it clearly looks like Microsoft is NOT planning to release Windows 7 in 2009.
Q. What is the expected timeline for the availability of Windows 7?
A. We are currently in the planning stages for Windows 7 and expect it will take approximately 3 more years to develop. The specific release date will be determined once the company meets its quality bar for release.
All this smoke of Windows 7, being released next year, may have led to confusion in the minds of the Windows Vista user.
http://www.winvistaclub.com/i7.html
the effects are very slow and drop frames
on
KDE 4.0 Is Out
·
· Score: 1
"the effects are very slow and drop frames, there are remnants everywhere, you name it. This is annoying, but acceptable, seeing this is the first official release of the new KWin, and you cannot expect the developers to reach the same level of stability and performance of OS X' Quartz Extreme, Vista's Desktop Window Manager"
http://osnews.com/story/19159/KDE_4.0.0:_Sweet_Follows_Sour
Linux Kernel Random Number Generator Local DoS and Privilege Escalation Vulnerability:
http://www.securityfocus.com/bid/25348
Vulnerable:
Ubuntu Ubuntu Linux 7.04 sparc
Ubuntu Ubuntu Linux 7.04 powerpc
Ubuntu Ubuntu Linux 7.04 i386
Ubuntu Ubuntu Linux 7.04 amd64
Ubuntu Ubuntu Linux 6.10 sparc
Ubuntu Ubuntu Linux 6.10 powerpc
Ubuntu Ubuntu Linux 6.10 i386
Ubuntu Ubuntu Linux 6.10 amd64
Ubuntu Ubuntu Linux 6.06 LTS sparc
Ubuntu Ubuntu Linux 6.06 LTS powerpc
Ubuntu Ubuntu Linux 6.06 LTS i386
Ubuntu Ubuntu Linux 6.06 LTS amd64
Linux kernel 2.6.22 1
Linux kernel 2.6.22
Linux kernel 2.6.22
Linux kernel 2.6.21 4
Linux kernel 2.6.21.7
Linux kernel 2.6.21.6
Linux kernel 2.6.21.2
Linux kernel 2.6.21.1
Linux kernel 2.6.21
Linux kernel 2.6.21
remote code execution flaw in linux KDE with KPDF
Impact
======
A remote attacker could entice a user to open a specially crafted PDF
file in KWord or KPDF that would exploit the integer overflow to cause
a stack-based buffer overflow in the StreamPredictor::getNextLine()
function, possibly resulting in the execution of arbitrary code with
the privileges of the user running the application.
KOffice is an integrated office suite for KDE. KWord is the KOffice
word processor. KPDF is a KDE-based PDF viewer included in the
kdegraphics package.
http://www.gentoo.org/security/en/glsa/glsa-200710-08.xml
This ATI's flaws requires administrative privileges...
In linux it's possible to replace the whole kernel with a single command line, because linux kernel hasn't a code protection mechanism.
linux has a worst protection than Vista
The results of the analysis show that Windows Vista continues to show a trend of fewer total and fewer High severity vulnerabilities at the 6 month mark compared to its predecessor product Windows XP and compared to other modern competitive workstation OSes linux and Mac OS X
Mitigating Factors: Internet Explorer 8 is not affected and Protected Mode in Internet Explorer 7 in Windows Vista limits the impact of the vulnerability.
but it's not enabled by default in IE7. And XP hasn't ASLR.
XP TCP/IP stack is obsolete. Vista TCP/IP stack is much better. Yet another reason to use Vista
UAC is NOT poorly implemented. UAC implementation is much better than Linux's sudo. The programs are poorly implemented assuming administrative privileges for everything!
so I feel miracled because with a P4 1.7GHz, 1GB RAM and a geforce 6200, my Vista Home Premiums is faster than XP
this news is pure F U D
what these hackers just discovered is a way to make sure the flaw is exploited "successfully" even under vista which was supposed to prevent every buffer overflows exploits with the help of DEP and ASLR. (as opposite to windows xp where these kind of flaw could always be successfully exploited)
this is just FUD
this news is pure FUD
this news is pure FUD because all OS's are affected, NOT just only Windows.
Windows 3.1 is faster than XP
this news is pure FUD
Microsoft is NOT planning to release Windows 7 in 2009 ! Contrary to all that is being said on the net, it clearly looks like Microsoft is NOT planning to release Windows 7 in 2009. Q. What is the expected timeline for the availability of Windows 7? A. We are currently in the planning stages for Windows 7 and expect it will take approximately 3 more years to develop. The specific release date will be determined once the company meets its quality bar for release. All this smoke of Windows 7, being released next year, may have led to confusion in the minds of the Windows Vista user. http://www.winvistaclub.com/i7.html
"the effects are very slow and drop frames, there are remnants everywhere, you name it. This is annoying, but acceptable, seeing this is the first official release of the new KWin, and you cannot expect the developers to reach the same level of stability and performance of OS X' Quartz Extreme, Vista's Desktop Window Manager" http://osnews.com/story/19159/KDE_4.0.0:_Sweet_Follows_Sour
Linux Kernel Random Number Generator Local DoS and Privilege Escalation Vulnerability: http://www.securityfocus.com/bid/25348 Vulnerable: Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Linux kernel 2.6.22 1 Linux kernel 2.6.22 Linux kernel 2.6.22 Linux kernel 2.6.21 4 Linux kernel 2.6.21 .7
Linux kernel 2.6.21 .6
Linux kernel 2.6.21 .2
Linux kernel 2.6.21 .1
Linux kernel 2.6.21
Linux kernel 2.6.21
this news wins "The Best FUD of the Year 2007" award.
remote code execution flaw in linux KDE with KPDF Impact ====== A remote attacker could entice a user to open a specially crafted PDF file in KWord or KPDF that would exploit the integer overflow to cause a stack-based buffer overflow in the StreamPredictor::getNextLine() function, possibly resulting in the execution of arbitrary code with the privileges of the user running the application. KOffice is an integrated office suite for KDE. KWord is the KOffice word processor. KPDF is a KDE-based PDF viewer included in the kdegraphics package. http://www.gentoo.org/security/en/glsa/glsa-200710-08.xml
This news is fure FUD This news is fure FUD This news is fure FUD
This ATI's flaws requires administrative privileges... In linux it's possible to replace the whole kernel with a single command line, because linux kernel hasn't a code protection mechanism. linux has a worst protection than Vista
this ATI's flaw is locally exploitable only and it requires administrative privileges.
This news is pure FUD, because this update is a reliable update and NOT a secuity update.
The results of the analysis show that Windows Vista continues to show a trend of fewer total and fewer High severity vulnerabilities at the 6 month mark compared to its predecessor product Windows XP and compared to other modern competitive workstation OSes linux and Mac OS X
this news is pure FUD