HP Advertorial

Conten width:260px + 10px padding left + 10px padding right
Max height: 2000px

« Intel goes all-in-one with next gen processors | Main | Stupendously useful Firefox feature »

Is nothing secure any more?

That was the question in my mind this morning, as I woke up XP and found that Windows Update had downloaded some patches overnight.

The details for the patches are available from Microsoft here, but check this out...

Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a malformed .ANI, cur, or .ico file, which results in memory corruption when processing cursors, animated cursors, and icons...

All versions of Windows are affected, with Windows 2000 the hardest and Vista the least - so get patching.

Speaking of security, I note that a new Stration worm variant is being emailed out at the moment. NOD32 identifies it as Win32/Stration.XW. I got two samples in that usual, idiotic "Mail Server Report - install this Update" social engineering style message. Keep your antivirus up-to-date and don't shoot yourself in the foot by running untrusted attachments, mmkay?

Comments

That'll come with SP3, I'm afraid...

"buffer overflow"? They are *still* getting that well known insecurity? The string handling libraries have (or should have) secure versions of all the routines which can be affected. Why don't they just use them?

Post a comment

Subscribe
Newsletter & SubscriptionsPC World is New Zealand’s top selling computing and technology magazine.

It provides up-to-the-minute editorial, insight and buying advice for personal computing, cell phones, game consoles, digital entertainment and broadband.
SIGN UP
PCWorldUpdate
PC World's fortnightly round-up of tech news, gear and game reviews, software selections, and handy How Tos.