Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Microsoft sees 3 'critical' Windows security flaws
AP via Boston.com ^ | 9 August 2005

Posted on 08/09/2005 2:03:40 PM PDT by Fractal Trader

Microsoft Corp. warned users of its Windows operating system on Tuesday of three newly found "critical" security flaws in its software, including one that could allow attackers to take complete control of a computer.

Computer security experts urged users to download and install the patches, which are available at www.microsoft.com/security.

"Users (should) apply the updates as quickly as possible," said Oliver Friedrichs, senior manager of Symantec Security Response, part of security software company Symantec Corp. SYMC.O.

Microsoft said that vulnerabilities exist in its Internet Explorer Web browser, the most severe of which could allow an attacker to take complete control of an affected computer.

An attacker could exploit that vulnerability by luring users to malicious Web pages and running software code on the user's PC resulting to take it over.

Microsoft also issued another security warning, which it rated at its second-highest level of "important."

For more than three years, Microsoft has been working to improve the security and reliability of its software as more and more malicious software targets weaknesses in Windows and other Microsoft software.

[SNIP]

(Excerpt) Read more at boston.com ...


TOPICS: Business/Economy; Technical
KEYWORDS: atnoextracharge; backdoor; bloatware; crapware; criticalflaw; exploit; getamac; internetexploiter; lookoutexpress; lowqualitycrap; malware; microsloth; microsoft; patch; securityflaw; spyware; theskyisblue; trojan; trojanhorse; virus; virusbait; windows; worm; wormfriendlycrap; youpaidforit
I wonder if these exploits are being used by the Cool Web Search malware mentioned in another post.
1 posted on 08/09/2005 2:03:41 PM PDT by Fractal Trader
[ Post Reply | Private Reply | View Replies]

To: Fractal Trader

Probably so. My question is, why only three?


2 posted on 08/09/2005 2:11:34 PM PDT by Mister_Diddy_Wa_Diddy
[ Post Reply | Private Reply | To 1 | View Replies]

To: Fractal Trader
An attacker could exploit that vulnerability by luring users to malicious Web pages...

DU?

3 posted on 08/09/2005 2:13:32 PM PDT by Mark (Proven scientific experiment: The NY Times flushes easily down the standard toilet.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Fractal Trader

> Microsoft said that vulnerabilities exist in its Internet Explorer Web browser ...

Download and use FireFox.

It's not perfect either, but it is vastly safer.

And make sure your firewall, anti-virus and anti-spyware
apps are up to date (or switch to Linux, which has vastly
less need for such defenses).


4 posted on 08/09/2005 2:14:08 PM PDT by Boundless
[ Post Reply | Private Reply | To 1 | View Replies]

To: Fractal Trader
whoa, complete control?

i'd better take an axe to those darn COMPUTERS before they get ambitious and try to get control over...over...the whole world!

/ humor off

5 posted on 08/09/2005 2:16:16 PM PDT by NoClones
[ Post Reply | Private Reply | To 1 | View Replies]

To: Mister_Diddy_Wa_Diddy

There are 3 critical-rated security updates, but more that are rated non-critical.

Including that Windows malware detector tool, I'm currently downloading 8 updates.


6 posted on 08/09/2005 2:21:39 PM PDT by Terpfen (Liberals call the Constitution a living document because they enjoy torturing it.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Fractal Trader

Any idea how you can determine what service pack your computer is currently running--1 vs 2?


7 posted on 08/09/2005 2:22:00 PM PDT by Cautor
[ Post Reply | Private Reply | To 1 | View Replies]

To: Boundless
... or switch to Linux...

Whoa, I see a typo there! I think you meant "OS X," not Linux. :)
8 posted on 08/09/2005 2:22:38 PM PDT by Terpfen (Liberals call the Constitution a living document because they enjoy torturing it.)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Mister_Diddy_Wa_Diddy

I get the suspicion that they are built in on purpose.


9 posted on 08/09/2005 2:23:49 PM PDT by airborne
[ Post Reply | Private Reply | To 2 | View Replies]

To: Cautor
Any idea how you can determine what service pack your computer is currently running

Open "My Computer" and select the menu item "Help/About"

10 posted on 08/09/2005 2:24:18 PM PDT by dinasour (Pajamahadeen)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Fractal Trader

This cant be! I have been told many times that closed source is much safer because the code is not out there for the world to see..


11 posted on 08/09/2005 2:24:39 PM PDT by N3WBI3 (If SCO wants to go fishing they should buy a permit and find a lake like the rest of us..)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Terpfen

You getting MS05-038? That's the cumulative IE patch. I keep getting "page not found."


12 posted on 08/09/2005 2:25:43 PM PDT by Billthedrill
[ Post Reply | Private Reply | To 6 | View Replies]

To: Fractal Trader

This cant be! Ive been told many times windows is much more safe because the hackers dont have easy access to the source.. Were they lying to me?


13 posted on 08/09/2005 2:26:39 PM PDT by N3WBI3 (If SCO wants to go fishing they should buy a permit and find a lake like the rest of us..)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Cautor

start -> run -> then type "winver" (without the quotes)


14 posted on 08/09/2005 2:27:51 PM PDT by N3WBI3 (If SCO wants to go fishing they should buy a permit and find a lake like the rest of us..)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Terpfen

You can switch to Linux, but you can't switch your existing WinXP box to OS X.... yet.


15 posted on 08/09/2005 2:30:06 PM PDT by MediaMole
[ Post Reply | Private Reply | To 8 | View Replies]

To: Billthedrill

I don't know the ID#, but I just downloaded 5 security updates, two routine updates, and that Windows malware detection tool (which of course detected nothing, because I keep my system protected.)


16 posted on 08/09/2005 2:30:46 PM PDT by Terpfen (Liberals call the Constitution a living document because they enjoy torturing it.)
[ Post Reply | Private Reply | To 12 | View Replies]

To: Terpfen

>> ... or switch to Linux...

> Whoa, I see a typo there!
> I think you meant "OS X," not Linux. :)

Well, ya, sure, but:
- it's not a free download, and
- it won't run on your existing hardware that is
presently hosting Mr.Bill's fragile collage of DOS patches


17 posted on 08/09/2005 2:33:16 PM PDT by Boundless
[ Post Reply | Private Reply | To 8 | View Replies]

To: NoClones
complete control

Yeah, mine sold my house while I wasn't looking and blew it all on poker.

18 posted on 08/09/2005 2:33:50 PM PDT by Right Wing Assault ("..this administration is planning a 'Right Wing Assault' on values and ideals.." - John Kerry)
[ Post Reply | Private Reply | To 5 | View Replies]

To: dinasour

Thank you. Will do.


19 posted on 08/09/2005 2:35:04 PM PDT by Cautor
[ Post Reply | Private Reply | To 10 | View Replies]

To: N3WBI3

Thanks to you also.


20 posted on 08/09/2005 2:35:36 PM PDT by Cautor
[ Post Reply | Private Reply | To 14 | View Replies]

To: Terpfen
I think you meant "OS X," not Linux.

Is MacOS X available for the Intel platform yet?

As an aside, I got a Mac Mini a couple of months ago. Good machine at a good price. I'm a *nix goon, and grok its BSDness. But what I like the most is that the system is scarcely bigger than a double CD jewel case. I could easily stack a dozen of these things in one Intel desktop footprint.

21 posted on 08/09/2005 2:38:07 PM PDT by Prime Choice (E=mc^3. Don't drink and derive.)
[ Post Reply | Private Reply | To 8 | View Replies]

To: Boundless

No, OS X isn't free, but it's well worth the money. I maintain that OS X is open source done right, since it's based on BSD. The UI is perfect.


22 posted on 08/09/2005 3:09:03 PM PDT by Terpfen (Liberals call the Constitution a living document because they enjoy torturing it.)
[ Post Reply | Private Reply | To 17 | View Replies]

To: Prime Choice

No Intel Macs until 2006. I'm holding off on a Mac Mini until Apple switches over.

Personally, I'm hoping that Apple turns the Mini into an HTPC of sorts. Get a GeForce 6200 in there for its Purevideo capabilities, a 5400/7200 RPM HD, and some program with HT capabilities (iTunes 5.0?) and the Mini will sell like hotcakes. It's a perfect candidate for Intel's Yonah chip, too.


23 posted on 08/09/2005 3:10:46 PM PDT by Terpfen (Liberals call the Constitution a living document because they enjoy torturing it.)
[ Post Reply | Private Reply | To 21 | View Replies]

To: MediaMole

True, but were I to switch to another OS, I'd want to just get the best thing available, rather than trying to make do with what I have.


24 posted on 08/09/2005 3:12:03 PM PDT by Terpfen (Liberals call the Constitution a living document because they enjoy torturing it.)
[ Post Reply | Private Reply | To 15 | View Replies]

To: Mister_Diddy_Wa_Diddy
Probably so. My question is, why only three?

No doubt there are others that M$ and the hackers know, but you the end user does not know. These will not be revealed to you until M$ has a fix. This is to protect microsoft and microsoft only.

Informing the users of other threats that are not yet fixable will only serve to sow fear, uncertainy and doubt (FUD) into the enduser regarding microsoft's "security is job one" message.

25 posted on 08/09/2005 3:26:48 PM PDT by AFreeBird (your mileage may vary)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Fractal Trader

buy a computer condom. you just slip it on and you're safe.
no viruses AND no unwanted pregnancies.


26 posted on 08/09/2005 4:03:30 PM PDT by pipecorp (Let's have a CRUSADE! , the muslim half has already started. ps. I need more cowbell!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: All; Golden Eagle
This cant be! Ive been told many times windows is much more safe because the hackers dont have easy access to the source.. Were they lying to me?

Whoever made this comment is obviously a troll. I would reply to the original poster of this comment; however, after he admitted he was the troll in freepmail he asked that I never respond to him again.

27 posted on 08/10/2005 5:25:45 PM PDT by for-q-clinton (If at first you don't succeed keep on sucking until you do succeed)
[ Post Reply | Private Reply | To 13 | View Replies]

To: Fractal Trader
Just ran the updates today before I read this. They now make you dl Active X. I'd been trying to avoid that, but finally needed it when I wanted to buy some stamps made out of my own photos so took the plunge.

It didn't sound like MS Active X has anything to do with that.

28 posted on 08/10/2005 5:30:39 PM PDT by Aliska
[ Post Reply | Private Reply | To 1 | View Replies]

To: NoClones
Best laugh I have had all day! Thanks. I have just had it with my dial up. It has disconnected me for the last time!!! I ordered Direcway Internet from the Direct TV people today. I can't get cable or DSL out here, so that was all there was left. I NEED my computer. Where else can I get this kind of fun and excitement?
29 posted on 08/10/2005 5:31:46 PM PDT by Goodgirlinred ( GoodGirlInRed Four More Years!!!!!)
[ Post Reply | Private Reply | To 5 | View Replies]

To: for-q-clinton; N3WBI3
There were more patches announced for Linux the same day, yet the lunies like NEWBIE would love to hide that little fact.

Distribution ID Package Date
Ubuntu USN-163-1 xpdf 2005-08-09
Red Hat RHSA-2005:670-01 xpdf 2005-08-09
Red Hat RHSA-2005:598-01 sysreport 2005-08-09
Red Hat RHSA-2005:671-01 kdegraphics 2005-08-09
Red Hat RHSA-2005:706-01 CUPS 2005-08-09
Red Hat RHSA-2005:720-01 ucd-snmp 2005-08-09
Mandriva MDKSA-2005:133 netpbm 2005-08-09
Mandriva MDKSA-2005:132 heartbeat 2005-08-09
Red Hat RHSA-2005:627-01 gaim 2005-08-09
Red Hat RHSA-2005:589-01 gaim 2005-08-09

30 posted on 08/10/2005 6:38:37 PM PDT by Golden Eagle
[ Post Reply | Private Reply | To 27 | View Replies]

To: Golden Eagle

That is really ironic.

But I'm *sure* they had them fixed in less than 24 hours from the time they were notified of the bugs. {/sarcasm}


31 posted on 08/10/2005 7:35:53 PM PDT by for-q-clinton (If at first you don't succeed keep on sucking until you do succeed)
[ Post Reply | Private Reply | To 30 | View Replies]

To: Golden Eagle

I was shocked to see RH have so many bug fixes. Oh wait, since it's RH I need to say they are great for fixing all those bugs.

I was also shocked to see Linux have a buffer overflow vulnerability. Here's a taste of one of the bulletins.

-



Red Hat Security Advisory

Synopsis: Critical: gaim security update
Advisory ID: RHSA-2005:627-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-627.html
Issue date: 2005-08-09
Updated on: 2005-08-09
Product: Red Hat Enterprise Linux
CVE Names: CAN-2005-2102 CAN-2005-2103 CAN-2005-2370
-


1. Summary:

An updated gaim package that fixes multiple security issues is now available.

This update has been rated as having critical security impact by the Red
Hat Security Response Team.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Desktop version 3 - i386, x86_64
Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64
Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux Desktop version 4 - i386, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64

3. Problem description:

Gaim is an Internet Messaging client.

A heap based buffer overflow issue was discovered in the way Gaim processes
away messages. A remote attacker could send a specially crafted away
message to a Gaim user logged into AIM or ICQ that could result in
arbitrary code execution. The


32 posted on 08/10/2005 7:40:28 PM PDT by for-q-clinton (If at first you don't succeed keep on sucking until you do succeed)
[ Post Reply | Private Reply | To 30 | View Replies]

To: Golden Eagle; for-q-clinton

Hmm for once I decide to see how ms fanatics would respond so some of the sarcasm they so readily dish out whenever there is an OSS bug and they buy it hook line and sinker... What do they do? well they dont address the serious issue for which the thread was created, instead they just attack something else to deflect from a serious MS bug..


33 posted on 08/10/2005 8:58:05 PM PDT by N3WBI3 (If SCO wants to go fishing they should buy a permit and find a lake like the rest of us..)
[ Post Reply | Private Reply | To 30 | View Replies]

To: N3WBI3
Hmm for once I decide to see how ms fanatics

LOL. You're a joke calling everyone a troll when in fact you are a troll. Also you asked that I never post to you again and that you would do so in kind. Well, looks like you can't even keep that promise.

34 posted on 08/10/2005 11:54:09 PM PDT by for-q-clinton (If at first you don't succeed keep on sucking until you do succeed)
[ Post Reply | Private Reply | To 33 | View Replies]

To: N3WBI3

Also to to mock your last post a little.

For once I decide to post one of the RH vulnerabilities... What do they do? well they don't address the serious issue, instead they just attack something else to deflect from a serious MS bug.


35 posted on 08/10/2005 11:56:50 PM PDT by for-q-clinton (If at first you don't succeed keep on sucking until you do succeed)
[ Post Reply | Private Reply | To 33 | View Replies]

To: N3WBI3

Also to to mock your last post a little.

For once I decide to post one of the RH vulnerabilities... What do they do? well they don't address the serious issue, instead they just attack something else to deflect from a serious Linux bug.


36 posted on 08/10/2005 11:56:59 PM PDT by for-q-clinton (If at first you don't succeed keep on sucking until you do succeed)
[ Post Reply | Private Reply | To 33 | View Replies]

To: Right Wing Assault

Just this morning mine demanded I get it coffee and donuts. Must be all the police sites I visit. :o)


37 posted on 08/10/2005 11:59:57 PM PDT by BigCinBigD
[ Post Reply | Private Reply | To 18 | View Replies]

To: N3WBI3

freepMail from N3WBI3 to me:

Re: EU plan could put open sourcers in court
From N3WBI3 | 08/03/2005 1:18:07 PM EDT replied

Hey let me ask you something are you always going to troll around or do you actually want to have a discussion? just need to know wether or not to completely ignore you...

Re: EU plan could put open sourcers in court
To N3WBI3 | 08/03/2005 1:59:02 PM EDT sent

Me the troll? LOL. Look in the mirror. Many of my questions are legit and aren't trolling. Others are a setup to future lines of questioning to make a point. unfortunately, I find I must do this with most FOSS types because they will argue it's FREE as in FREE BEER, then when you show that it isn't they switch to FREE as in FREE to Innovate.

How is what I'm doing trolling? If you read my earlier posts on the current thread it relates to the thread. That isn't trolling.

Re: EU plan could put open sourcers in court
From N3WBI3 | 08/03/2005 2:45:15 PM EDT replied

You have answered my question with teh attidue of this mail and the other post, thanks..

Re: EU plan could put open sourcers in court
To N3WBI3 | 08/03/2005 3:18:13 PM EDT sent

You're such the troll it's unbelievable. How many times did you post to me before I responded? Do the math...then look who the troll is. Just because I schooled you on the thread, you don't need to resort to name calling.

Re: EU plan could put open sourcers in court
From N3WBI3 | 08/03/2005 3:24:43 PM EDT read

My Purpose was not to have an argument, yours was... Call me what you will and if indeed you think I am a troll than you’ll be glad to know I won’t be addressing you anymore... Please extend me the same.

 

 


38 posted on 08/11/2005 12:05:00 AM PDT by for-q-clinton (If at first you don't succeed keep on sucking until you do succeed)
[ Post Reply | Private Reply | To 33 | View Replies]

To: for-q-clinton
He's done the same to me before too, saying he'll never post to me again after I completely exposed and embarrassed him over something. Obviously not a man of his word, but we already knew that.
39 posted on 08/11/2005 5:26:54 AM PDT by Golden Eagle
[ Post Reply | Private Reply | To 38 | View Replies]

To: Golden Eagle

Those are application bugs, not OS bugs. MSIE issues are, by Microsoft's own definitions used in court, bugs in the OS.


40 posted on 08/11/2005 5:31:11 AM PDT by kevkrom (WARNING: If you're not sure whether or not it's sarcasm, it probably is.)
[ Post Reply | Private Reply | To 30 | View Replies]

To: kevkrom

And according to your definition of the Linux O/S, it's no larger than 1 file in Windows like ntoskrnl.exe, right? These holes in Red Hat are distributed with each copy of Linux, just like many files other than ntoskrnl.exe are distributed with Windows.

Everyone is getting wise to the lunix myths, not just a few of us anymore.


41 posted on 08/11/2005 5:35:38 AM PDT by Golden Eagle
[ Post Reply | Private Reply | To 40 | View Replies]

To: Fractal Trader
Its important to patch security flaws quickly. I've never had a problem with my computer being compromised but better safe than sorry. And of course, be sure to keep your anti-virus and anti-spyware software up to date as well.

(Denny Crane: "Sometimes you can only look for answers from God and failing that... and Fox News".)
42 posted on 08/11/2005 5:37:31 AM PDT by goldstategop (In Memory Of A Dearly Beloved Friend Who Lives On In My Heart Forever)
[ Post Reply | Private Reply | To 1 | View Replies]

To: for-q-clinton
lol sorrydid not mean to upset you..

I figure as you have talked about me by name without promoting and posting it to bot GE and B2K all bets were off..

43 posted on 08/11/2005 5:45:35 AM PDT by N3WBI3 (If SCO wants to go fishing they should buy a permit and find a lake like the rest of us..)
[ Post Reply | Private Reply | To 38 | View Replies]

To: Golden Eagle
And according to your definition of the Linux O/S, it's no larger than 1 file in Windows like ntoskrnl.exe, right?

Wrong, but thanks for playing (and, not surprisingly, completely misrepresenting me).

The operating system refers to the whole set of programs, drivers, etc., that are responsible for the basic systems operation. This includes things like the scheduler, memory management, file management, and so on.

Now, in Microsoft's case, because of some of their software architecture decisions, some user-level appications (specifically, "explorer") are tied into the operating system. Because of the modular nature of UNIX-like systems, this doesn't happen with user applications, because it is designed to abstract the OS away from the applications, especially since the applications come from multiple sources.

Now, to the specific list you were posting... "gaim" is an instant-messenger client. If AOL had a bug in their AIM program for Windows, would it be fair to say it's a problem with the Windows OS? Of course not. Then why is a "gaim" bug a "Linux" problem? Answer: it isn't -- it's an application bug.

44 posted on 08/11/2005 5:46:03 AM PDT by kevkrom (WARNING: If you're not sure whether or not it's sarcasm, it probably is.)
[ Post Reply | Private Reply | To 41 | View Replies]

To: Fractal Trader

Sometimes I think Windows ability to boot up is a flaw.


45 posted on 08/11/2005 5:46:45 AM PDT by TheForceOfOne (The alternative media is our Enigma machine.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Golden Eagle
Actually its after you took a pot shot at my family dweeb..
46 posted on 08/11/2005 5:47:12 AM PDT by N3WBI3 (If SCO wants to go fishing they should buy a permit and find a lake like the rest of us..)
[ Post Reply | Private Reply | To 39 | View Replies]

To: N3WBI3
I figure as you have talked about me by name without promoting and posting it to bot GE and B2K all bets were off..

Do you really want me to expose you again? How about I show where you did the same about me BEFORE I mentioned you?

It's not that big of a deal, but I am finding a disturbing trend. You just make up stuff to suit your needs.

47 posted on 08/11/2005 6:16:02 AM PDT by for-q-clinton (If at first you don't succeed keep on sucking until you do succeed)
[ Post Reply | Private Reply | To 43 | View Replies]

To: for-q-clinton

Was it in reply to your post mentioning you by name? I jsut really wanted you to see how you reacted when a sarcastic post hit a windows thread and as predicted it was the exact same way I reacted when you hit the linux thread.... Dont keep making it worse by going on and ignoring the serious vulnerabilities that this thread is about..


48 posted on 08/11/2005 6:29:10 AM PDT by N3WBI3 (If SCO wants to go fishing they should buy a permit and find a lake like the rest of us..)
[ Post Reply | Private Reply | To 47 | View Replies]

To: N3WBI3

You're busted for being a troll and then you just claim...I was testing a theory. Yeah, right. Keep lying to yourself as no one else is believing you and you're making yourself look silly to your OSS Ping list compatriots.


49 posted on 08/11/2005 7:31:03 AM PDT by for-q-clinton (If at first you don't succeed keep on sucking until you do succeed)
[ Post Reply | Private Reply | To 48 | View Replies]

To: for-q-clinton
making yourself look silly to your OSS Ping list compatriots.

I wish that were the case, but they love to lie and distort, he's a perfect example of their kind, and is therefore probably being cheered for his antics. Oh well, at least the OSS fanatics as a group are still stuck down in the <5% of overall society, as they have been for years.

50 posted on 08/11/2005 10:23:32 AM PDT by Golden Eagle
[ Post Reply | Private Reply | To 49 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson