also @ TechSpot: UK's SOCA seizes domain of popular music blog, rnbxclusive.com
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Sign up or Login to participate.

Go Back   TechSpot OpenBoards > TechSpot Community > General Discussion

Collaborate in the cloud with Office, Exchange, SharePoint, and Lync

Microsoft reveals DirectX 'critical' flaw

Thread Tools Search this Thread
  #1  
Old 07-24-2003
Julio's Avatar
TechSpot Executive Editor
 
Location: Ecuador
Member since: Feb 2002, 5,355 posts
System specs
Microsoft reveals 'critical' flaw

The flaw is unusually widespread, affecting all versions of DirectX from version 5.2 to the current 9.0a running on all versions of Windows from Windows 98 through the new Windows Server 2003, according to the Microsoft bulletin.

The flaw, which received Microsoft's highest severity rating, involves the way DirectX handles MIDI music files. A malformed MIDI file could overrun the buffer in DirectX, at which point extra software embedded in the file would be executed.
Exploiting the flaw would entail the creation of a maliciously malformed MIDI file, which vulnerable Windows users would have to be tricked into running, either through e-mail or a Web page.

Read more: CNet News.
  #2  
Old 07-24-2003
Abraxas's Avatar
TechSpot Enthusiast
 
Member since: Jun 2003, 205 posts
Does 9.0b fix that?
  #3  
Old 07-24-2003
Phantasm66's Avatar
TechSpot Evangelist
 
Location: Glasgow, Scotland
Member since: Feb 2002, 6,504 posts
I don't know (have not checked) but I would imagine that that would explain 9.0b 's sudden arrival I have certainly downloaded and installed 9.0b as soon as I read about it here.

  #4  
Old 07-25-2003
---agissi---'s Avatar
TechSpot Paladin
 
Location: Montana
Member since: Mar 2002, 2,304 posts
Another bug :eek:

Do they ever check they're software for this kind of stuff?? Its posted all the time
  #5  
Old 07-25-2003
XtR-X's Avatar
TechSpot Maniac
 
Location: Orange County, CA
Member since: Jun 2003, 1,040 posts
I guess it's safe to say that we should all avoid MIDIs for a short while until the problem is completely solved.

The scary thing is that we can trail off to a site that has embedded MIDI inside the HTML and we could be attacked by it.
  #6  
Old 07-25-2003
TS | Thomas's Avatar
TechSpot Maniac
 
Location: Ireland
Member since: Feb 2002, 1,327 posts
Yes, DirectX 9.0b fixes this.
Closed Thread

Similar Topics
Topic Replies Forum
Microsoft reveals first Internet Explorer 9 details 4 TechSpot News and Comments
Microsoft warns world of critical security flaw 13 TechSpot News and Comments
Microsoft XP Security Flaw 0 General Discussion
Critical Security Flaw in Many Ethernet Device Drivers 0 General Discussion
Microsoft Ups IE Flaw to 'Critical' 0 General Discussion

Thread Tools Search this Thread
Search this Thread:

Advanced Search
All times are GMT -4. The time now is 06:59 AM.