internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet |Refer-It

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Norton AntiVirus 2008

Most Popular Software Downloads
Ad-Aware 2008 Free
Windows XP Service Pack 3
Internet Explorer 7
QuickTime for Windows
Adobe Flash Player
AVG Anti-Virus Free
Paint Shop Pro
Windows Live Suite
CCleaner (Crap Cleaner)
Winamp

Most Popular Software Articles
Windows Vista Tips & Tricks, Part 1
Windows Vista: Worthy of the Hype?
Windows Wireless Zero Configuration: Five Steps to Sanity


Software Reviews

More Problems Found in Microsoft Software
Newly Discovered Flaw Not That Severe
Andy Patrizio

For the third time this month, a security flaw has been found relating to Excel, an application not normally associated with viruses and bugs. However, in this case, it's not directly an Excel problem. At the same time, Microsoft had to issue a patch for a patch released on June 12, which was supposed to fix a critical security hole.

Fortunately, the newly discovered flaw is not that severe. The fix was to Windows' Routing and Remote Access (RRA) service, known as security bulletin MS06-025. While the security hole was fixed, it broke direct dial-up scripting for some users with outdated modems.

A new document has been posted on the Microsoft support site addressing this issue. Microsoft is working on the patch but did not set a deadline for when a fix will be issued.

The Excel flaw is the third flaw to be found in the widely used spreadsheet, which isn't normally associated with viruses and security holes. This attack could be used to run unauthorized software on a PC, but it requires the user to open an Excel document first and then click on a hyperlink. A warning about the vulnerability was first published on the Securitytracker.com, which follows such errors.

The attack takes advantage of a flaw in Microsoft's hyperlinking dynamic link library (DLL) and Adobe's Flash technology, which can be used in an Excel document. When the user opens the Excel file and clicks on a link, the malicious Flash code will execute automatically without prompting the user to run, and can theoretically do more than just execute a Flash animation.

This is the third problem facing Excel in a week. On June 16, Microsoft alerted users to an undefined vulnerability and warned them not to open file attachments from unknown sources. A second, less critical flaw was found days later. Microsoft still has yet to issue patches for those two flaws.

Microsoft addressed the latest flaw in a blog posting that stated the flaw was actually in the hlink.dll, which is a Windows component that handles operations involving hyperlinks.

"Any attempt to exploit this vulnerability would require convincing a user to open a specially-crafted Excel document. The user would then also have to locate and click on a specially-crafted long link in that document. We have not found any way to attempt to exploit this vulnerability that involves simply opening a document: a user must click a hyperlink in the document," wrote Christopher Budd in the posting.

Once again, Microsoft reiterated not opening files from unknown senders, something people should have learned by now. "It's no different than Word docs. When you get something from a stranger, you have to take a reasonable amount of caution not to blindly open things up," said Stuart Moore, CEO of SecurityTracker.

Although the flaw is viewed as an Excel problem, the flaw is in the hyperlinking DLL and Excel was simply used as a proof of concept. "The way Microsoft sometimes smashes their apps and OSes together, sometimes it's hard to tell where an app problem stops and an OS problem starts," he said.

News courtesy of internetnews.com

June 23, 2006

Download Internet Explorer Security Patches Now!Download

View All Microsoft Service & Security Releases

Contents:
1. Newly Discovered Flaw Not That Severe






JupiterOnlineMedia

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

Solutions
Whitepapers and eBooks
Microsoft Article: Will Hyper-V Make VMware This Decade's Netscape?
Microsoft Article: 7.0, Microsoft's Lucky Version?
Microsoft Article: Hyper-V--The Killer Feature in Windows Server 2008
Avaya Article: How to Feed Data into the Avaya Event Processor
Microsoft Article: Install What You Need with Windows Server 2008
HP eBook: Putting the Green into IT
Whitepaper: HP Integrated Citrix XenServer for HP ProLiant Servers
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 1
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 2--The Future of Concurrency
Avaya Article: Setting Up a SIP A/S Development Environment
IBM Article: How Cool Is Your Data Center?
Microsoft Article: Managing Virtual Machines with Microsoft System Center
HP eBook: Storage Networking , Part 1
Microsoft Article: Solving Data Center Complexity with Microsoft System Center Configuration Manager 2007
MORE WHITEPAPERS, EBOOKS, AND ARTICLES
Webcasts
Intel Video: Are Multi-core Processors Here to Stay?
On-Demand Webcast: Five Virtualization Trends to Watch
HP Video: Page Cost Calculator
Intel Video: APIs for Parallel Programming
HP Webcast: Storage Is Changing Fast - Be Ready or Be Left Behind
Microsoft Silverlight Video: Creating Fading Controls with Expression Design and Expression Blend 2
MORE WEBCASTS, PODCASTS, AND VIDEOS
Downloads and eKits
Sun Download: Solaris 8 Migration Assistant
Sybase Download: SQL Anywhere Developer Edition
Red Gate Download: SQL Backup Pro and free DBA Best Practices eBook
Red Gate Download: SQL Compare Pro 6
Iron Speed Designer Application Generator
MORE DOWNLOADS, EKITS, AND FREE TRIALS
Tutorials and Demos
How-to-Article: Preparing for Hyper-Threading Technology and Dual Core Technology
eTouch PDF: Conquering the Tyranny of E-Mail and Word Processors
IBM Article: Collaborating in the High-Performance Workplace
HP Demo: StorageWorks EVA4400
Intel Featured Algorhythm: Intel Threading Building Blocks--The Pipeline Class
Microsoft How-to Article: Get Going with Silverlight and Windows Live
MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES