internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet |Refer-It

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Internet Explorer 8

Most Popular Software Downloads
Opera
Internet Explorer 7
QuickTime for Windows
Winamp
Mozilla Firefox 3
Ad-Aware 2008 Free
Adobe Flash Player
Paint Shop Pro
Adobe Shockwave Player
AVG Anti-Virus Free
7-Zip

Most Popular Software Articles
Windows Vista Tips & Tricks, Part 1
Windows Vista: Worthy of the Hype?
Windows Wireless Zero Configuration: Five Steps to Sanity


Software Reviews

Microsoft Patches 10 Vulnerabilities
June Patch Tuesday Arrives with Seven Security Bulletins
Sean Michael Kerner

Microsoft is out with its June Patch Tuesday vulnerability haul, this time issuing advisories on a range of technologies including Internet Explorer, Bluetooth, Microsoft Speech, DirectX, Windows Internet Name Service (WINS), and Pragmatic General Multicast (PGM) protocol.

Among the advisories labeled with the maximum severity of critical is MS08-31, which details a pair of vulnerabilities in Microsoft's Internet Explorer browser. One of them is titled "Request Header Cross-Domain Information Disclosure Vulnerability," and it could potentially have allowed an attacker to read a user's data.

According to Microsoft's advisory on the issue, "an attacker who successfully exploited this vulnerability could read data from a Web page in another domain in Internet Explorer."

Microsoft noted that some social engineering would be required for a user to be at risk from the vulnerability. The user would have to physically visit a Web site that hosted the malicious code in order to be at risk.

The second Internet Explorer vulnerability is titled "HTML Objects Memory Corruption Vulnerability" and could lead to arbitrary code execution on the user's PC.

"When Internet Explorer displays a Web page that contains certain unexpected method calls to HTML objects, it may corrupt memory in such a way that an attacker could execute arbitrary code," Microsoft stated in its advisory.

Also on the critical side are a pair of vulnerabilities in Microsoft's DirectX, which is core part of Windows multimedia handling infrastructure.

One the issues is a remote code execution vulnerability that could be trigged by viewing a malicious MJPEG file. The second DirectX issue is also a remote code execution risk, this time triggered by the way DirectX handles Synchronized Accessible Media Interchange (SAMI) file types.

Microsoft's advisory notes that "Microsoft Synchronized Accessible Media Interchange (SAMI) is a media format that allows a content developer to include captions with digital media files."

The Windows Internet Name Service (WINS) gets patched in the June update for a privilege escalation vulnerability.

"An elevation of privilege vulnerability exists in the Windows Internet Name Service (WINS) in the way that WINS does not sufficiently validate the data structures within specially crafted WINS network packets," Microsoft explained in its advisory.

"The vulnerability could allow a local attacker to run code with elevated privileges. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete date; or create new accounts."

Microsoft is also providing a patch in the June update for its Active Directory system. According to the advisory on the issue, the vulnerability is due to insufficient validation of specially crafted LDAP (define) requests. The issue could lead to a denial of service (DoS) condition or a system restart.

Among the fixes on this Patch Tuesday includes for a protocol that many have likely never heard of, let alone used.

There are two updates for security vulnerabilities in the Pragmatic General Multicast (PGM) protocol which could lead to a DoS condition.

"Only one engineer on our team had ever heard of it and he previously worked as a tester on the core network components team, a Microsoft spokesperson wrote on the Security Vulnerability Research and Defense blog. "PGM is a multicast transport protocol that guarantees reliable delivery from multiple sources to multiple receivers."

News courtesy of internetnews.com

June 11, 2008

Download Windows Live OneCare Now!Download

Download Microsoft Windows Malicious Software Removal Tool Now!Download

View All Microsoft Service & Security Releases

Contents:
1. June Patch Tuesday Arrives with Seven Security Bulletins




internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info

Legal Notices, Licensing, Reprints, Permissions, Privacy Policy.
Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

Whitepapers and eBooks

Symantec Whitepaper: Converging System and Data Protection for Complete Disaster Recovery
Intel Whitepaper: Comparing Two- and Four-Socket Platforms for Server Virtualization
IBM Solutions Brief: Go Green With IBM System xTM And Intel
HP eBook: Simplifying SQL Server Management
IBM Contest: Are You the Next Superstar? Join the "Search for the XML Superstar" Contest to Find Out
Intel PDF: Quad-Core Impacts More Than the Data Center
Intel PDF: Virtualization Delivers Data Center Efficiency
Go Parallel Article: PDC 2008 in Review
Avaya Article: Communication-Enabled Mashups: Empowering Both Business Owners and IT
Intel Whitepaper: Building a Real-World Model to Assess Virtualization Platforms
PDF: Intel Centrino Duo Processor Technology with Intel Core2 Duo Processor
Microsoft Article: Build and Run Virtual Machines with Hyper-V Server 2008
  Go Parallel Article: Q&A with a TBB Junkie
IBM Whitepaper: Innovative Collaboration to Advance Your Business
Internet.com eBook: Real Life Rails
IBM eBook: The Pros and Cons of Outsourcing
Internet.com eBook: Best Practices for Developing a Web Site
IBM CXO Whitepaper: The 2008 Global CEO Study "The Enterprise of the Future"
Avaya Article: Call Control XML in Action - A CCXML Auto Attendant
IBM CXO Whitepaper: Unlocking the DNA of the Adaptable Workforce--The Global Human Capital Study 2008
Adobe Acrobat Connect Pro: Web Conferencing and eLearning Whitepapers
Symantec Whitepaper: Comprehensive Backup and Recovery of VMware Virtual Infrastructure
MORE WHITEPAPERS, EBOOKS, AND ARTICLES