ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Microsoft issues another two patches

Published: 09 Jun 2004 08:40 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft released two security patches for its Windows operating systems on Tuesday, plugging holes in an online-gaming feature and a third-party program that the company includes with several applications.

One patch fixes a problem in the DirectPlay network gaming functionality of DirectX, which enables games that support the feature to offer head-to-head matchups over the Internet. The security issue could enable an attacker to disrupt the connection and crash the game.

The second patch solves a security problem with the Crystal Reports Web Viewer, a third-party product included with Visual Studio .Net 2003, Outlook 2003 with Business Contact Manager, and Microsoft Business Solutions CRM 1.2. The flaw could allow for a denial-of-service attack or give an attacker access to information on the computer.

The two flaws are ranked as "moderate," the software giant's second-lowest grade for security vulnerabilities.

"Even if it is not software that Microsoft has written, it is software that Microsoft has provided, so we are issuing a fix," said Stephen Toulouse, security program manager for the company.

The two software updates bring the total number of bulletins issued by Microsoft to 17 in 2004, though the actual number of vulnerabilities fixed by the patches is much higher.

Microsoft released patches for a score of flaws in mid-April, but the fixes did not prevent the Sasser computer worm, released to the Internet 17 days later, from spreading.

The latest flaws can't be used by attackers to gain control of computers, so they can't be used by a worm writer to create a Sasser-like program.

The network-gaming flaw only affects games that use Microsoft's free peer-to-peer gaming system rather than the client-server architecture used by many multiplayer games, such as the Quake and Unreal Tournament series. The flaw is present in Microsoft's consumer desktop operating systems -- including Windows 98, 98SE, ME, 2000, XP and XP 64-bit -- and also affects Windows Server 2003.

"The game could either crash or the UI (user interface) might become unresponsive," Toulouse said.

The Crystal Reports Web Viewer allows users to view and modify documents created with Business Objects' Crystal Reports application. The vulnerability in the viewer could allow an attacker to delete and modify files on the victim's system.

The software giant also used the monthly update cycle to revamp its security Web site by collecting its scheduled monthly updates in the same place and adding an RSS (Really Simple Syndication) feed of security bulletins to its site.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
66 out of 177 people found this useful


Full Talkback thread

1 comment

  1. More patches ..more patches My PC is beginning to... terry maloney

Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Crystal Reports/ SQL server Report Writer Required

Very short term contract in the West Midlands - I am currently looking for a Crystal Reports Developer to start a 3 - 5 days contract. The ideal ...

London - Crystal Reports/ SQL/ VB Senior Developer needed ASAP !!

London - Crystal Reports/ SQL/ VB Developer needed asap for a leading Investment Management company based in London ! The following skills are ...

C++ Software Developers - MFC and Gaming experience - Coventry

The main skills required revolve around C++ gaming knowledge, other desirable skills would be C++, MFC and mathematics. The company are constantly ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation