Microsoft
Jpeg security flaws revealed
R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Microsoft releases critical security patch

Jpeg files could be used to spread viruses

Daniel Thomas, Computing 15 Sep 2004
ADVERTISEMENT

Microsoft has found two new security flaws in its software, including a critical hole that could spread viruses using Jpeg graphics.

Buffer overflow problems when processing the graphics files means Microsoft Windows, Office and developer tools could all be affected, including specific applications such as Internet Explorer, Outlook and Word.

The company has released an urgent security patch to prevent the flaw spreading in the wild, but says to date it has seen no attacks resulting from it.

Mikko Hyppönen, director of antivirus research at F-Secure, told Computing that the flaw is one of the biggest risks he has seen in previous months and advised users to patch immediately.

'All you need to do is access a web site using a vulnerable router or open an email containing a JPEG and you could be compromised,' said Hyppönen.

'But when it does appear it's unlikely to spread in minutes, like the Sasser or Blaster worms, because it involves human interaction,' he says.

'It will fall between network and email worms in terms of severity.'

Microsoft has also issued a patch for its WordPerfect Converter, which is present in certain Microsoft Office programmes.

Security Update for JPEG Processing (GDI+)

WordPerfect Converter Security Update

What do you think? Email feedback@computing.co.uk

If you want to be first with the news, visit Computing every day.

See also:

Vulnerability affects processing of PNG filesUsers urged to be careful when viewing PNG images  11 Feb 2005
Mobile devices the 'new frontier' for virusesVirus writers target handhelds, mobiles ... and your car  10 Feb 2005

All Bugs & Fixes

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Newcastle upon Tyne, United Kingdom | NCFE
Information Services Manager - £37,626 - £50,633 - Newcastle Upon Tyne   Information Services Manager, (IT Manager) Newcastle Upon Tyne, Times Top 100 company, City Centre Location.  We're looking for an experienced IT Manager/professional who ... more >
United Kingdom | Advent Computer Training
Are you stuck in a dead end job? Do you want to take control of your salary, life and career? Advent IT and computer training offers advanced, professional training and helps you find the right ... more >
United Kingdom | Advent Computer Training
Are you stuck in a dead end job? Do you want to take control of your salary, life and career? Advent IT and computer training offers advanced, professional training and helps you find the right ... more >
United Kingdom | ESRC
Web/Project Manager - £33,118 to £35,694 + Benefits Cutting-edge research is our business. You'll give us the cutting-edge web technologies to match. The Economic and Social Research Council is the UK's leading research agency for ... more >
More job opportunities