Search Perform an advanced search query SOFTPEDIA
 
SOFTPEDIA
Updated one minute ago
HomeSubmit a program for being reviewedAdvertise on our websiteGet help on surfing our websitesSend us your feedbackGet information about our XML/RSS backend and how to use itBrowse the news archiveVisit our discussion forumVizitati forumul in limba romana



KLIP
  1. HOME
  2. SCIENCE
  3. TECHNOLOGY
  4. WEBMASTER
  5. SECURITY
  6. MICROSOFT
  7. LINUX
  8. APPLE
  9. GAMES
  10. TELECOMS
  11. REVIEWS
  12. LIFE & STYLE
  13. EDITORIALS
  14. INTERVIEWS
  15. RSS
Welcome!
Hello, Guest

Login if you have a Softpedia.com account.

Otherwise, register for one.

PATCHES AND VULNERABILITIES

2 Year Old Critical Vulnerability Comes Back to Haunt XP SP3 RTM

- A patch is available

By: Marius Oiaga, Technology News Editor

The latest service pack for Windows XP, despite being just a standard release, is designed to also take the operating system to a new level of security. The minor evolution represented by the jump from SP2 to SP3 will not bulletproof Windows XP, but what it will do is provide all of the security patches released since late 2004 through Windows Update bundled with the service pack. And yet Windows XP Service Pack 3 RTM Build 5512 is still vulnerable to exploits targeting a security flaw approximately two years old, according to Microsoft.

"We re-released MS06-069 to add XP SP3 as an affected version", revealed Tami Gallupe, MSRC Release Manager. However, this time around, the Redmond company is not at fault. The label of Microsoft Security Bulletin MS06-069 reveals that this issue was patched as far back as 2006, on November 14 in fact. A couple of years ago Microsoft served a security update for vulnerabilities in Flash Player from Adobe that could allow an attacker to perform remote code execution on an operating system affected by the vulnerability, in the eventuality of a successful exploit.

The list of impacted platforms contains not only XP SP2 and SP3 but also Windows Vista (but not Vista SP1). "Vulnerable versions of Macromedia Flash Player from Adobe are redistributed with Microsoft Windows XP Service Pack 2, Microsoft Windows XP Service Pack 3, and Microsoft Windows XP Professional x64 Edition", Microsoft informed after it has updated the security bulletin.

Because the security vulnerability patched by MS06-069 targets a flaw in third party software, the Redmond company has not included the item among the updates in XP SP3 RTM. In this context, end users who perform clean installs of XP SP3 via slipstream integrated versions of the service pack are at risk from exploits unless they apply the patch that is already available. There are not changes in the binaries of the update for XP SP2 in comparison to those for XP SP3.

"Several remote code execution vulnerabilities exist in Macromedia Flash Player from Adobe because of the way that it handles Flash Animation (SWF) files. An attacker could exploit these vulnerabilities by constructing a specially crafted Flash Animation (SWF) file that could potentially allow remote code execution if a user visited a Web site containing the specially crafted SWF file. The specially crafted SWF file could also be sent as an e-mail attachment. A user would only be at risk if opening this e-mail attachment. An attacker who successfully exploited these vulnerabilities could take complete control of an affected system", reads the description of the vulnerability as provided by Microsoft.


MORE RELATED ARTICLES: Enable Vista-Native Network Access Protection on XP SP3 XP SP3 Download Still Live Despite Widespread Problems 9 Critical Errors that Will Prevent the Installation of XP SP3 RTM Build 5512 It All Comes Down to Going Either for XP SP3 or for Vista SP1 Download Windows XP SP3 RTM Network Installation Package Microsoft Makes Its Own Vista SP1 vs. XP SP2, Leaves XP SP3 Out Critical Security Patch for Windows XP Service Pack 3 Final Download Windows XP Service Pack 3 - ISO-9660 CD Image File New Version of Internet Explorer 7 Available for Windows XP SP3 RTM
 
Comments | Link here | Subscribe
Print | Send to friend
Today's News | Yesterday's News

Search:


14th May 2008, 10:25 GMT | Copyright (c) 2008 Softpedia | Contact:
Read by 889 user(s) | Rating: | 6 vote(s) so far | Cast your vote:
2 Year Old Critical Vulnerability Comes Back to Haunt XP SP3 RTM - USER OPINIONS




We are sorry, there are no opinions available for this article.






SHARE YOUR OPINION ABOUT 2 Year Old Critical Vulnerability Comes Back to Haunt XP SP3 RTM

Since you are not logged on, your comments will have to be approved before being displayed.
Click here to login, or register.
Your Name:
Your Email:
Type in the result:
Your Opinion:
 


DO YOU WANT TO CONTACT US?  

If you have some comments or you want to send us some information you can send us an email directly to .
You can use the form below for the same purpose.
Your full name: (at least 3 characters)
Your email address: (at least 5 characters)
Message subject: (at least 5 characters)
Message text:
(at least 10 characters)
Type in the result:
 
 



© 2001 - 2008 Softpedia. All rights reserved.
Softpedia™ and Softpedia™ logo are registered trademarks of SoftNews NET SRL.
Copyright Information | Privacy Policy | Terms of Use | Contact Softpedia | Update your software | Archive