SECURITY FIX: DirectX 8 on Win2000/ME/98 SE/98
Results 1 to 6 of 6

Thread: SECURITY FIX: DirectX 8 on Win2000/ME/98 SE/98

  1. #1
    Registered User TechZ's Avatar
    Join Date
    Apr 2003
    Location
    Bahrain, Middle East
    Posts
    7,525

    SECURITY FIX: DirectX 8 on Win2000/ME/98 SE/98

    DirectX consists of a set of low-level Application Programming Interfaces (APIs) used by Windows programs for multimedia support. Within DirectX, the DirectShow technology performs client-side audio and video sourcing, manipulation and rendering. There are two buffer overruns with identical effects in the function used by DirectShow to check parameters in a Musical Instrument Digital Interface (MIDI) file. A security vulnerability results because it would be possible for a malicious user to attempt to exploit these flaws and execute code in the security context of the logged on user.

    An attacker could seek to exploit this vulnerability by creating a specially crafted MIDI file designed to exploit this vulnerability and then host it on a Web site or on a network share, or send it via an HTML email. In the case where the file was hosted on a web site or network share, the user would need to open the specially crafted file. If the file was embedded in a page, the vulnerability could be exploited when a user visited the Web page. In the HTML E-mail case, the vulnerability could be exploited when a user opened or previewed the HTML e-mail. A successful attack could have the effect of either causing DirectShow, or an application making use of DirectShow, to fail, or causing an attacker's code to run on the user's computer in the security context of the user.


    Download: Security Fix for DirectX 8 on Windows 2000/ME/98 SE/98

  2. #2
    Registered User slgrieb's Avatar
    Join Date
    Feb 2003
    Posts
    4,103
    Uh, why not just update to DirectX 9.0c so in one swell foop you can fix all the old bugs and be exposed to all the latest ones?

  3. #3
    Registered User TechZ's Avatar
    Join Date
    Apr 2003
    Location
    Bahrain, Middle East
    Posts
    7,525
    As slgrieb pointed out, for those still using an older version of Dx, update:
    http://www.microsoft.com/windows/directx/default.aspx

  4. #4
    Registered User Luxman's Avatar
    Join Date
    Mar 2004
    Location
    Vancouver
    Posts
    70
    DirectX8-KBB19696-x86-ENU.exe

    Properties/Digital Signatures/Thursday, August 07, 2003 (!)

  5. #5
    Registered User TechZ's Avatar
    Join Date
    Apr 2003
    Location
    Bahrain, Middle East
    Posts
    7,525
    Date Published: 9/22/2005
    They mustve been testing :P

    or mabye its an updated version of an older fix?

  6. #6
    Intel Mod Platypus's Avatar
    Join Date
    Jan 2001
    Location
    Australia
    Posts
    5,783
    Quote Originally Posted by TechZ
    or mabye its an updated version of an older fix?
    Most likely. The DirectX buffer vulnerability has been around since 2003, but if the fix has been updated, it would also be made available for extended phase products, as the vulnerability is classified critical. Some people could still be using DX8 for compatability reasons.

Similar Threads

  1. Help with spyware
    By Trying in forum Spyware & Antivirus - Security
    Replies: 28
    Last Post: January 28th, 2006, 03:39 PM
  2. UPDATE: WinAmp 5.05 (Security bug fix)
    By TechZ in forum Other Software Applications
    Replies: 0
    Last Post: August 30th, 2004, 10:28 AM
  3. DirectX 9.0C, Please read carefully before downloading
    By TechZ in forum Other Software Applications
    Replies: 4
    Last Post: July 31st, 2004, 12:33 PM
  4. [RESOLVED] W2K SP2??
    By Bjorn in forum Windows NT/2000
    Replies: 3
    Last Post: February 17th, 2001, 12:58 PM
  5. [RESOLVED] DirectX 6.1/7.0 & MS Y2K Installation Problems
    By Jean-Paul Bulot in forum Windows 95/98/98SE/ME
    Replies: 2
    Last Post: October 25th, 1999, 04:17 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •