Vulnerability affects processing of PNG files
Vulnerability affects processing of PNG files
R E L A T E D   C O N T E N T
ADVERTISEMENT

Virus warning hits Windows Media Player

Users urged to be careful when viewing PNG images

Robert Jaques, vnunet.com 11 Feb 2005
ADVERTISEMENT

Computer users have been warned to be on their guard when viewing images after the discovery of a vulnerability affecting the processing of PNG (Portable Network Graphic) files by popular applications including MSN Messenger and Windows Media Player.

The issue affects applications including Windows Media Player 9.0 (when running on Windows 2000, XP Service Pack 1 and Server 2003), Windows Messenger version 5.0 (standalone version that can be installed on all supported operating systems), and MSN Messenger 6.1 and 6.2.

The PNG format is used by these applications to view icons or any other kind of image. The flaw centres on an error in the processing of these types of files, and could allow arbitrary code to be run on vulnerable systems. A similar problem was discovered with Jpeg files in September last year.

Considering the widespread use of the affected applications, IT security firm Panda Software warned that it is "highly likely" that viruses will emerge to exploit the problem.

Luis Corrons, director of PandaLabs, said: "Every time a security problem is detected in a popular program, the creators of malicious code start trying to find an exploit as quickly as possible.

"Judging by past experience, it is clear that the time gap between the discovery of a vulnerability and the emergence of a virus that takes advantage of it is shortening. For this reason it is important to stay up-to-date on the latest releases for the programs you have on your computer."

Panda urged PC users to download the Microsoft patch that resolves this problem, which can be found here.

Microsoft released a dozen patches on 8 February to fix a range of vulnerabilities, some of which were rated 'critical'.

See also:

Mydoom.bb spreading in the wildSecurity experts raise risk assessment on Mydoom.bb  17 Feb 2005
Virus displays nationalist sloganMalicious code infects executable files  16 Feb 2005
Virus Throttle detects virus-like behaviourSecurity software promises to control spread of viruses across networks  14 Feb 2005
Jeffrey Lee Parson sent down for Blaster B wormUS gets tough on virus writers  31 Jan 2005
SecurityThe latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack.  15 Apr 2004

All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
C# Web Developer, Finance, London Financial Services Required: C#, ASP.NET, AJAX Fantastic opportunity not to be missed!! This is a great opportunity to work on a unique objectives that no other company is doing working ... more >
| JAM Recruitment
Senior Hardware Engineer Scotland/Edinburgh Communication Systems Permanent Position 40-45K+Benefits A leading organisation involved with the design and development of data acquisition systems and synthesis boards for a range of radar, signal intelligence and software radio ... more >
| JAM Recruitment
FPGA Engineer Defence/Safety Critical Buckinghamshire Permanent Position 45K+Benefits A leading UK defence organisation requires an experienced digital design engineer to strengthen its existing development team due to a number of long-term projects that have recently ... more >
| JAM Recruitment
DSP Engineer 3 Months Contract Hertfordshire £Excellent Rates£ This position requires you to have experience of measurement algorithms development for the generation and analysis of digital wireless communication standards including GSM, EDGE, UMTS, WLAN and ... more >
More job opportunities