找回密码
 注册账户
查看: 216|回复: 0

Security Fix for DirectX 8 on Win2000, ME, 98SE, and Win98 (KB819696)

[复制链接]
admin 发表于 2012-3-21 20:55:26 | 显示全部楼层 |阅读模式
This security patch fixes a MIDI file security issue in Windows 2000, Windows ME, Windows 98SE, and Windows 98 systems where DirectX has been updated to versions from 8.0 through 8.1b.
There are two buffer overruns with identical effects in the function used by DirectShow to check parameters in a Musical Instrument Digital Interface (MIDI) file. A security vulnerability results because it would be possible for a malicious user to attempt to exploit these flaws and execute code in the security context of the logged on user.

An attacker could seek to exploit this vulnerability by creating a specially crafted MIDI file designed to exploit this vulnerability and then host it on a Web site or on a network share, or send it via an HTML email. In the case where the file was hosted on a web site or network share, the user would need to open the specially crafted file. If the file was embedded in a page, the vulnerability could be exploited when a user visited the Web page. In the HTML E-mail case, the vulnerability could be exploited when a user opened or previewed the HTML e-mail. A successful attack could have the effect of either causing DirectShow, or an application making use of DirectShow, to fail, or causing an attacker’s code to run on the user’s computer in the security context of the user.

Download:
DirectX8-KB819696-x86-ENU.exe | MoreInfo…
您需要登录后才可以回帖 登录 | 注册账户

本版积分规则

存档|黑屋|手机|网络实验室 本站服务器由美国合租以及IDCLayer国际数据提供!!!

GMT+8, 2026-6-9 05:48 , Processed in 0.012593 second(s), 7 queries , Gzip On, Redis On.

Powered by Discuz! X3.5

© 2001-2025 Discuz! Team.

快速回复 返回顶部 返回列表