Language Selection

English French German Italian Portuguese Spanish

M$ admits to Media Center hole

Filed under
Microsoft

Microsoft is developing a patch for a newly discovered security flaw in versions of Windows XP which poses a particular threat to computers running XP Media Center edition.

The flaw is in Windows Remote Desktop Services (RDS) and could allow a hacker to cause a computer to crash repeatedly by sending specially crafted data packets.

"Our investigation has determined that this is limited to a denial of service attack, so an attacker could not use this vulnerability to take complete control of a system," said Microsoft in a security advisory.

The user who discovered the vulnerability, security researcher Tom Ferris (aka 'badpack3t'), claims that he alerted Microsoft to the problem in May. The company told him that a patch would be released on 9 August as part of the usual monthly cycle.

"I have been working with Microsoft to get a patch out for this," said Ferris. "Microsoft told me the patch was going to be released in August. We know it's only a DoS [denial of service attack], which is kind of boring, so this is why we decided to report it to Microsoft."

Full Story.

More in Tux Machines

Debian 6.0 Long Term Support reaching end-of-life

The Debian Long Term Support (LTS) Team hereby announces that Debian 6.0 ("squeeze") support will reach its end-of-life on February 29, 2016, five years after its initial release on February 6, 2011. There will be no further security support for Debian 6.0. The LTS Team will prepare the transition to Debian 7 ("wheezy"), which is the current oldstable release. The LTS team will take over support from the Security Team on April 26, 2016. Read more

Tiny Core Linux 7.0 Up to Release Candidate Phase, Adds Linux Kernel 4.2.9

Robert Shingledecker announced the release and immediate availability for download and testing of the first RC (Release Candidate) build of the upcoming Tiny Core Linux 7.0 operating system. Read more

Mozilla Thunderbird 45.0 to Finally Bring GTK3 Integration for Linux, Sort Of

Earlier today, Mozilla has come out with the sixth point release of the stable 38.0 branch of its Thunderbird e-mail, news, and chat client, fixing a few minor issues reported by users since the 38.5.x series. Read more

OpenPHT 1.5.1 for Debian/sid

I have updated the openpht repository with builds of OpenPHT 1.5.1 for Debian/sid for both amd64 and i386 architecture. For those who have forgotten it, OpenPHT is the open source fork of Plex Home Theater that is used on RasPlex, see my last post concerning OpenPHT for details. Read more