Vista SP2 Final Scheduled for April, Recently Discovered Vulnerability to be Tackled Then
Article by George Norman
On 25 Nov 2008
According to recent reports, the release candidate of the Windows Vista Service Pack (SP2 RC) will be released in the second month of 2009, and the final version of the software will drop two months later. The good news is that with Vista SP2 we can finally enjoy a more stable Windows-based operating system; the bad news is that a recently discovered vulnerability in Vista that could allow an attacked to initiate a DoS (Denial of Service) attack will not be dealt with now, a fix will be issued with the release of Vista SP2.

Late October we were reporting that SP2 for the Windows Vista operating system will be released in June 2009; we are glad to see that Microsoft is pushing the release date forward by a couple of months. Looking back in time we will notice that Vista SP1 was released at the beginning of 2007, and that late last month we saw the release of a pre-Beta SP2. Also by looking to Microsoft history one will observe that all their operating systems (including XP) have become stable and worth working with only after the release of SP2. One of the reasons why Microsoft is releasing SP2 early is to convince the people that are still using XP to switch to Vista.

Advertising

According to Secunia, a Danish company that specializes in tracking security vulnerabilities, there is a security problem in Windows Vista that when maliciously and locally exploited will allow the attacker to launch a DoS attack. “The vulnerability is caused due to the "CreateIpForwardEntry2()" function not properly limiting the length of the IP address prefix of the destination IP address passed via the "MIB_IPFORWARD_ROW2" structure. This can be exploited to cause a buffer overflow and e.g. crash a vulnerable system,” explains Secunia.

The good thing about this security issue is that it is rated “non-critical” and it can be successfully exploited only if the attacker is a member of the “Network Configuration Operators Group”. It is also worth mentioning that the problem only affects Vista users, not XP. The bad news is that Microsoft will not bother with an individual patch, it will address this issue alongside others with next year’s SP2.



Tags: Microsoft, Windows, Windows Vista
About the author: George Norman
George is a news editor.
You can follow him on Google+, Facebook or Twitter

I Hope you LIKE this blog post! Thank you!
What do YOU have to say about this
blog comments powered by Disqus
Popular News
By George Norman on 29 Mar 2017
What should you do when you have 5, 10, 15, or 30 minutes for a break? If you're drawing a blank and can't think of anything, come check out these 16 useful ideas.
By George Norman on 29 Mar 2017
The 8 games that are part of the Hooked on Multiplayer Humble Bundle come shy of a hundred dollars. But you can get them for a fraction of that cost, just $10.
Related News
By George Norman on 22 Mar 2017
Buying a new computer is no easy thing. It is a big investment and a big decision that you shouldn’t just rush into. That’s why you have to mull things over and ask yourself a few very important questions.
By George Norman on 07 Oct 2016
Right out of the box, BitTorrent offers a pretty enjoyable user experience. There’s room for improvement though, and all you have to do is turn off a few settings that are enabled by default.
By George Norman on 20 Mar 2017
Google Chrome, the web browser that has more than 1 billion users and loads more than 771 billion pages each month, is best known for its minimal interface, lightning fast speed, and wealth of settings. Hidden among them are...
By George Norman on 10 Nov 2016
Want to experience exciting tank battles on your PC or Mac and go against players who take to the battlefield on phones and tablets? Now you can!
Sponsored Links
Hot Software Updates
Top Downloads
Become A Fan!
Link To Us!
Vista SP2 Final Scheduled for April, Recently Discovered Vulnerability to be Tackled Then
HTML Linking Code