Vista SP2 Final Scheduled for April, Recently Discovered Vulnerability to be Tackled Then
According to recent reports, the release candidate of the Windows Vista Service Pack (SP2 RC) will be released in the second month of 2009, and the final version of the software will drop two months later. The good news is that with Vista SP2 we can finally enjoy a more stable Windows-based operating system; the bad news is that a recently discovered vulnerability in Vista that could allow an attacked to initiate a DoS (Denial of Service) attack will not be dealt with now, a fix will be issued with the release of Vista SP2.
Late October we were reporting that SP2 for the Windows Vista operating system will be released in June 2009; we are glad to see that Microsoft is pushing the release date forward by a couple of months. Looking back in time we will notice that Vista SP1 was released at the beginning of 2007, and that late last month we saw the release of a pre-Beta SP2. Also by looking to Microsoft history one will observe that all their operating systems (including XP) have become stable and worth working with only after the release of SP2. One of the reasons why Microsoft is releasing SP2 early is to convince the people that are still using XP to switch to Vista.
According to Secunia, a Danish company that specializes in tracking security vulnerabilities, there is a security problem in Windows Vista that when maliciously and locally exploited will allow the attacker to launch a DoS attack. “The vulnerability is caused due to the "CreateIpForwardEntry2()" function not properly limiting the length of the IP address prefix of the destination IP address passed via the "MIB_IPFORWARD_ROW2" structure. This can be exploited to cause a buffer overflow and e.g. crash a vulnerable system,” explains Secunia.
The good thing about this security issue is that it is rated “non-critical” and it can be successfully exploited only if the attacker is a member of the “Network Configuration Operators Group”. It is also worth mentioning that the problem only affects Vista users, not XP. The bad news is that Microsoft will not bother with an individual patch, it will address this issue alongside others with next year’s SP2.
Tags: Microsoft, Windows, Windows Vista
Late October we were reporting that SP2 for the Windows Vista operating system will be released in June 2009; we are glad to see that Microsoft is pushing the release date forward by a couple of months. Looking back in time we will notice that Vista SP1 was released at the beginning of 2007, and that late last month we saw the release of a pre-Beta SP2. Also by looking to Microsoft history one will observe that all their operating systems (including XP) have become stable and worth working with only after the release of SP2. One of the reasons why Microsoft is releasing SP2 early is to convince the people that are still using XP to switch to Vista.
Advertising
According to Secunia, a Danish company that specializes in tracking security vulnerabilities, there is a security problem in Windows Vista that when maliciously and locally exploited will allow the attacker to launch a DoS attack. “The vulnerability is caused due to the "CreateIpForwardEntry2()" function not properly limiting the length of the IP address prefix of the destination IP address passed via the "MIB_IPFORWARD_ROW2" structure. This can be exploited to cause a buffer overflow and e.g. crash a vulnerable system,” explains Secunia.
The good thing about this security issue is that it is rated “non-critical” and it can be successfully exploited only if the attacker is a member of the “Network Configuration Operators Group”. It is also worth mentioning that the problem only affects Vista users, not XP. The bad news is that Microsoft will not bother with an individual patch, it will address this issue alongside others with next year’s SP2.
Tags: Microsoft, Windows, Windows Vista
I Hope you LIKE this blog post! Thank you!
What do YOU have to say about this
blog comments powered by Disqus
Popular News
By George Norman on 10 Feb 2012
With the release of Wolfram|Alpha Pro, the team behind the popular computational knowledge engine took a very big step forwardBy George Norman on 10 Feb 2012
Microsoft has just announced that this February, as part of the Patch Tuesday program, it will roll out a grand total of 9 security bulletins to all customers all over the world.Related News
By George Norman on 08 Oct 2011
Communications Manager with Microsoft, Kristina Libby (pictured to the left), has recently made public a list of 10 ways you will know that when your child grows up, he or she will work for the Redmond-based software giantBy George Norman on 09 Dec 2011
As the proud owner of an Android-powered Galaxy S2, I have to say that there are plenty of fun and interesting apps out there to use. As large as the screen is on my Galaxy S2, I sometimes want something that’s biggerBy George Norman on 23 Dec 2011
Redmond-based software giant Microsoft has said goodbye to its keynote presentation and booth at the Consumer Electronics Show (CES), the technology trade show held each January in the Las Vegas Convention Center. By George Norman on 22 Nov 2011
If you’re thinking about getting a new smartphone, chances are that you’re considering getting and iPhone or an Android-powered device. There is a third alternative that most people forget about: you could get a Windows PhoneAdvertising
Hot Software Updates
Top Downloads
2.
Opera5.
Trillian8.
AIM9.
Skype10.
Ad-Aware12.
Nero13.
Google Earth14.
Picasa15.
Winamp16.
iTunes17.
RealPlayer18.
uTorrent19.
eMule20.
WinRAR21.
BitComet22.
WinZip23.
Shareaza24.
CCleaner25.
Recuva26.
Tweak UI27.
CuteFTP Home29.
Adobe Reader30.
NewsPiperBecome A Fan!
Link To Us!
Vista SP2 Final Scheduled for April, Recently Discovered Vulnerability to be Tackled Then
HTML Linking Code
HTML Linking Code





