Stories
Slash Boxes
Comments

SoylentNews is people

posted by chromas on Monday April 09 2018, @06:12PM   Printer-friendly
from the (unsigned⠀int) dept.

https://www.theregister.co.uk/2018/04/04/microsoft_windows_defender_rar_bug/

A remote-code execution vulnerability in Windows Defender – a flaw that can be exploited by malicious .rar files to run malware on PCs – has been traced back to an open-source archiving tool Microsoft adopted for its own use.

[...] Apparently, Microsoft forked that version of unrar and incorporated the component into its operating system's antivirus engine. That forked code was then modified so that all signed integer variables were converted to unsigned variables, causing knock-on problems with mathematical comparisons. This in turn left the software vulnerable to memory corruption errors, which can crash the antivirus package or allow malicious code to potentially execute.


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 2) by lentilla on Tuesday April 10 2018, @06:50AM (3 children)

    by lentilla (1770) on Tuesday April 10 2018, @06:50AM (#664849)

    Now, that's exactly what I would have done when I didn't know what a term means - I would have looked it up and silently moved on.

    I would have thought everyone knew what "knock-on effect" meant, and today I learnt that not everybody did. That in itself is interesting. So now; not only did the person who posed the question learn the answer; I discovered that "knock-on" isn't a globally known term; and likely multiple others learnt a new term and its definition.

    I find this interesting about places like stackexchange. I see so many questions that I; personally; would be mortified to actually ask - those kind of questions that could be solved with ten minutes of research and reading. But I absolutely love reading those questions and answers. If it's a outstanding question "on my list", that's ten minutes I don't have to spend finding the answer for myself. Ironic that it is other people's laziness that gives me an opportunity for easier learning. Well, it's not laziness; per se; it's just a different style of information gathering. Whilst I would silently research, others simply ask that dumb question that's on the tip of their tongue. Boy am I ever so glad some people ask dumb questions - otherwise we'd all be sitting silently in the library, researching the same beginner question and never communicating with each other!

    Starting Score:    1  point
    Karma-Bonus Modifier   +1  

    Total Score:   2  
  • (Score: 2) by FatPhil on Tuesday April 10 2018, @01:29PM (2 children)

    by FatPhil (863) <reversethis-{if.fdsa} {ta} {tnelyos-cp}> on Tuesday April 10 2018, @01:29PM (#664931) Homepage
    It's been a phrase I've known forever, I'm surprised to hear that it's not international English.
    Another similar one that shocked me is "one-off", as in "the festival's a one-off event". It's bizarre saying things that seem to be so obvious in meaning, and having (US) Americans look at you as if you just slipped a foreign word into the sentence. The hardest thing is when you're finally asked to define it, and the best definition you can give for it is to just repeat it, because that's the obvious bloody term for the concept, argh!!1!

    Indeed. I'm also very glad that search engines are as powerful as they are nowadays (OK, google is, the rest are still rather '90s) such that you can type your dumb question in, and it will get mapped onto a similarly-but-differently worded more-or-less dumb question that's already been answered. In the old days, it used to be a matter of you having to work out exactly what question to ask, but nowadays, the search engine doesn't impose that burden so much.
    --
    Great minds discuss ideas; average minds discuss events; small minds discuss people; the smallest discuss themselves
    • (Score: 0) by Anonymous Coward on Tuesday April 10 2018, @03:17PM (1 child)

      by Anonymous Coward on Tuesday April 10 2018, @03:17PM (#664981)

      That's nothing. Brits get pissed when they get beer, while Americans get pissed when they don't get beer. ;-)

      • (Score: 2) by TheGratefulNet on Thursday April 12 2018, @04:15AM

        by TheGratefulNet (659) on Thursday April 12 2018, @04:15AM (#665746)

        ...we also drive on the parkway and park on the driveway.

        --
        "It is now safe to switch off your computer."