Stories
Slash Boxes
Comments

SoylentNews is people

posted by takyon on Saturday September 22 2018, @01:55AM   Printer-friendly
from the jet-drag dept.

Microsoft's Jet crash: Zero-day flaw drops after deadline passes:

The Zero Day Initiative has gone public with an unpatched remote-code execution bug in Microsoft's Jet database engine, after giving Redmond 120 days to fix it. The Windows giant did not address the security blunder in time, so now everyone knows about the flaw, and no official patch is available.

The bug, reported to Microsoft on May 8 with a 120-day deadline before full disclosure, was described on Thursday by ZDI, here. It was discovered by Lucas Leong of Trend Micro Security Research.

The bad news: it's a remote-code execution vulnerability, specifically, an out-of-bounds memory write. The good news is that an attacker can only trigger the bug by tricking the victim into opening a specially crafted Jet file, and any arbitrary malicious code smuggled in the document is executed only with the user's privileges (we've all made sure that users don't have admin privilege, right?) The booby-trapped Jet file can also be opened using JavaScript, so someone could be fooled into viewing a webpage that uses JS to open the file, causing the code to run if it's picked up by the database.

The other good news is that the Jet database engine is not terribly well deployed: it's mostly associated with Microsoft Access and Visual Basic. However, if you are using it, you probably will want to stop users from opening any maliciously rigged files.


Original Submission

This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
(1)
  • (Score: 0) by Anonymous Coward on Saturday September 22 2018, @02:11AM (18 children)

    by Anonymous Coward on Saturday September 22 2018, @02:11AM (#738444)

    It's time corporate america swtich to linux/bsd. MS got nothing to offer them.

    • (Score: 0) by Anonymous Coward on Saturday September 22 2018, @02:40AM (13 children)

      by Anonymous Coward on Saturday September 22 2018, @02:40AM (#738452)

      Wake up sleepyhead. Corporate globalists are making bank on Linux. The entire Internet of Things is built around embedded Linux systems which you have no control over. Your corporate overlords deny you the freedom to modify Linux in devices you own. Worry not about how they paid exactly zero cents for the free Linux they use to spy on you. Do not concern yourself when corporate interests had Linus fired from Linux. Keep giving money to your corporate masters. Profits are sky high ever since Linux morons like you created free Linux and lowered software costs to zero for evil corporations. You have only yourself to blame.

      • (Score: 1) by khallow on Saturday September 22 2018, @02:48AM (7 children)

        by khallow (3766) Subscriber Badge on Saturday September 22 2018, @02:48AM (#738455) Journal

        Profits are sky high ever since Linux morons like you created free Linux and lowered software costs to zero for evil corporations. You have only yourself to blame.

        Funny how that was supposed to bother us. Guess another troll fail.

        • (Score: -1, Troll) by Anonymous Coward on Saturday September 22 2018, @02:58AM (6 children)

          by Anonymous Coward on Saturday September 22 2018, @02:58AM (#738460)

          Corporate billionaires making billions by taking the hard work of volunteers who got paid nothing doesn't bother khallow. Khallow is the living embodiment of psychotic avarice. Another example of defective human garbage.

          • (Score: 2, Touché) by khallow on Saturday September 22 2018, @04:05AM (2 children)

            by khallow (3766) Subscriber Badge on Saturday September 22 2018, @04:05AM (#738477) Journal

            Corporate billionaires making billions by taking the hard work of volunteers who got paid nothing doesn't bother khallow.

            Yep.

            Khallow is the living embodiment of psychotic avarice.

            Nope.

            • (Score: -1, Troll) by Anonymous Coward on Saturday September 22 2018, @04:45PM (1 child)

              by Anonymous Coward on Saturday September 22 2018, @04:45PM (#738587)

              Yep. Khallow is a selfish megalomaniac who likes seeing the downtrodden get trampled by the rich and the powerful. Khallow desperately wants billionaire status for himself and trampling everyone else is his way to get there. Khallow is sick. Khallow needs to be put down.

              • (Score: 1) by khallow on Sunday September 23 2018, @04:06AM

                by khallow (3766) Subscriber Badge on Sunday September 23 2018, @04:06AM (#738761) Journal

                Khallow is a selfish megalomaniac who likes seeing the downtrodden get trampled by the rich and the powerful.

                No downtrodden or trampling in the scenario given. We're supposed to care because something freely given gets freely used by billionaires?

                Khallow desperately wants billionaire status for himself and trampling everyone else is his way to get there.

                That's why I post on SN. Lots of trampling opportunities here.

                Khallow is sick. Khallow needs to be put down.

                "We're sorry but your pet soylentil has contracted a terminal case of billionairitus. He'll keep biting ankles until someone gives him a billion dollars and that just isn't going to happen."

          • (Score: 5, Interesting) by MichaelDavidCrawford on Saturday September 22 2018, @09:16AM (2 children)

            by MichaelDavidCrawford (2339) Subscriber Badge <mdcrawford@gmail.com> on Saturday September 22 2018, @09:16AM (#738507) Homepage Journal

            I get psychotic all the time.

            The reason I'm a coder at all is that I can write good code even when I'm delusional.

            I realized that was the case back in 1988, when I was all alone in my building when the NAZIs started having Panzer maneuvers in the parking lot.

            Looked out the window... just an empty parking lot.

            Looked back at my terminal, NAZIs were in the parking lot again.

            But that night's code was damn good.

            --
            Yes I Have No Bananas. [gofundme.com]
            • (Score: -1, Troll) by Anonymous Coward on Saturday September 22 2018, @04:49PM (1 child)

              by Anonymous Coward on Saturday September 22 2018, @04:49PM (#738589)

              Considering your preferred method of marketing your skills is waxing quixotic and sucking cock until you land the gig, I have to wonder, don't your prospective bosses worry about how you might go psychotic and bite their dicks off?

      • (Score: 1, Insightful) by Anonymous Coward on Saturday September 22 2018, @02:58AM (4 children)

        by Anonymous Coward on Saturday September 22 2018, @02:58AM (#738461)

        These concerns were actually expressed by Richard Stallman and were the subject of GPLv3. Stallman was worried about Tivo like devices (now smartphones), that take away users freedom by denying the user the ability to install their own operating system or have any control over the software the device runs. Torvalds was very resoundingly opposed to GPLv3 especially since Linux is funded by Google et al.

        • (Score: 0) by Anonymous Coward on Saturday September 22 2018, @03:24AM (1 child)

          by Anonymous Coward on Saturday September 22 2018, @03:24AM (#738467)

          Richard Stallman began the GNU Project with the explicitly stated goal of lowering programmer salaries to the level of sales clerks. He very nearly is succeeding. On average he has succeeded already when the vast numbers of unpaid free software programmers are counted. There are yet some few millennial hipster douchebags who earn pay in the six figure range and are deluded enough to believe they deserve to get paid for coding work. This state of affairs is not economically sustainable and professional coder pay will be corrected to zero by the invisible hand of capitalism. On the subject of Mr Torvalds all I can say is I hope he enjoys his new career of selling coffee.

          • (Score: 0) by Anonymous Coward on Saturday September 22 2018, @06:09AM

            by Anonymous Coward on Saturday September 22 2018, @06:09AM (#738485)

            Interesting. Can I subscribe to your newsletter?

            Will he enjoy selling coffee? With $150m in the bank, he just may.

        • (Score: 2) by MichaelDavidCrawford on Saturday September 22 2018, @09:18AM (1 child)

          by MichaelDavidCrawford (2339) Subscriber Badge <mdcrawford@gmail.com> on Saturday September 22 2018, @09:18AM (#738508) Homepage Journal

          -loaders.

          Usually it's just a simple command in adb.

          That's how one does Android Platform Development - you just unlock your phone, roll a firmware image then upload it to your phone.

          --
          Yes I Have No Bananas. [gofundme.com]
          • (Score: 0) by Anonymous Coward on Saturday September 22 2018, @04:39PM

            by Anonymous Coward on Saturday September 22 2018, @04:39PM (#738584)

            IoT is more than just smartphones. Go to the electronics section of any big box store, Walmart, Target, Best Buy, pick one, and almost every product for sale is running Linux. Launch the web browser on a TV and check the user agent string and you'll see Linux mentioned. Buy a Wi-Fi router and look in the packaging for a full printed copy of the GPL.

            You don't have the freedoms granted to you by the GPL when you buy products containing Linux. Companies have the freedom to take Linux and sell it to you in a locked down black box which you are not allowed to modify.

            The free software movement in theory gives you the freedom to modify your software. In practice the only thing free software accomplishes is enriching billionaires who made their billions by taking free software for free and denying you your freedoms.

            By gifting labor to capitalists for free, free software is making the future much worse, not better.

    • (Score: 0) by Anonymous Coward on Saturday September 22 2018, @06:12AM

      by Anonymous Coward on Saturday September 22 2018, @06:12AM (#738487)

      Just in time when control of Linux is up for grabs.

    • (Score: 4, Interesting) by MichaelDavidCrawford on Saturday September 22 2018, @09:13AM (2 children)

      by MichaelDavidCrawford (2339) Subscriber Badge <mdcrawford@gmail.com> on Saturday September 22 2018, @09:13AM (#738506) Homepage Journal

      "Nobody can figure out how to copy a file."

      Not my words, but the founder and President of that vendor.

      Linux might actually be ready for the Desktop, but you're going to have to overcome decades of sloth such as a certain release of Slackware whose gEdit lost all the text that was not displayed in the window.

      That is, if you wrote a chapter of your Great American Novel then shrunk the window to just a few inches high, most of your chapter just vanished into the Ether.

      --
      Yes I Have No Bananas. [gofundme.com]
      • (Score: 2) by kazzie on Saturday September 22 2018, @01:12PM (1 child)

        by kazzie (5309) Subscriber Badge on Saturday September 22 2018, @01:12PM (#738533)

        a certain release of Slackware whose gEdit lost all the text that was not displayed in the window.

        Whenabouts was that? I've been dabling with Slackware for well over a decade and can't recall hearing of this.

  • (Score: 2) by Gaaark on Saturday September 22 2018, @03:27AM (3 children)

    by Gaaark (41) on Saturday September 22 2018, @03:27AM (#738469) Journal

    When will people stop being stupid?

    What will it take? Seriously.....what will it REALLY take to get people to stop being stupid?

    --
    --- Please remind me if I haven't been civil to you: I'm channeling MDC. ---Gaaark 2.0 ---
    • (Score: -1, Troll) by Anonymous Coward on Saturday September 22 2018, @03:29AM

      by Anonymous Coward on Saturday September 22 2018, @03:29AM (#738471)

      Unfortunately a bullet in the head is the only possible cure for khallow.

    • (Score: 2) by MostCynical on Saturday September 22 2018, @06:35AM

      by MostCynical (2589) on Saturday September 22 2018, @06:35AM (#738490) Journal

      When not-stupid is easier than stupid.

      Stupid is often lazy plus uninformed, but laziness feeds ignorant, so..

      Won't even happen when stupid causes death (already happened)

      --
      "I guess once you start doubting, there's no end to it." -Batou, Ghost in the Shell: Stand Alone Complex
    • (Score: 2) by Freeman on Monday September 24 2018, @04:44PM

      by Freeman (732) on Monday September 24 2018, @04:44PM (#739250) Journal

      I'm not stupid, or uniformed, I'm just stuck with an either / or situation and so far it's been me using Windows. They have definitely nearly pushed me out of the Microsoft camp entirely with the recent Win10 built-in spyware, though. All it would take is them announcing some subscription based model and I'm 100% out. The unfortunate part is that I hear VR on Linux isn't well supported. I don't have enough skin in the game to not dump it, if necessary though.

      Most of the reason why I don't have Linux on my current box is, because of ease of use. It would take more effort to switch everything over to Linux than I want to spend, right now. I have limited free time and don't want to take the effort to switch to Linux. Assuming, I knew that I would have a seamless transition and the few games I am currently playing ran well. I would make the switch. There's no guarantee that I wouldn't be stuck distro hopping only to find out that something, something, have to build something, because something. Sure, I can figure it out and maybe it would just work. I don't have tons of free time anymore. I have a wife and kid and they both need and want my attention. So, at the end of the day, I just want to relax and that doesn't involve switching graphic drivers, because it doesn't work on this game.

      --
      Joshua 1:9 "Be strong and of a good courage; be not afraid, neither be thou dismayed: for the Lord thy God is with thee"
  • (Score: 0) by Anonymous Coward on Saturday September 22 2018, @07:02AM

    by Anonymous Coward on Saturday September 22 2018, @07:02AM (#738491)

    says is all

  • (Score: 3, Interesting) by MichaelDavidCrawford on Saturday September 22 2018, @08:38AM (3 children)

    by MichaelDavidCrawford (2339) Subscriber Badge <mdcrawford@gmail.com> on Saturday September 22 2018, @08:38AM (#738501) Homepage Journal

    If it's used by Microsoft Access, then it is _exceedingly_ well deployed.

    This flaw could be quite a serious problem, potentially a national emergency.

    I'd rather not point out where all those Access installs are, but I'm going to drop a dime to a software vendor that's been building their product on Access for decades.

    --
    Yes I Have No Bananas. [gofundme.com]
    • (Score: 4, Interesting) by MichaelDavidCrawford on Saturday September 22 2018, @09:10AM

      by MichaelDavidCrawford (2339) Subscriber Badge <mdcrawford@gmail.com> on Saturday September 22 2018, @09:10AM (#738504) Homepage Journal

      Dime Dropped. The guy I emailed is generally good about his email.

      The software in question is quite cool as well as quite popular, but yes I was appalled when they explained it was built on top of Access.

      --
      Yes I Have No Bananas. [gofundme.com]
    • (Score: 4, Interesting) by digitalaudiorock on Saturday September 22 2018, @01:45PM

      by digitalaudiorock (688) on Saturday September 22 2018, @01:45PM (#738535) Journal

      As I recall, it was used in Diebold voting machines at least at one point.

    • (Score: 2, Informative) by Anonymous Coward on Saturday September 22 2018, @08:17PM

      by Anonymous Coward on Saturday September 22 2018, @08:17PM (#738640)

      Every version of Windows in modern use has the Jet DB engine included. MSJET*.DLL etc. So "not terribly well deployed" is absolutely false since it's only a part of practically every single 32/64-bit Windows machine that exists. In fact, I just confirmed by fishing through the CAB files that Windows 95 OSR2 (aka Win95B) has MSJT3032.DLL which is Jet 2.0, so yeah, it's literally deployed even on ancient Win95 machines.

(1)