Quantcast

Blogs

Bugs and Fixes

Contributing Editor Stuart J. Johnston advises you on how to fix the latest problems affecting your operating system, your browser, your other software, and your hardware.

Subscribe to this blog

Bugs and Fixes |

Zap Zero-Day IE Attack Before It Zaps You

I feel some nostalgia as I write this column because, after penning Bugs & Fixes for eight and a half years--102 columns total--it's time for me to sign off. I've immensely enjoyed writing for you through all those years, and I'm grateful that PC World gave me the opportunity to do so.

I've always had two goals in mind: helping you ward off current threats, and providing useful information about how security holes and attacks on them work, so you'll be better prepared to deal with future problems. I hope that I have fulfilled at least the spirit of those goals. Now, as my dad back in Montana used to say: "nuff said."

Read more...

Bugs and Fixes |

Microsoft Defeats a Seven-Year-Old Bug

Microsoft recently released two new patches, one of which fixes a security hole that the company has been trying to plug since 2001. Amazingly, no one exploited the hole during those seven years.

Previous patches had mitigated the problem, so Microsoft rated its severity level as Important, the second-highest rating on the company's four-tier scale.

Read more...

Bugs and Fixes |

Worm Risk Spurs Critical Microsoft Patch

A scary security flaw that would allow malicious worms to infect one PC and then automatically jump to others prompted Microsoft to release a rare out-of-cycle patch in October. The glitch is critical for both 32-bit and 64-bit versions of Windows XP and Windows Server 2003, and for Windows Server 2000. Microsoft says that targeted attacks exploited the hole prior to the patch's release, and that "detailed exploit code" is currently available online.

This marks the first time since April 2007 that Microsoft has released a fix outside of its normal Patch Tuesday cycle; it wa s sparked by lessons learned from worm epidemics like Blaster and Slammer, which cost users billions of dollars to disinfect in 2003.

Read more...

Bugs and Fixes |

iTunes 8 to Vista: Give Me a B, an S, an OD

Apple's hugely popular devices may have become gold standards, but recent glitches in the new iTunes 8 bring an unwelcome blast from the past to Microsoft's latest operating system. Connect an iPhone or iPod, and some Vista PCs either crash with the dreaded Blue Screen of Death or spontaneously restart.

Apple says the problem can have more than one cause, and the company hasn't yet promised a patch. But if you're suffering from this unhappy pairing, Apple suggests a few options, including reinstalling iTunes 8, updating old device drivers, and checking for address conflicts be­­tween USB devices. For details, including which iPod models can have trouble (all iPhones do), head to Apple's support page.

Read more...

Bugs and Fixes |

Just What Color Is a Security Hole?

image

Illustration: Harry Campbell
Computer attacks in space are no longer the stuff of science fiction: Recently, laptops on the International Space Station turned out to have computer viruses. NASA believes that the malware--a password stealer that targets online games--may have infected the laptops via a USB thumb drive that one of the astronauts carried aboard. While it wasn't much of a threat, it just goes to show that the little buggers are everywhere.

One flaw in the largely forgotten Windows Image Color Management (ICM) system allows a villain to take over your PC if you view a tainted image displayed on a Web page or embedded in an Office document or e-mail. This is one of 19 holes for which Microsoft issued six "critical" patches; attackers could use them for their malicious creations (no booster rocket required). Though ICM (meant to ensure that colors display correctly on different devices) never caught on, the insecure code still resides in Windows 2000 Service Pack 4 (SP4) through XP SP3 and Windows Server 2003. Vista users are safe.

Read more...

Bugs and Fixes |

Firefox 3 Breaks Records, Then Itself

image

Illustration: Harry Campbell
Mozilla's Firefox 3, upon its recent release, set a new record for browser downloads in a single day: more than 8 million copies in just 24 hours. So it's no surprise that these days hackers are spending more time hunting for Firefox holes.

Mozilla issued updates to patch two security holes in both Firefox 2 and 3. The first fix blocks a malicious attack program from crashing Firefox by sending more pipe (the vertical line, or "|") characters than the browser can handle. The second vulnerability involves a similar overflow attack risk.

Read more...

Bugs and Fixes |

Ward Off an Ongoing PDF Zero-Day Attack

image

Illustration: Harry Campbell
These days, the makers of popular software may as well put big bull's-eyes on their products. When nearly everyone uses a particular program, a security hole in that application instantly creates a huge pool of targets for online crooks.

Here's an example: This month Adobe closed a hole in its Acrobat and Reader programs even as they were already under attack--a true zero-day scenario.

Read more...

Bugs and Fixes |

Microsoft's Jet Engine Sputters

image

Illustration: Harry Campbell
You won't hear it screaming through the skies or crashing on the tarmac, but a busted 'Jet' engine may be lurking in your Windows computer.

This Jet is a database engine in Windows XP, Vista, and 2000 for use by other programs that you might install, such as Office. It's normally behind the scenes, but a recent zero-day security bug--one that actively attacked before there was a fix--let the bad guys take over vulnerable PCs by targeting a Jet flaw. XP SP2 and Windows 2000 SP4 (and earlier) are at risk; Vista and XP SP3 are safe.

Read more...

Bugs and Fixes |

Install Windows XP SP3 Right

Still on Windows XP? Me too. So we'll both want to be sure to install Windows XP Service Pack 3 (SP3), which should be available from Microsoft by the time you read this.

SP3 will come via Automatic Updates, and like most service packs, it focuses on must-have bug fixes. Unlike SP2, which included big changes with the Windows Security Center, this third pack adds new functionality only for enterprise networks.

Read more...

Bugs and Fixes |

Hackers Focus Efforts on Firefox, Safari

Many people are switching from Internet Explorer to alternative browsers such as Firefox and Safari. Though that might make them feel more secure, the shift has also opened new doors for bad guys.

Case in point: We have no IE bugs to report this month, but both Firefox and Safari have been hit hard.

Read more...

Bugs and Fixes |

Vista Service Pack 1: 573 Fixes in Limbo

image

Illustration: Harry Campbell
Service Pack 1 for Windows Vista is (almost) ready for prime time. SP1 contains a whopping 573 bug fixes and patches that have accumulated since Vista first shipped in early 2007, plus some performance improvements. I advise you to get it--but only after the wrinkles are ironed out.

Microsoft says a few programs, including The New York Times Reader and Zone Alarm 7.1 security suite, can't start or work properly with Vista SP1. Most affected companies now have updates to fix the problem.

Read more...

Bugs and Fixes |

Rogue Packets Stalk Windows Vista, XP

Just in time for spring, Microsoft has been busy tending to a new swarm of bugs, including a critical hole in Windows Vista and XP that could expose you to an early-season bite without your doing anything other than being online.

In an attack, a cracker could broadcast rogue TCP/IP packets to a range of addresses on the Internet, possibly including your PC's. Sounds all too common, right? These rogue packets, however, are designed to trick their way past Windows' security and hijack your PC, making your machine part of a botnet for sending out spam--or worse, a self-copying worm.

Read more...

Latest News

  • Sony Unwraps Two New Media Players The Walkman has come a long way. On Wednesday Sony released two new slick looking Walkmans. These are definitely not your father's Walkman.
  • Cisco Gets Social With Entertainment OS Cisco on Wednesday announced the availability of Eos, or Entertainment Operating System, its hosted platform for media...
  • OQO Launches Handheld PC With OLED Touch Screen OQO launched a touch screen ultramobile PC with and OLED screen and 3G connectivity.
  • New Liquid Cools Hot Gaming PCs Hardcore Computer developed Core Coolant, a new liquid to cool its high end gaming PCs.
  • Panasonic HDTVs To Support Amazon Video on Demand Owners of new and recent Panasonic HDTVs will soon be able to stream movies rented from Amazon.com. Plus, Panasonic pushes 3D HDTV and its green initiatives, and shows the skinniest plasma to date.

Today's Special Offers

Name City
Address 1 State Zip
Address 2 E-mail (optional)