Microsoft has released DirectX 9.0b enduser runtime via WindowsUpdate and the release fixes some security problems and performance improvements. Download here, bug fix for 9.0a, more information on both issues here and here, SDK here.
Why does this strike me as odd? How in the name of Woz does a multimedia API have a security flaw that can allow someone to compromise the computer? This is classic. Trustwortthy Computing, my arse.
…how come I don’t keep getting patches for OpenGL?
Everytime I fire up Return to Castle Wolfenstein Enemy Territory or Soldier Of Fortune II, I keep geting that sinking feeling like there should be a security patch…
Why does this strike me as odd? How in the name of Woz does a multimedia API have a security flaw that can allow someone to compromise the computer?
As the release stated, it’s an unchecked buffer in DirectShow that would allow someone to create a MIDI file that overflows the buffer and executes code. It doesn’t change the restrictions under which the MIDI file was run, but since some people are still running 98/Me, or are running NT/2k/XP/2k3 as an administrator all the time, there could still be a chance of a real problem.
It just shows that unchecked buffers can be a problem whether your app is something people expect to be dealing with security routinely or is just playing a music file…
whilst I would think that it will be rather modest, will this likely mean DX9 specific or general performance?
Fu***ing Microsucks
I guess the “b” stands for “beta”?
Why does this strike me as odd? How in the name of Woz does a multimedia API have a security flaw that can allow someone to compromise the computer? This is classic. Trustwortthy Computing, my arse.
Just peachy. I’ve not even installed 8.0 yet! [No room on hdd]
<g>
—
Michael
I got 300 more dance marks
http://www.scene.org/file.php?file=/demos/groups/farb-rausch/fr-025…
3dmark2003 is just too bit a download so I user this one instead, and besides it has cool music (hopefully not a .mid file 😉
…how come I don’t keep getting patches for OpenGL?
Everytime I fire up Return to Castle Wolfenstein Enemy Territory or Soldier Of Fortune II, I keep geting that sinking feeling like there should be a security patch…
Why does this strike me as odd? How in the name of Woz does a multimedia API have a security flaw that can allow someone to compromise the computer?
As the release stated, it’s an unchecked buffer in DirectShow that would allow someone to create a MIDI file that overflows the buffer and executes code. It doesn’t change the restrictions under which the MIDI file was run, but since some people are still running 98/Me, or are running NT/2k/XP/2k3 as an administrator all the time, there could still be a chance of a real problem.
It just shows that unchecked buffers can be a problem whether your app is something people expect to be dealing with security routinely or is just playing a music file…
So far, DirectX 9.0a is still up on their server, and has not been updated to host 9.0b yet.
Well, I found their redist package for DirectX 9.0b, and they thought they could hide it from me!:
http://download.microsoft.com/download/c/9/c/c9c8a1d4-7690-4c98-baf…
While its nice to know that the big M$ is looking
out for us with all these security updates I can’t
help but wonder how much of Direct X is actuallyu a
performasnce booster and how much is just cruft and
security ‘updates’ for those of us who don’t normally
update their windows…Will Direct X replace IE in
spoonfeeding us unwanted OS ‘improvements’ and ect?
While we’re on it, how much of these security problems
could be remeoved if IE weren’t an issue?