Is there a security breech in Windows?

My aunt keeps calling us, telling us we HAVE to download some kind of patch for Windows, a jpeg patch, or some sort, or we’re going to completely crash. (I’m running Windows XP)

I don’t recall seeing anything on Microsoft’s webpage, about a “jpeg” patch.

Any information on this?
Thanks

It’s one of the standard updates that you get when you choose TOOL->WINDOWS UPDATE from IE and it scans for updates.

If you have ‘automatic updates’ turned on likely it’s already installed.

No, I did not have it on. Thanks, I’ll just go through updates.

My aunt made it sound like a major crisis.

Is the ocean wet? :smiley:

Some more info about the problem:

http://www.internetnews.com/security/article.php/3407961

http://www.wired.com/news/infostructure/0,1377,64959,00.html?tw=wn_tophead_8

More than you wanted to know about Windows’ newly-revealed jpeg parsing vulnerability, courtesy Slashdot.

I remember an e-mail hoax about malicious code hidden in image files from around eight or nine years ago. You know, silly-ha-ha to fun with the rubes, like the “Internet Cleaning Day” hoax.

“You can’t sneak executable code into a picture, that’s just ridiculous.”

:smack:

Guinastasia:

Nit note:

You knew that this is what breech means,right? It was just your way of adding humor to your thread title,right?

I’m so very sorry.I hope this hasn’t changed our non-existent relationship.

Ah, I see.

Okay, the second one, listed here:
http://www.microsoft.com/technet/security/bulletin/MS04-027.mspx

How do I figure out what version I use? I only had a trial version of Office, and I’m hopelessly confused.

(I hate this crap)

:smack:

Aw, it’s just not my day, is it? :o

Can you be more specific?

Meaning, the second link I posted, I’m not sure which patch to download.

If you’re not running Office currently on your machine, then you don’t need any of those. If you are running Office, then pick one which matches your version of office. If you’ve got “Automatic Updates” turned on, your system will download and install the correct one without you having to think about it.

Oh, and there’s been no reports of anyone getting hit with a virus hidden in a jpeg, as of yet, so there’s no need to panic. It’ll be at least a week before any show up, now that M$ has announced it.

Ah, thanks. We had a trial of Office, but it’s expired, and quite frankly, I prefer Word Pad.