Microsoft fear over zlib flaw

Just how much open source code does it use?

Written by Nick Farrell

Microsoft fears that it might be affected by the same security flaw that could leave Linux systems vulnerable. The company has confirmed that the zlib software-compression library flaw could affect Office, Explorer, DirectX, Messenger, Windows XP and Front Page.

The applications contain code borrowed from the Linux compression library, making them vulnerable to a similar attack.

A Microsoft spokesman said it was not a forgone conclusion that any applications would be hit by the bug, but its security teams were investigating the situation.

The zlib library is used in almost every Linux and Unix system, and the so-called "double free" flaw in the library which was recently discovered may leave it open to attack.

The open-source compression project, Gzip, has identified more than 600 applications which use the zlib code, including some from Microsoft.

The fact that Redmond is investigating the problem has confirmed how much open sourced based code is within the company's products, according to analysts.

While Microsoft has never denied that it used open-source software, it forbids its programmers from using GNU General Public Licence code, which could force it to publish its own source code.

Tags:

Further reading

Compression bug puts Linux at risk

Open source distributors rush to release advisories   More...

Related articles

Debian flaw exposes communications breakdown

A wake up call for open source developers, Gartner warns   More...

Mozilla patches cross-browser Firefox flaw

Fix does not cover Internet Explorer problem   More...

Attack code targets unpatched Adobe Reader flaw

Time running out for Adobe to patch 'critical' vulnerability   More...

Security flaw hits MSN Messenger

Vulnerability puts users at risk of arbitrary code execution   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

04 Jul 2008

5.51 MBPodcast Special: Views from the Valley More...

03 Jul 2008

3.46 MBGreen grid computing, Trojans stop play and location-based services More...

02 Jul 2008

3.2 MBOnline TV, SME security and flexible laptops More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Online pornography

US rebate cheques spent on porn

Economic stimulus package works wonders   More...

Louis Vuitton

UK online fake goods market worth £800m

Legal experts warn of dramatic rise in 'e-fencing'   More...

Advertisement

Fibre-optics

New fibre-optic connections overtake cable

Broadband first-timers choosing fibre where possible   More...

Stars and Stripes

Cyber-crooks celebrate Independence Day

Security firms warn users to take extra care   More...

Advertisement