amiga-news DEUTSCHE VERSION
.
Links| Forums| Comments| Report news
.
Chat| Polls| Newsticker| Archive
.


.
  Per page
Show titles only
.


Archiv 'New hardware and software products'


11.Nov.2001
Amiga Future


FreeCD: Toons, Genetic Species, and Racing
For the FreeCD series Patrick Henz has released three new CD-ROMs about the subjects 'Toons', 'Genetic Species', and 'Racing'.

They toon it again
Part two of this Amiga Toons series contains more than 100 issues of Sabrina Online, the adventures of Space Rat, caricatures by Thorsten Dudai, MPG cartoons, photos and games by Black Legend and Mutation Software, as well.

Genetic Species
Thanks to Marble Eyes now the 3D shooter 'Genetic Species' is available as a already installed FreeCD.

Racing
This CD contains the full versions of 'Wheelspin AGA' and 'Aerial Racers', many photos from Monaco, the Nürburgring and Zolder, many paper models, a Formula 1 database, as well as a Rocking-Tune.

To order the CDs follow the title link. (sd) (Translation: mj)

[News message: 11. Nov. 2001, 23:09] [Comments: 0]
[Send via e-mail]  [Print version]  [ASCII version]
10.Nov.2001
Christoph Gutjahr (ANF)


Serious security leak in MUI Internet programs? (update)
Following the title link you find an English written document that reveals a severe security leak in MUI programs.

Programs displaying text by using a MUI text object can be forced to execute Shell commands via active PIPE: devices with particular escape sequences. To say it clearly: It's theoretically possible to force for example YAM via a mail with specifically manipulated subject line to delete files on the computer of the receiving person.

It's not an error in MUI or AwnPIPE:/APIPE:, it should be the task of the programmers to filter such sequences before displaying text received via the Internet.

As first security measure it is recommended not to use affected programs anymore or not to mount AwnPIPE:/APIPE: devices during the boot process (remove all PIPE: icons from SYS:Devs/DosDrivers/).

Affected applicationen are for example YAM and StrICQ.

Not affected are the products of Vaporware, obviously the ESC sequences get already filtered here (it's not said from which program versions on).

Update:
Jens Langner, one of the lead programmers of YAM, points out that a hotfix is already in the works and that there'll soon be a 2.3 fix release removing this security leak in YAM.

Update II:
Hynek Schlawack and Sebastian Bauer will as soon as possible release a fix for SimpleMail.

Update III:
As the original text shows seems this exploit danger to be not given using PIPE: as this doesn't offer any start possibilities: "The standard AmigaOS PIPE: is not affected since it is incapable of executing commands". Therefore was the above text changed accordingly. (ps) (Translation: wk)

[News message: 10. Nov. 2001, 18:07] [Comments: 0]
[Send via e-mail]  [Print version]  [ASCII version]

09.Nov.2001
Christoph Gutjahr (ANF)


Skins for the OS3.9 audio CD player
A collection of new skins for the audio CD player of OS 3.9 can be found at the title link. (ps) (Translation: rh)

[News message: 09. Nov. 2001, 20:16] [Comments: 0]
[Send via e-mail]  [Print version]  [ASCII version]
1 453 900 ... <- 905 906 907 908 909 910 911 912 913 914 915 -> ... 920 933 952

.
Masthead | Privacy policy | Netiquette | Advertising | Contact
Copyright © 1998-2026 by amiga-news.de - all rights reserved.
.