Miscellanous Bugs
Home Up Search Trademarks how to use

For best results: this site requires that cookies be enabled for proper operation - see Legal Page for more info

 

Select Any of These

Translate this page      using FreeTranslation.com

Misc. Bugs

LAST UPDATED: Thursday, 14 February 2008 20:47:28 -0600

TOMB RAIDER SOUND FIX

Tomb Raider: The Last Revelation fans who use a Creative Labs SoundBlaster PCI 128 may experience problems with the game's music and sound effects when they use DirectX 7. Eidos Interactive (the maker of the popular game series) has developed a patch to fix this and other problems. You can download it from the Web site's tech support page at

http://www.eidosinteractive.com/help.html

Just click Patches in the list of site areas.

ADAPTEC EZ CD CREATOR CD COPY BUG

For reasons as yet undetermined, Adaptec's EZ CD Creator 4.0 contains a bug that affects the CD copy function. Many CD-R drives are making "coasters" (ruined or otherwise unusable CD-Rs) when a user tries to do a direct CD-to-CD copy at any speed. However, the light at the end of the tunnel is that the since-released version 4.01 restores the copy function for all supported drives at all speeds. For more information, browse to

http://cdr.adaptec.com

ALIENS VERSUS PREDATOR PATCH

Fox Interactive has a patch available for the retail version of Aliens Versus Predator that should enable game saves and solve other gameplay issues players have reported. Download it from

http://www.foxinteractive.com/products/products.html?/avp/sys_reqs.html

You will need to provide your name and e-mail address to download the patch.

ALPHA CENTAURI: ALIEN CROSSFIRE UPDATE FROM ELECTRONIC ARTS

Fans of Firaxis and Electronic Arts' popular game, Alpha Centauri, and the expansion pack, Alien Crossfire, should download a patch that features approximately 27 fixes and enhancements to the game, addressing many of the bugs found in the shipping version. Download the patch from the official game site at

http://www.AlienCrossfire.com

EA SPORTS NBA LIVE 99 PATCH

Patch 1.1 for EA Sports' NBA Live 99 fixes a bug that jumped a game straight to the fourth quarter if you went to Substitutions, then saved the game at half time. You can download the patch from the Electronic Arts Web site at

http://www.ea.com/tech_support/patch_detail.cfm?id=14106

EXTENDED VIDEO CARD SUPPORT FOR TIGER WOODS 99 PGA TOUR GOLF

EA Sports has developed a patch containing support for Matrox G200 and 3dfx Banshee video cards. The patch also eliminates shot delays when you're playing an Internet game. Log on to the Internet using the machine on which you play the game, then use the game's Upgrade Check to download and install the patch.

COREL WORDPERFECT 9 FOR WINDOWS--POSSESSED?

Scrolling to the 13th prompt in a WordPerfect 9 template makes the first 12 prompts in the dialog box disappear. Freaky, but a fix is available from Corel as part of Service Pack 2 at

http://www.corel.com/support/downloads/index.htm

MINOR BUGS EXIST IN MCAFEE OFFICE 2000

Users of McAfee Office 2000 suite or those who plan to purchase this all-in-one PC maintenance and problem-solving suite should know of several minor bugs that affect its performance. First of all, several users have complained of problems right off the bat with installation. It caused inexplicable crashes on more than a few systems, and caused other systems to report incorrect amounts of hard disk space. Furthermore, the WinGauge CPU meter consistently gave inaccurate readings, and the Crash Protector failed to catch an Internet Explorer 5.0 lockup. To date, McAfee has no plans to fix these bugs, most likely since the bugs do not affect all users. If you own the product, you may want to check out McAfee's Web site to watch for related news that might develop.

http://www.mcafee.com

SERVICE PACKS FOR COREL WORDPERFECT OFFICE 2000

Corel is currently working on several service packs containing a total of over 200 updates for the WordPerfect Office 2000 Suite. Fixes include but are not limited to: Thesaurus and Speller instabilities, Word 97 incompatibilities, RTF inconsistencies, spreadsheet formula oddities, address book export perplexities, and macro difficulties. To date, only Service Packs 1 and 2 are available. Service Pack 3 will be available in March (as will a Bug Tip reminder). Be advised that the two available packs total over 80MB. However, if downloading them is not feasible, Corel will send a CD-ROM containing the patches for US$10. To download, browse to the site below for Service Pack 1:

http://www.corel.com/support/ftpsite/pub/WordPerfect/wpwin/Office2000/2000_service_pack_1.htm

Then locate, register, and download Service Pack 2 from the Updates page at

http://www.corel.com/support/ftpsite/pub/wordperfect/wpwin/office2000/index.htm

SIERRA'S LORDS OF MAGIC PATCHED

Sierra has made a patch available for its Lords of Magic game. The patch fixes a number of unspecified bugs. Download it from Sierra's FTP site at

ftp://ftp2.sierra.com/pub/patches/pc/lom202.exe

APPLE PATCHES OS 9 AGAIN

Apple has released Open Transport 2.6 to fix various DHCP bugs and to prevent denial-of-service attacks. The fix also solves problems that have arisen since the introduction of Apple's previous patch, OT Tuner 1.0. Download the fix at

http://asu.info.apple.com/swupdates.nsf/artnum/n11560

SONY REPLACES COPIES OF GRAN TURISMO 2

Sony has offered to replace buggy copies of the PC-CDROM version of Gran Turismo 2. Some users experienced a loss of their saved data if they used a Machine Test too many times. Other users reported that it was impossible to achieve the full 100-percent score in the game. Meanwhile, graphical glitches and other minor problems were also reported. Users who think these bugs may be affecting them are urged to contact Sony's customer support (800/345-7669) and speak to a representative.

MACROMEDIA DRUMBEAT 2000 BUG

The error message "80004005 - Cannot open database '(unknown)'..." crops up in Drumbeat 2000 for Windows 95, 98, and NT when users access a Web site. A bug in the Microsoft MDAC 2.1 patch causes this problem; it may cause all Access databases to stop abruptly and refuse to open. Reboot the server. Macromedia says it plans to work around this problem on its DrumNote Web site by switching to SQL servers.

WESTWOOD'S BLADE RUNNER PATCHED

Westwood Studios has released two patches to fix problems that have arisen between its Blade Runner game and certain CD- and DVD-ROM
drives. If you are experiencing problems, download the respective patch from Westwood's FTP site at

For CD-ROM problems, go to

ftp://ftp.westwood.com/pub/bladerunner/updates/cdversion/BLADE.EXE

For DVD-ROM problems, check

ftp://ftp.westwood.com/pub/bladerunner/updates/dvdversion/BLADE.EXE

APPLE'S NEW AUDIO EXTENSION IS BUGGY

Apple has removed Audio Update 1.2 from its Web site after reports of an incompatibility with the Mac OS 9 networking software. The problem occurs when a PPP or TCP/IP connection is running and the system goes into Sleep mode or System Shutdown. If this happens and you have Audio Update 1.2 on your system, the OS will crash and you have to reboot.

Furthermore, some users have reported problems with installing Audio Update 1.2 over Audio Update 1.1. The application can't finish when installing over the previous update. Apple has developed Audio Update 1.3, which you should install instead. You can read more about the problem and solution at Apple's Web site:

http://til.info.apple.com/techinfo.nsf/artnum/n31167

AUTOCAD UPDATED

An update is available for the AutoCAD 3D Graphics System. It provides significant performance improvements for software and OpenGL-accelerated 3D in AutoCAD 2000, plus a few bug fixes. The 3D Graphics System Update modifies 3D graphics drivers and DLL files in Autodesk products that use the new Heidi-based 3D Graphics subsystem. These products include AutoCAD 2000, AutoCAD Mechanical 2000, Mechanical Desktop 4, AutoCAD Architectural Desktop 2, AutoCAD Map 2000, and AutoCAD LT 2000. Download the update from

http://www.autodesk.com/support/autocad/patch2000.htm

BALDUR'S GATE BUG FIXED

Fans of Interplay's game, Baldur's Gate, may want to download a patch that will fix a problem--an NPC spawning bug that occurs if you are VERY thorough in exploring every area in the game and its expansion pack, Tales of the Sword Coast. Download the patch from

http://www.bioware.com/download/bgmain2.zip

SONIC FOUNDRY VEGAS PRO 1.0 PATCHED

Some issues have come up regarding installation and registration of Sonic Foundry's Vegas Pro, the popular new hard-disk  audio multitracker. A patch in the form of a repair utility is available. Download the patch only if you are using version 1.0 and have received the following message after entering your serial number: "The Activation Code has no time left on it." Install the repair utility and reenter your serial number. For more information or to download the patch, browse to

http://www.sonicfoundry.com/Download/default.asp?DID=121

THE SIMS USERS WITH DVD

If you use a DVD drive in your system and play Maxis's The Sims, you may experience invalid page faults in iviaudio.ax.  patch is available to keep your Sim running smoothly. Download the patch from

http://www.thesims.com/us/downloads/ivi_fix.zip

Unzip the file and double-click the patch to install.

CORPORATETIME FOR THE WEB UNLIMITED LOG-IN ATTEMPTS

Steltor (formerly CS&T) CorporateTime for the Web is a calendar and schedule management tool with a Web interface. It does not limit the number of log-in attempts, even if invalid user names or passwords are entered. This allows a malicious user to use what is known as a "brute-force" attack to repeatedly attempt a log-in using a constantly changing series of user names and/or passwords. Using this attack, the user could conceivably harvest possible valid log-in names and passwords for later exploitation of the program. There are currently no fixes or workarounds for this bug. Concerned users are urged to contact Steltor for more information.

http://www.steltor.com/products/index.cfm?fuseaction=ctw

EIDOS SYDNEY 2000 AUDIO INCOMPATIBILITIES

System halts in Eidos Interactive's Sydney 2000 game have been attributed to incompatibilities in the included DirectX drivers. Users who are experiencing these problems are urged to contact their sound card manufacturer's Web site for a DirectX 7.0a-compatible driver. 

Reports indicate that included drivers are buggy on certain cards.

ETRUST IDS PROVIDES WEAK ENCRYPTION

A weak encryption scheme exists in the Computer Associates eTrust Intrusion Detection System password that authorizes users to view and configure the application's Registry settings. A local or remote user with access to the Registry and knowledge of the password's location could convert the encrypted password to plain text using simple techniques. Computer Associates maintains that administrative access to the machine is required to exploit this vulnerability. However, it has addressed the issue in the latest release. Browse to

http://www.ca.com/solutions/enterprise/etrust/intrusion_detection/support/maintenance.htm

ETRUST IDS VULNERABLE TO DOS ATTACKS

Computer Associates' eTrust Intrusion Detection System is susceptible to a DoS (Denial of Service) attack. If sent several discovery packets, each with a unique MAC address, the Intrusion Detection System will become unstable. This will put undue load on the CPU and you will have to restart the system. A fix is included in release 4, build 1.4.5. There are also patches available:

ftp://ftp.cai.com/pub/etrust/IntrusionDetection/hf_eID_14113.zip

To upgrade to the latest release of eTrust, go to

http://www.ca.com/solutions/enterprise/etrust/intrusion_detection/support/maintenance.htm

FINAL FANTASY VIII BUGS WINDOWS

According to Electronic Arts, players of its popular game, Final Fantasy VIII, have experienced discolored lines across the screen when playing the game in Windows 95 and 98. This only affects users who have GeForce video adapters. EA has released a patch, available for download from the Patches link on its home page at

http://www.ea.com

Just type Final Fantasy in the Game Title box to locate the patch.

ICQ 2000A TEMPORARY LINK ISSUE

When using Mirabilis's popular ICQ chat and e-mail utility, the user unknowingly creates a temporary Internet link in the default temp folder. This link remains in the folder even after the user signs out or closes ICQ. Another user can then open it, gaining full access to the ICQmail Web account. Until Mirabilis patches the issue (at this time there is no more information on a forthcoming upgrade or patch), users should manually delete the contents of the temp folder. The default location is c:\windows\temp, but it may differ on your system.

I-DRIVE VERSUS FILO IN DOS ATTACK

I-drive is a provider of Web-based storage where users can store downloaded files from the Internet. Filo is the application used to download files to the i-drive account. Filo's proxy server is susceptible to a buffer overflow attack. i-drive has fixed the problem with Filo 1.5.3. To install the upgrade, download the installer from

http://www.idrive.com/site/download/WinFiloInstaller.exe

PLANET CMS, NETSCAPE DIRECTORY SERVER PLAIN TEXT PASSWORD

Both iPlanet Certificate Management System and Netscape Directory Server store their administrative passwords in plain text format. Obviously, successful retrieval of an unencrypted password would give a malicious user administrative control over the application. Retrieval is possible because of a prior directory traversal bug. Not to fear, however--both bugs have been patched for both applications. Browse to

http://www.iplanet.com/downloads/patches/index.html

KERBEROS NULL-TERMINATION BUG

If you have MIT Kerberos4 KDC and Kerberos5 KDC enabled to serve Kerberos4 tickets, they can be vulnerable to a DoS (Denial of Service) attack. The code that services AUTH_MSG_KDC_REQUEST does not properly check for null termination. The MIT advisory and patches are available online. Browse to

http://web.mit.edu/kerberos/www/advisories/index.html

LINUX SPLITVT BUFFER OVERFLOW BUG

Splitvt, included with several LINUX distributions, contains a buffer overflow bug that could allow a malicious user to obtain root privileges. This bug affects splitvt 1.6.3 and earlier. Users are urged to upgrade to splitvt 1.6.4 to fix the problem.

MACROMEDIA 3 VERSUS MCAFEE

Users have reported an error when running Macromedia 3 in a Windows environment with McAfee Virus Scan. The "File is locked" error may not necessarily result from a bug (it depends on how you look at it), but there is a workaround for the problem:

- Launch McAfee Virus Scan.

- From the Tools menu, select Safe And Sound.

- Launch the Setup Wizard.

- Verify that the Delete A Backup Set option is checked.

- Select Next to eliminate the virtual drive.

MANDRAKE GNUPG INCORRECT KEY VALIDATION

GnuPG is a free software package that ships with Mandrake Linux distributions 7.0 and 7.1. GnuPG makes use of Public Key Infrastructure (PKI) to both encrypt and verify the validity of files and e-mail. A problem exists with GnuPG version 1.0.3 and prior. Files can be signed with one or more private keys to establish authenticity. The problem occurs when GnuPG tries to verify all the keys used to sign a package. In the event that a file is signed with multiple keys, one or move invalid keys will still be reported as valid by GnuPG. Mandrakesoft has patched the problem for Sparc and i586 systems.

Upgrade lists are available through Mandrake at

http://www.linux-mandrake.com/en/security/mdk71-updates.php3

Or browse the links below to the patch for your version and processor.

MandrakeSoft Linux Mandrake 7.1

i586:

ftp://ftp.linux.tucows.com/pub/distributions/Mandrake/Mandrake/updates/7.1/RPMS/gnupg-1.0.4-2mdk.i586.rpm

Sparc:

ftp://ftp.linux.tucows.com/pub/distributions/Mandrake/Mandrake/updates/7.1/SRPMS/gnupg-1.0.4-2mdk.src.rpm

MandrakeSoft Linux Mandrake 7.0

i586:

ftp://ftp.linux.tucows.com/pub/distributions/Mandrake/Mandrake/updates/7.0/RPMS/gnupg-1.0.4-2mdk.i586.rpm

Sparc:

ftp://ftp.linux.tucows.com/pub/distributions/Mandrake/Mandrake/updates/7.0/SRPMS/gnupg-1.0.4-2mdk.src.rpm

MCAFEE 4.5 VERSUS WINDOWS 9X

An incompatibility between Network Associates' McAfee VirusScan 4.5 and Windows 95/98 has been discovered. If a user has installed McAfee 4.5 and attempts to run either Microsoft Scandisk or Defrag, the system will lock up and require rebooting. The workaround is to disable VirusScan before running Scandisk or Defrag (remember to reenable it when finished). McAfee is aware of the problem and plans to release a fix as part of a 4.5 Service Pack, scheduled for an October 2000 release.

MIDNIGHT COMMANDER PERMISSIONS ELEVATION

Midnight Commander is a file management tool for Unix systems. It allows users to traverse their file system using a menu-console interface. There exists a vulnerability in the way Midnight Commander handles directories that may allow arbitrary commands to execute when maliciously created directories are opened. Attackers can embed commands into directory names after certain byte values; these commands will execute when a user opens them using Midnight Commander. Because the program doesn't list entire directory names if they are long, the commands can be hidden from the user if enough normal-looking characters precede them. If properly exploited, this bug can lead to an elevation of permissions for the attacker. There are currently no fixes for this vulnerability. Concerned users should request more information from the discussion group available at the following URL:

http://www.gnome.org/mc/

O'REILLY WEBSITE PRO WRITE ACCESS

By default, O'Reilly WebSite Pro creates default CGI folders, designated as world-readable. One of these folders contains uploader.exe, which a GET request could access and then use to upload any malicious file to the server. Though it's minor vulnerability in theory, it poses a significant risk. A quick fix is to modify the permissions for the CGI folders so they are not world-readable; or you can delete uploader.exe.

http://website.oreilly.com

PASSWD 1.2 PROVIDES WEAK ENCRYPTION

PassWd 1.2 is a password-management utility designed to store log-in information to various URLs. The log-in information--including user name, password, and link location--is stored in a file called pass.dat in the PassWD folder. The information is encrypted with a weak encoding algorithm that includes the key to decode any stored password. The same is true for PassWD across all Windows operating systems (95, 98, and NT4). There are technically no vendor-supplied patches for this problem. Users are urged to upgrade to PassWD 2000 and delete the old pass.dat file.

QUICKRES IN BEOS PERSONAL EDITION

The Quickres tool for the BeOS Personal Edition will hang when the user tries to either scroll the list of NetPenguin's resources or click the Type column. Be has acknowledged the bug and has stated that it will fix this problem in a future release of BeOS PE.

Unfortunately, Be hasn't given any more specifics. For more information on Be, browse to

http://www.be.com

SONICWALL DENIAL OF SERVICE

SonicWall provides Internet security solutions in the form of hardware. A bug exists in its SOHO model which could lead to a Denial of Service (Dos). When an unusually long user name is specified on the authentication page, SonicWall SOHO will stop responding and refuse any new connections. A restart of the service may be required to gain normal functionality. Furthermore, it has been verified that this vulnerability is exploitable via malformed HTTP requests as well. SonicWall has released a firmware upgrade to patch this issue. To receive the patch, contact SonicWall tech support at:

http://techsupport.sonicwall.com/swtech.html

WFTPD DIRECTORY TRAVERSAL BUG

Texas Imperial Software's Winsock FTPd is a popular FTP daemon for Windows. Unfortunately, it contains bugs that could allow a user to access the root directory of the drive containing the software. To its credit, FTPd allows the administrator to restrict users' access to only the home directory and below. However, a specially malformed cd command will allow a user to effectively "back out" of the home directory and gain access to any other file on the drive. This bug affects versions 3.0pro, 2.41RC14, and 2.41RC14pro. Texas Imperial Software has developed upgrades for all affected versions. Users can download them respectively from the following URLs:

http://www.wftpd.com/downloads/protr300.zip

http://www.wftpd.com/downloads/wftpd241.zip

http://www.wftpd.com/downloads/32wfd241.zip

For more information on Texas Imperial Software or Winsock FTPd, browse to:

http://www.wftpd.com

ADOBE FRAMEMAKER 6.0 HYPERTEXT COMMANDS

Several users have discovered that many hypertext commands don't work in PDF documents created in Adobe FrameMaker 6.0. The FrameMaker 6.0 Update for Windows fixes this and other problems. To download, browse to:

http://www.adobe.com/support/downloads/fmwin.htm

BORLAND/INPRISE INTERBASE BACKDOOR PASSWORD

Interbase is an open source relational database offered by Borland Inprise Corporation. It contains a backdoor user account and password. When accessed, this account will eliminate all implemented security, allowing full control of any database and contents within the database. This level of access will allow any function to be performed, including modification of objects, root access, and execution of arbitrary functions. The backdoor account is hard-coded in the database engine. Borland has patched the issue for versions 4.0, 5.0, and 6.0. Download the patch that corresponds to your version and platform:

http://www.borland.com/interbase/downloads/download.html

DREAMWEAVER 4 VERSUS BBEDIT

Macromedia Dreamweaver 4 and later may lock up after a user saves a document modified in BBEdit 6.0 and give the following error message: Dreamweaver: error sending kReloadFile Apple Event to BBEdit. Error #-1712

Trial version BBEdit users are urged to uninstall BBEdit and replace it with the trial version included on the Dreamweaver 4 CD-ROM. If the problem occurs when using the full BBEdit 6 version, users should download the 6.02 update from:

http://www.barebones.com/

QUARKEXPRESS KEYSTROKES ON MACINTOSH

Quark has determined that the Shift-F10 shortcut used to display master pages may not work in the Macintosh PowerPC version of QuarkXPress 4.11. Use Shift-F4 until a fix is released.

http://www.quark.com

Questions?

Just Check out some of our sponsors

Shop at BestPrices.Com!

web server downtime monitoring

HALO Computer Technology

COPYRIGHT 1998 - 2008 All names used are Trademarks of the respective companies

Home ] Up ]

Send mail to CompanyWebmaster  with questions or comments about this web site.
Copyright © 2007 HALO Computer Technology
Last modified: 02/14/08