Slashdot Mirror


Microsoft Issues Five New Security Warnings

smelroy writes "Microsoft on Wednesday issued security bulletins for five new software vulnerabilities, including a flaw in Visual Basic for Applications that the company rated as critical. The company has posted patches for each of the flaws on its Web site. Four of the problems affect Microsoft's Office desktop software. You can read the story here and the security bulletins here."

16 of 576 comments (clear)

  1. deja vu by Anonymous Coward · · Score: 5, Funny

    i'm having this funny feeling of deja vu...

    1. Re:deja vu by Winterblink · · Score: 5, Funny

      *draws dual 9mms* It's a glitch in the Matrix. It happens when they patch something.

      --
      "I'm a leaf on the wind. Watch how I soar."
      -Hoban Washburn
    2. Re:deja vu by Anonymous Coward · · Score: 5, Funny

      Re:deja vu (Score:0)
      by Anonymous Coward on Thursday September 04, @10:11AM (#6868436)
      Could this be a glitch in the Matrix?

      Re:deja vu (Score:2)
      by Winterblink (575267) on Thursday September 04, @10:11AM (#6868444)
      *draws dual 9mms* It's a glitch in the Matrix. It happens when they patch something.

      Two identical posts at the exact same time. Now that *has* to be a glitch in the Matrix!

    3. Re:deja vu by RLW · · Score: 5, Funny

      documentary style music.
      Voice over:
      It's the wheel of glitches.

      Location: M$aFT glitch preserve.

      M$aFT Tour Guide: The life cycle of the glitch is an often fast and furrious one, many only living for a few short days upto a few months typically. Although on some low exposure less used systems they may obtain a Methuselahn life span of a several years.
      slight pause
      Tour Guide Continues: Here at the M$aFT glitch preserve we try to breed and raise our glitches for survival in the wild.

      Interupting Guide Tour member: Why do you breed and raise glitchtes anyway? Aren't there enough bugs in the wild already. I mean ...

      Cutting off the Tour member Tour Guide: They are glitches, not bugs. As far as the number of glitches in the wild each glitch performs important ecological functions. There are some that encourage users to upgrade their Office packages, there are others that spark the need to upgrade development IDEs and there are others still that motivate upgrades to new versions of our glitch preserve, uh, I mean OS.

    4. Re:deja vu by MarkGriz · · Score: 5, Funny

      Linus, I need an exit... fast!

      --
      Beauty is in the eye of the beerholder.
  2. critical VBA flaw by b17bmbr · · Score: 5, Insightful

    wouldn't ANY vba flaw be critical. if i recall correctly, through vba, you can manipulate the entire file system. while it doesn't give you low level access, it has access to every COM object on your system. in fact, weren't the code red and i love you virii (and many others) written in VBA. VBA seems to be such a big reason that businesses can't move away from windows/office. to me, it seems like a reason TO move away from office.

    --
    My problem? I was perfectly gruntled, until some numbnuts came by and dissed me.
    1. Re:critical VBA flaw by mforbes · · Score: 5, Insightful

      OpenOffice and StarOffice also having built-in scripting languages. Perhaps the risks of buffer overruns aren't as common under those (I don't know, since I lack much experience with those scripting languages), but in all fairness to MS, if OpenOffice were the leading suite & de facto standard, it would also see many attacks. The problem in this case isn't that the flaw exists-- patches are easy enough to apply. It's that with the near-monopoly MS has over hundreds of millions of users, you can always guarantee some large subset of users won't have the patches installed, and thus will be vulnerable to attack.

      --

      Allegedly real newspaper headline from 1998:
      Man Struck by Lightning Faces Battery Charge

  3. Sigh... it seems a day doesn't go by by winkydink · · Score: 5, Funny

    ...without either e-mail from RedHat about a bug or news from MS about one. Lucky me, today I have both.

    --

    "I'd rather be a lightning rod than a seismometer." -Ken Kesey

  4. Microsoft Issues Five New Security Warnings by Anonymous Coward · · Score: 5, Funny



    1.SuSE

    2.Red Hat

    3.Mandrake

    4.Debian

    5.Gentoo

  5. Snapshot Viewer affected? by Karl+Cocknozzle · · Score: 5, Interesting

    Crap! That means I have to touch every machine in the enterprise--again! Just two weeks after "touching 'em all" (not in the baseball sense) from the last round of worm patches.

    How I long for the old days of Novell... Ah...take me away!

    --
    Who did what now?
  6. Re:what % of Windows is patches? by n3rd · · Score: 5, Insightful

    And how long until the entire operating system, and all the Microsoft applications, are all just patches?

    Interesting? Come on.

    Linux was released. Then patched. Then patched again. And again until it became what it is today.

    Apache web server anyone?

  7. Latest Debian gnu/Linux seccurity warnings! by Anonymous Coward · · Score: 5, Insightful

    [29 Aug 2003] DSA-375 node - buffer overflow, format string
    [26 Aug 2003] DSA-374 libpam-smb - buffer overflow
    [26 Aug 2003] DSA-344 unzip - directory traversal (new revision)
    [18 Aug 2003] DSA-364 man-db - buffer overflows, arbitrary command execution (new revision)
    [16 Aug 2003] DSA-373 autorespond - buffer overflow
    [16 Aug 2003] DSA-372 netris - buffer overflow
    [13 Aug 2003] DSA-358 linux-kernel-2.4.18 - several vulnerabilities (new revision)
    [11 Aug 2003] DSA-371 perl - cross-site scripting
    [09 Aug 2003] DSA-361 kdelibs, kdelibs-crypto - several vulnerabilities (new revision)
    [08 Aug 2003] DSA-370 pam-pgsql - format string
    [08 Aug 2003] DSA-369 zblast - buffer overflow
    [08 Aug 2003] DSA-368 xpcd - buffer overflow
    [08 Aug 2003] DSA-367 xtokkaetama - buffer overflow

    Stop calling the kettle black! Fix your own problems. This stuff wouldn't happen if Debian didn't use out of date software, as most of the flaws mentioned were fixed in the new versions!

  8. Office Updates EXTREMELY Frustrating by syntap · · Score: 5, Insightful

    I'm in a mixed environment where we have some Dells that came with Small Business Edition (either SR1 or original), and other users who needed Access that we purchased Office 2000 Pro for. Because Microsoft requires the original CD, it really adds to the burden of updating because you have to figure out which friggin' disc to use on each individual station. If they would just let us run the damn patch without the CD verification it would be easier.

    Plus, their order of updates is fux0r3d. They have the spell checker update listed as more recent than SP2, but when I run it I get an error message that the update only runs on SP1 .

    It's bad enough to need so many patches, but there are many basic things like the above that Microsoft could easily improve.

  9. This is the origin of the apache servers name... by evil_one666 · · Score: 5, Interesting
    http://www.apache.org/history/timeline.html

    Brian Behlendorf started collecting patches to be applied to the last version of NCSA. The initial versions of Apache are available primarily as a series of patches. Hence, initially, the name Apache, as it was "a patchy server". At least, so the legend goes.
  10. And Office Update process is broken. by Angostura · · Score: 5, Insightful
    a couple of points on this.

    While I've just about managed to educate friends and familly about the need to run Windows Update, WU does not in itself warn of critical security issues - you have to remember to visit Office Update manually... and who is going to do that? No one, in my experience.

    but it gets better - The Office Security updates require you to insert the original CD. This seems a mighty strange move, and not terribly useful for me since the CD is several thousand miles away locked up in a cupboard on the other side of the Atlantic.

    Can anyone explain the warped logic here? I could understand it if the new patches enabled new functionality? but these are security patches.

  11. Comparing Red Hat updates to MS.. by saintjab · · Score: 5, Interesting

    I'm sure this will get modded down, or ignored by the moderators all together, as off topic; but I feel it's a good camparison. I have two, relatively similar, workstations. One running Red Hat 9 and the other WinXP. I use RH Up2Date on the Linux bawx and Windows Update on the XP machine religiously. The observation that I have made are pretty amazing. Microsoft releases roughly 4 patches for every 1 that RH releases. The RH packages, other than kernel updates, do not require any reboots; where most of the MS ones do. I've not had a single occurrance of an adverse effect on my Linux machine from any patches, where I have had a miriad of issues with the XP/Office updates (insert CD, permissions issues, BSODs, etc). I'm not at all trying to scream the virtues of Linux and downplay MS, but there are real issues. Not to even mention never having adware, spyware, etc. installed on my RH machine without my knowledge. I'm extremely carefull with all of my machines and I stilled managed to get some IE search bar added to my browser. I removed it quickly with Spybot search and destroy, but it still happened. I think MS needs to take a step back from the cash register and seriously evealuate their tactics and practice where desktops are conncered. That is, if they ever want their update service to be even close to as effective as RH. But thats just my two cents and I'm sure there are a line of people out there to tell me I'm wrong and/or full of crap; but these are real world observations from someone who is completely OS neutral. ..jab

    --
    "Reality is a crutch for people who can't handle drugs" - George Bernard Shaw (1856 - 1950)