Slashdot Mirror


Flurry of Security Patches

yggy writes "It's been a hectic day on the security patching front. Microsoft's bulletins for July include patches for three critical vulnerabilities on the same day that Mozilla releases new security updates for Firefox and Thunderbird. Not to be left behind, Apple fixed two Tiger flaws while Oracle issued a critical database server update." (See these separate stories on today's release of Firefox 1.0.5 and the 10.4.2 update from Apple, too.)

8 of 212 comments (clear)

  1. Tomorrow by mfloy · · Score: 5, Insightful

    So today we have a bunch of new patches, which means tomorrow we will have all the exploits being developed and released. The major problem with patches is they often are not installed by end users, and that is the bread and butter of zombie botnets.

    1. Re:Tomorrow by Parham · · Score: 5, Insightful

      Luckily Windows has tried to stop this from happening as much as possible by downloading the patches in the background, and then asking you to install, and bugging you to install until you do. What I'm actually waiting for is, seeing what NEW security problems these new security fixes make. This recent article in the games section comes to mind amongst other things.

    2. Re:Tomorrow by Tim+C · · Score: 3, Insightful

      More than that, Windows gently reminds you at appropriate times that you really ought to have patches download and install themselves automatically. ("At appropriate times" means on the Windows Update site, and in the Security Centre)

      Now, you may argue that that's a bad idea, you should always know what's being installed on your machine and what it might break, etc, and I'd agree. The flip side of that though is that anything that increases the likelihood of home users installing security updates has got to be a Good Thing.

      [It's been 4 minutes since you last successfully posted a comment

      Editors, can we *please* get this fixed?]

  2. Re:Hmm.....time to go to Windows Update..... by Kimos · · Score: 3, Insightful
    However, despite not updating my Windows install for months, I still have yet to be infected with one virus, spyware/adware program, or have my machine hacked. Maybe it has more to do with the fact that I browse the Internet with care, rather than update with every stupid patch M$ puts out ...
    I don't think it's fair to say that you're too smart to get viruses/malware like everything else, it's probably a few other factors that you take for granted. Using Firefox is one of them. You have the major Windows patches so that protects you from most of it right there. Think of the MSBLAST traffic that's still out there, meaning that each of those machines is still pre-SP2. Also, being behind a router/NAT/firewall helps (again, I'm assuming). A good number of zombie machines are the direct to DSL or cable modem kind of one computer households.
  3. Re:Firefox by Slashcrunch · · Score: 4, Insightful

    Anyone that claims open source is entirely free of bugs is dreaming and/or misinformed.

    The beautiful part is the speed at which critical bugs in OSS are corrected after being discovered.

  4. Re:But wait... by Caledai · · Score: 5, Insightful

    Nah - its not that Microsoft sucks because the release patches.

    Neither does OS suck because they release patches.

    Its because microsoft takes so long to release patches for certain vulnerabilities that have been documents - even up to half a year before..

    And that the continue to promote products that have been proven to be seriously flawed, and release new versions without those flaws fixed.

    There is a difference between releasing a product, and then patching it - and releasing a product knowing it needs patches before its released.

    I gotta admit - look how much testing the do on the patches they do release. Service Pack 2 anyone?

    --
    Although it can be funny, tell them to plug the power in.
  5. Re:Open source by bigman2003 · · Score: 3, Insightful

    Most of the exploits are written AFTER the patches come out. Most exploit writers just look at the patch, see what it fixes, and then figure out the vulnerability. So the patches don't really need to be released immediately. (This is the practical reality, of course there are others who find this plan to be horrible, but it works for me.)

    I really like this once a month patch cycle. I get an idea that maybe they plan the patches a little better, and test them more.

    Maybe EA should have done that with Battlefield 2, instead of trying to rush a patch out.

    --
    No reason to lie.
  6. Re:Open source by man_of_mr_e · · Score: 4, Insightful

    You think so? Check out the patch list for FF 1.05

    http://www.mozilla.org/projects/security/known-vul nerabilities.html#Firefox

    12 vulnerabilities in this patch, the oldest was created in APRIL! And it's marked as high severity.

    The newest we don't know, because Mozilla is keeping it hidden until July 20th, but if you take the Bugzilla report number, and add one to it you can get the bug that was created directly after it, and that was created in MAY!

    So yes, Mozilla DOES sit on critical bugs for months.