Slashdot Mirror


Microsoft Flubs Patch, Putting Users At Risk

An anonymous reader writes "Microsoft is rushing to fix a flaw introduced by the company's latest security update to Internet Explorer. From the article: 'The flaw, initially thought to only crash Internet Explorer, actually allows an attacker to run code on computers running Windows 2000 and Windows XP Service Pack 1 that have applied the August cumulative update to Internet Explorer 6 Service Pack 1, security firm eEye Digital Security asserted. The update, released on August 8, fixed eight security holes but also introduced a bug of its own, according to Marc Maiffret, chief hacking officer for the security firm, which notified Microsoft last week that the issue is exploitable.'"

2 of 209 comments (clear)

  1. Re:Closed source strikes again by baadger · · Score: 5, Informative

    The difference is the Ubuntu slip up was fixed within hours, the Microsoft slip up ..is still counting...

  2. Just Please... by moehoward · · Score: 5, Informative


    Please don't automatically reboot my machines again when the patch's patch is installed. I have the custom options in MS Update to allow me to control install/reboot for the updates. Well, it ignored that this week and rebooted 2 of my machines for me.

    Then, I noticed that The Register had a couple of articles this week about the same thing happening to others.

    Just who in the hell does MS think they are?

    Oh, and if the patch's patch's patch needs a reboot as well, don't do that too.

    Oh, and if.... nevermind.

    --
    "If you want to improve, be content to be thought foolish and stupid." - Epictetus