Slashdot Mirror


Microsoft Flip-Flops On URI Protocol Handing Flaw

a-twitter writes "After months of insisting there is nothing to patch, Microsoft has done a complete 180 on the URI protocol handling vulnerability, announcing in a security advisory that a Windows update will be released to revise URI handling code within ShellExecute() to be more strict. The MSRC blog explains the background and offers more details on this issue."

7 of 126 comments (clear)

  1. like a dervish, they are by User+956 · · Score: 4, Funny

    After months of insisting there is nothing to patch, Microsoft has done a complete 180 on the URI protocol handling vulnerability

    If it took them that many months, it sounds like they did a 1260.

    --
    The theory of relativity doesn't work right in Arkansas.
    1. Re:like a dervish, they are by ricebowl · · Score: 4, Funny

      If it took them that many months, it sounds like they did a 1260.

      And here I'm still saving to buy the 360...

      Sigh...

    2. Re:like a dervish, they are by ozmanjusri · · Score: 4, Funny

      Why don't you just twist a red glow-stick into a ring and glue it to the front of a cereal box? It'll work as well as most 360s do...

      --
      "I've got more toys than Teruhisa Kitahara."
    3. Re:like a dervish, they are by rk076200 · · Score: 2, Funny

      Microsoft has finally accepted responsibility for its role in a security weakness that allows malicious websites to run harmful code on an end user's machine.

    4. Re:like a dervish, they are by ricebowl · · Score: 2, Funny

      Why don't you just twist a red glow-stick into a ring and glue it to the front of a cereal box? It'll work as well as most 360s do...

      True enough, but will my glow-stick and cereal box be repaired under an extended warranty when it inevitably falls apart, or I add milk to the contents?

      I don't think Mr. Kelloggs will be forthcoming...

  2. The "New" Microsoft by Propaganda13 · · Score: 2, Funny

    After being criticized about security, Microsoft has taken additional steps to shorten the time between when they advise a customer of a vulnerability and when it is fixed. Ballmer stated "This is a win for both the customer and Microsoft."

  3. Re:Good. by Cassius+Corodes · · Score: 3, Funny

    Me. I'm gonna get a week's vacation docked.

    --
    Control is an illusion, order our comforting lie. From chaos, through chaos, into chaos we fly