Linked by Thom Holwerda on Wed 12th Jul 2006 18:01 UTC, submitted by LogError
Microsoft "Microsoft alerted us this time about seven vulnerabilities of which five were rated critical and two important. There are vulnerabilities in the Server service, the DHCP Client service, Excel and Office that could allow remote code execution."
Order by: Score:
And the beat goes on...
by Flatline on Wed 12th Jul 2006 14:17 UTC
Flatline
Member since:
2006-03-06

The latest installment in the endless patch cycle. No matter what system you use, it seems like there is constant patching involved. Of course, I'd *rather* have them giving out the patches...it means they are actually fixing bugs and closing security holes; the alternative wouldn't be pretty.

Reply Score: 1

RE: And the beat goes on...
by raver31 on Wed 12th Jul 2006 19:09 UTC in reply to "And the beat goes on..."
raver31 Member since:
2005-07-06

No matter what system you use, it seems like there is constant patching involved.

Tell that to the millions of Win98 and WinME users out there

Reply Score: 3

RE[2]: And the beat goes on...
by CPUGuy on Wed 12th Jul 2006 19:36 UTC in reply to "RE: And the beat goes on..."
CPUGuy Member since:
2005-07-06

Care to point me to a Linux vendor that supports their OS for as long as Win98 and ME have been around?

Reply Score: 5

RE[3]: And the beat goes on...
by situation on Wed 12th Jul 2006 20:40 UTC in reply to "RE[2]: And the beat goes on..."
situation Member since:
2006-01-10

Slackware? It has had security patches since it's birth, which was before Win98.

"omg that doesn't count!!! I meant Red Hat and professional support!!11!!1"

Reply Score: 2

RE[4]: And the beat goes on...
by Ronald Vos on Wed 12th Jul 2006 21:06 UTC in reply to "RE[3]: And the beat goes on..."
Ronald Vos Member since:
2005-07-06

Slackware? It has had security patches since it's birth, which was before Win98.

"omg that doesn't count!!! I meant Red Hat and professional support!!11!!1"


Didn't Redhat backport a lot of patches to the 2.4 kernel even? ;)

Reply Score: 1

RE[3]: And the beat goes on...
by joelito_pr on Wed 12th Jul 2006 20:41 UTC in reply to "RE[2]: And the beat goes on..."
joelito_pr Member since:
2005-07-07

That's the beauty of it, that you don't need to rely on the vendor to get your system secured.

Reply Score: 2

RE[3]: And the beat goes on...
by Moulinneuf on Wed 12th Jul 2006 21:04 UTC in reply to "RE[2]: And the beat goes on..."
Moulinneuf Member since:
2005-07-06

All of them !

GNU/Linux is one OS , with many vendor and supporter.

Windows 98 stopped being supported in 2000 , Microsoft patched it until july 2006.

Windows ME never was really supported , I pitty the fool who got to buy it , it got patched until july 2006.

If you got the money and whant older version upgraded and patched , there are vendors who can do the job for you , but you are better served by the latest offerings.

Reply Score: 1

RE[2]: And the beat goes on...
by Flatline on Wed 12th Jul 2006 20:49 UTC in reply to "RE: And the beat goes on..."
Flatline Member since:
2006-03-06

OK...I'll amend it: no matter what (supported) system you use, it seems like there is constant patching involved.

Reply Score: 1

An tomorrow....
by Jedd on Wed 12th Jul 2006 18:30 UTC
Jedd
Member since:
2005-07-06

... there'll be 7 more vulnerabilities to pop up.

Reply Score: 1

Old news
by jcinacio on Wed 12th Jul 2006 19:11 UTC in reply to "An tomorrow...."
jcinacio Member since:
2006-03-12

I really can't see the point on these so-called news. MS has been patching vulnerabilities for years, and it looks as it will continue to do so for some more.


Now, it's time for me to update my Linux system...

Reply Score: 2

Give the evil people a chance
by SEJeff on Wed 12th Jul 2006 18:52 UTC
SEJeff
Member since:
2005-11-05

Seriously guys, stop bashing Microsoft. They are *really* trying to make Vista a secure product. If they weren't, they wouldn't be demoing it's security features at real hacker conventions. Let them release it and then flood them with angry comments once holes are found in their new security features. A good example would be alsr:
http://www.tuxedo-es.org/blog/2006/07/06/vista-probe-02-release/

Microsoft is trying to catch up (security wise) where Linux was about 3-5 years ago. Let them try and if they do a miserable job, you will know as you see reports of worms ravaging the net.

Note I am writing this from an Ubuntu desktop at work as a Unix/Linux systems admin...

Reply Score: 0

RE: Give the evil people a chance
by Flatline on Wed 12th Jul 2006 19:00 UTC in reply to "Give the evil people a chance"
Flatline Member since:
2006-03-06

I wasn't bashing them at all. Like I said, I'd rather see them patching than not. And yes, they'll still have holes in Vista...every OS has holes (though OpenBSD has done a pretty darn good job making their system secure).

Reply Score: 4

mkools Member since:
2005-10-11

Yeah OpenBSD is secure, but only the 'default install' is, what can you do with the default install?
Run a Web/Mailserver?

If I install a Windows box and strip al crap with nlite and only install sendmail and apache on it it is as much secure as OpenBSD is.

Reply Score: 1

SEJeff Member since:
2005-11-05

If I install a Windows box and strip al crap with nlite and only install sendmail and apache on it it is as much secure as OpenBSD is.
ALSR, PIE, W^X, SSP, TCP Window Randomization, swap encryption, etc... Those are all proactive security features that go into OpenBSD. They come at the price of making it run more slowly and more difficult to use but increase security.

Microsoft uses the reactive approach to security and would not even compare to OpenBSD in your scenario. If you really don't understand something, please don't speak like you do.

Reply Score: 1

RE: Give the evil people a chance
by Tom K on Wed 12th Jul 2006 19:32 UTC in reply to "Give the evil people a chance"
Tom K Member since:
2005-07-06

Where Linux was?

Don't make you show you a vulnerability listing of the Linux kernel dating back 3-5 years ... And the kernel is just one part of a full-out GNU/Linux system.

Reply Score: 2

Moulinneuf Member since:
2005-07-06

vulnerability listing is not the same as in use vulnerabilities , more people looking at the code means more vulnerability are found and test done on it.

Reply Score: 2

SEJeff Member since:
2005-11-05

Actually, more people looking at the code means code needs to be written to a higher standard before it is released. It also means that bugs are likely to be fixed much more quickly than with a proprietary solution.
http://www.prnewswire.com/cgi-bin/stories.pl?ACCT=104&STORY=/www/st...

Reply Score: 1

7 in one blow!
by umccullough on Wed 12th Jul 2006 21:56 UTC
umccullough
Member since:
2006-01-26

And as I read that, memories of the childhood story came back...

Yeah I know, horrible.

Reply Score: 1

Dog bites man...
by tomcat on Wed 12th Jul 2006 22:00 UTC
tomcat
Member since:
2006-01-06

News at 11...


*yawn*

Reply Score: 2

cyclops
Member since:
2006-03-12

I'm surprised by the apathy to these patches. I'm amazed that anyone would say look at Vista and say "don't be mean" they are really trying with security.

Having looked at the profit Microsoft make each year, and their control of the OS market; Number of employees etc, Security is generally not good enough, and pointing to the next OS and saying thats the silver bullet is nonsence. Its not out till at least 2007.

The reality is that any comparison can be drawn to Linux or even OS X should be an embarassment to Microsoft.

The reality is the article in question contains nothing other than Microsoft fixed some serious vunerabilities, and they damn well should.

Its not a good indication of how effective they are at finding, fixing, or even quality of code, but then again judging by the comments here who would care.

Reply Score: 2

detail please?
by dillee1 on Thu 13th Jul 2006 06:14 UTC
dillee1
Member since:
2005-08-10

any TEXT description about what those vulnerabilities realy is?

Reply Score: 1

RE: detail please?
by slashQuack on Thu 13th Jul 2006 15:21 UTC in reply to "detail please?"
slashQuack Member since:
2006-01-27

ahem,

These updates include an undocumented, secret method of snooping your hard disk to obtain list of MS and/or other installed software so that MS can shove its asset management software down your throat, force an enterprise agreement upon you, rape and pillage your company's bankroll, offer poorly coded products with endless patching and security updates and last but not least, fund the Bill and Melinda Gates foundation in order to further suppress Linux in developing countries.

Did I miss anything?

< and yes, i'm be facetious... >

Edited 2006-07-13 15:22

Reply Score: 1

Test Test Test
by slashQuack on Thu 13th Jul 2006 15:14 UTC
slashQuack
Member since:
2006-01-27

Oh, I am so glad that I actually test these patches before pushing them out. My XP desktop is now utterly useless. Start Menu and taskbar no longer work, can't connect to network resources, etc. etc. None of the articles on MS or Google corrected the problem. System Restore is useless too. Good luck fellas.

Reply Score: 1