Re: Microsoft criticized for silent patches

Re: Microsoft criticized for silent patches

Secure Home | Search | About
 General Computer Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Re: Microsoft criticized for silent patches Michael D. Ober 04-21-2006
Posted by Michael D. Ober on April 21, 2006, 9:18 am
If you were  Registered and logged in, you could reply and use other advanced thread options

And your point is???

MS fixed the problem - finally. It is somewhat disconcerting that the
original flaw was reported over two years before it was fixed. You are
quibbling about the wording of the bulletin when you should be blasting MS
for taking two years to fix the problem.

Mike Ober.


> "The criticism focused on a two issues in Microsoft's security bulletin
> documenting the changes to Windows systems by a patch released last
> Tuesday. The advisory stated that the vulnerability being fixed was
> privately reported but that a "variation" of the flaw had been publicly
> disclosed in May 2004. Microsoft should have stated that the original
> vulnerability--more than 700 days old--had been fixed as well as a more
> recent, privately disclosed flaw, vulnerability researcher Matthew Murphy
> stated in a blog post."
>
> "The information as published is extremely misleading and Microsoft's
choice
> not to document a publicly-reported vulnerability is not one that will be
> for the benefit of its customers' security," wrote Murphy. The security
> researcher, a student in the information systems program at Missouri State
> University, is currently working with Metasploit founder HD Moore to find
> flaws in Internet Explorer and other browsers using data fuzzing
> techniques."
>
> http://www.securityfocus.com/brief/187?ref=rss
>
> Imhotep




Posted by Imhotep on April 21, 2006, 8:39 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Michael D. Ober wrote:

>
> And your point is???
>
> MS fixed the problem - finally. It is somewhat disconcerting that the
> original flaw was reported over two years before it was fixed. You are
> quibbling about the wording of the bulletin when you should be blasting MS
> for taking two years to fix the problem.
>
> Mike Ober.
>
>
>> "The criticism focused on a two issues in Microsoft's security bulletin
>> documenting the changes to Windows systems by a patch released last
>> Tuesday. The advisory stated that the vulnerability being fixed was
>> privately reported but that a "variation" of the flaw had been publicly
>> disclosed in May 2004. Microsoft should have stated that the original
>> vulnerability--more than 700 days old--had been fixed as well as a more
>> recent, privately disclosed flaw, vulnerability researcher Matthew Murphy
>> stated in a blog post."
>>
>> "The information as published is extremely misleading and Microsoft's
> choice
>> not to document a publicly-reported vulnerability is not one that will be
>> for the benefit of its customers' security," wrote Murphy. The security
>> researcher, a student in the information systems program at Missouri
>> State University, is currently working with Metasploit founder HD Moore
>> to find flaws in Internet Explorer and other browsers using data fuzzing
>> techniques."
>>
>> http://www.securityfocus.com/brief/187?ref=rss
>>
>> Imhotep


Quibbling??? I think the point of the article was that MS was trying to
deceive people...or at least, not being totally honest.

Imhotep

Similar ThreadsPosted
Microsoft patches Windows, Exchange flaws... May 11, 2006, 8:19 pm
Avast silent mode?! September 25, 2007, 3:36 pm
More Microsoft updates! August 8, 2006, 4:31 pm
Re: More Microsoft updates! August 9, 2006, 6:50 pm
Security suggestion for Microsoft June 6, 2005, 10:23 am
"Microsoft Security Update" August 21, 2008, 8:19 am
MicroSoft Talks Daily With Your Computer June 7, 2006, 10:33 pm
Re: Microsoft Misrepresenting WGA's Functionality? June 12, 2006, 3:24 am
Microsoft Zero Day security holes being exploited September 22, 2006, 10:37 pm
Microsoft Warns of PowerPoint Attack October 13, 2006, 11:32 pm

The site map in XML format XML site map

Contact Us | Privacy Policy