Microsoft Re-Re-Releases IE Patch 77
uniquebydegrees writes, "InfoWorld reports that on Tuesday Microsoft quietly released the second update for MS06-042. This is the cumulative patch for IE that actually introduced a new security hole into systems that applied the update. Microsoft re-released the patch back in August, but it now turns out that the updated patch had yet another vulnerability similar to the first, once again discovered by folks at eEye Digital Security. As with the previous hole, it concerned the handling of long URLs from web sites using HTTP 1.1 with compression."
Bugger! (Score:3, Interesting)
I just spent 4 hours downloading and installing patches over the weekend and now I've got more...
I'm just glad I don't use IE, that's all.
i'd really like to know why it downloaded all those outlook patches, considering i don't have that installed and have never had it installed...
Re: (Score:2)
DIR C:\PROGRA~1\OUTLOO~1
Son of a bitch. They're back on my box too. I remember how many hoops I had to jump through to delete them when I first set up this box. Now they're back, but the old batch file that wiped the multiple copies of the .DL_ files in \I386 as well as the copies in the DLLCACHE directory no longer works. WTF?
Re: (Score:1)
Re: (Score:2)
Re:Bugger! (Score:4, Funny)
Remind me of an old joke...
Windows 95: comes with built-in support for long filena~1.
Re: (Score:1)
I'm glad I don't use your ISP. It doesn't take me long to download the updates. No longer than it takes to download a Firefox update, which didn't get nearly as harsh a reaction even though they've also released quick fixes to regression patches. I didn't have to download any Outlook updates o
Re-Re-Releases IE Patch! (Score:4, Funny)
Re:Re-Re-Releases IE Patch! (Score:4, Interesting)
Re: (Score:1)
Bravo.
Re:Re-Re-Releases Ch-ch-changes (Score:1)
I knew Bill Gates was a David Bowie fan, but this is taking it too far!
Re: (Score:1)
Re:Re-Re-Releases in other news... (Score:1)
Re: (Score:2)
Actually, this reminds me of an old joke:
This opera singer was performing the famous aria 'Vesti la Giubba.' When he finished, the audience jumped to their feet and yelled "Encore! Encore!" So he sang it again. Again, the audience jumped to their feet yelling, "Encore! Encore!" So he sang it again. And again. And again. In fact, he sang it eight times. Finally, he walked out on stage and spoke to the audience.
"I'm honored," he said, "that you have asked me to sing th
Re: (Score:2)
10 Patches Later... (Score:1)
Re: (Score:1)
Re: (Score:2)
Re: (Score:2)
Does it have a picture of a train on it? (Score:1, Funny)
I choo-choo-choose to install it.
This is bad... (Score:2)
Maybe Microsoft just need to release a new operating system to fix the IE bugs for good. I heard Apple has a good operating system.
Re: (Score:2)
Re: (Score:1)
If you replace Microsoft's HTML rendering code with Gecko, you won't have done any better than change the set of bugs. At worst, you've created a target for crackers whose codebase is shared across many operating systems, and not just those sold by Microsoft.
So junk intended for Windows will, at best, cause crashes and misbehavior in Firefox, Galeon, etc. on Linux. At the worst, it could start showing up on your filesystem anywh
Re: (Score:1)
Sorry.
Since . . . (Score:5, Informative)
MS06-042 is the Security Bulletin.
KB918899 is the KB id w/ Patch.
Re: (Score:2)
Neither can they, it appears. That's why they had to release it all over again.
Twice.
Re: (Score:2)
Come on Microsoft, you're getting there, a few more and we'll be done (switching a few more people) !
Re: (Score:1)
It's no surprise he can't tell the difference. In this case, the patch is the vulnerability.
Besides, making a mistake while complaining about Microsoft isn't on the same scale as Microsoft releasing a series of bad patches. Did the GP's mistake result in any botnets? More importantly, the GP's mistake doesn't make Microsoft's mistake any less harmful.
Huh (Score:3, Funny)
Re: (Score:2)
Re: (Score:3, Insightful)
But more webservers use Apache over IIS, so why are there more eploits for IIS?
Re: (Score:3, Funny)
Re: (Score:2)
If you google it youll come up with more. ISS and Apache are very much on equal footing.
re-re-re-release. (Score:5, Funny)
My patch always works! (Score:2, Interesting)
2. Install Firefox and/or Opera (I like both, Opera for email, Firefox for everything else)
3.
4. Profit!
Re: (Score:1)
Re: (Score:2)
Re: (Score:1)
Re: (Score:1)
Re: (Score:1)
Great, but when will they stop the crashes? (Score:3, Informative)
Re: (Score:2)
Umm, if theres a hotfix available then they did fix that crash. Not sure what your goin for here.
1) Hotfixes are generally only available from microsoft support after you call and pay with a credit card.
2) Hotfixes are not real patches. That is, they aren't generally considered release quality code.
3) When the patch comes out, it may not mesh well with the hotfix, owing in part to #2
It sucks. Until a real patch is out, and available to everyone, Microsoft has not fixed the problem. And even then, judgin
And MS says that Vista won't need... (Score:1)
Code reuse? (Score:2)
Siebel (Score:1)
Sheeh! (Score:2)
Microsoft shouldn't waste time patching/supporting these older browser versions.
Re: (Score:1)
While your argument does have some merit, the whole "focus on the new stuff" idea isn't very helpful to a company's image. (Note to ACs: Perfect place to reply with "Can MS's image get any worse? LOLROFLMCBOFL!") For example, say you're playing an old-school game on the PC. Oh noes! It doesn't work. Why not? Well, the company's website says that only the FAQ pages for that game are still up, because they stopped giving specifi
Re: (Score:2)
Re: (Score:1)
Re: (Score:2)
Fair enough. =D (n/t) (Score:1)
Re: (Score:2)
While your argument does have some merit, the whole "focus on the new stuff" idea isn't very helpful to a company's image.
They can create a "new stuff" patch for the old stuff, or people could just use the patch they already have. XP SP2 is free.
Re: (Score:1)
You know, we also use "re-re" as well (Score:1, Offtopic)
Exit Our Hero (Score:2)
Cocky eEye e-mail (Score:1)
Unit testing? (Score:1)
Re: (Score:1)
http://www.nunit.org/ [nunit.org]
QA (Score:1)