Slashdot Log In
Patch Tuesday — IE7 Clean
Journal written by jginspace (678908) and posted by
kdawson
on Wed Dec 13, 2006 02:20 AM
from the patchwork-quilt dept.
from the patchwork-quilt dept.
jginspace writes "As per the advance notification, Microsoft's monthly security bulletin, released yesterday, addressed five general Windows issues and one in Visual Studio. It also included a fix for a problem in Outlook Express for a total of seven updates. As patch Tuesdays go it was fairly unremarkable. The only general Windows update labeled 'critical' is for a flaw in Media Player. As usual, there's a cumulative update for Internet Explorer, but significantly, the only versions of IE affected are 5 and 6. Version 7 is clean — which is welcome news in this first update since the upgrade was pushed to the world last month. Microsoft was silent on the two zero-day Word holes, one reported here and a new one. Sans is calling this 'Black Tuesday' and recommends patches be applied urgently for the Visual Studio and Media Player vulnerabilities. Sans is recommending the Heise Offline Update utility covered in a previous story."
Related Stories
[+]
Microsoft Issues Zero-Day Attack Alert For Word 483 comments
0xbl00d writes "Eweek.com is reporting a new Microsoft Word zero-day attack underway. Microsoft issued a security advisory to acknowledge the unpatched flaw, which affects Microsoft Word 2000, Microsoft Word 2002, Microsoft Office Word 2003, Microsoft Word Viewer 2003, Microsoft Word 2004 for Mac and Microsoft Word 2004 v. X for Mac. The Microsoft Works 2004, 2005 and 2006 suites are also affected because they include Microsoft Word. Simply opening a word document will launch the exploit. There are no pre-patch workarounds or anti-virus signatures available. Microsoft suggests that users 'not open or save Word files,' even from trusted sources."
[+]
DIY Service Pack For Windows 2000/XP/2003 197 comments
Karsten Violka writes "Looking for manageable Windows updates even without an internet connection? Heise's script collection
Offline Update 3.0 downloads the entire body of fresh updates for Windows 2000, XP, or Server 2003 from Microsoft's servers in one fell swoop and then uses them to create ISO-Images for CD or DVD. Included is an intelligent installer script that allows you to update as many PCs as desired." Sounds like a great idea, given the danger of putting an unpatched PC on the Internet to download security updates.
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
IE7 really clean? (Score:5, Insightful)
(http://www.toolz4schoolz.com/ | Last Journal: Tuesday December 12 2006, @08:36PM)
Re:clean != free of "critical" updates (Score:5, Insightful)
(http://www.daishar.com/blog)
Actually, IE7's anti-phishing technology is server-based. The judgement of a URL as "phish" or "non-phish" is done completely outside of your browser, outside of your own PC even, so there's no need for heuristic, signature, or filter updates to be pushed to users.
Re:clean != free of "critical" updates (Score:4, Insightful)
(http://www.cnycomputerservice.com/)
Even sounds a bit like spyware...
[adds another layer to tinfoil hat]
Re:clean != free of "critical" updates (Score:5, Informative)
(http://127.0.0.1/)
IE7 not clean: Secunia shows 3 unpatched holes (Score:5, Interesting)
http://secunia.com/product/12366/?task=advisories
But I installed Outlook Express 2 years ago? (Score:1, Interesting)
However, Windows/Microsoft Update keeps applying patches for "Outlook Express".
I'm sure that if I searched my drive for Outlook Express (or the correct search pattern), I would find that Windows never really uninstalled Outlooked Express. Lies lies lies!
Damn. (Score:3, Insightful)
(http://www.imwithfred.com/)
I assume that only security vulnerabilities will be patched in XP's IE7 until Vista is on the same update schedule as XP. These patches will be fashionably late and will only address the most severe issues with the browser, and that simple compatibility glitches will go unanswered. Once Vista is really rolling along there will be more consistency.
Ahhhh (Score:2)
(http://www.execyte.com/)
TLF
Article Text Isn't Very Good Journalism (Score:1, Troll)
clean (Score:5, Funny)
IE 7 Clean (Score:1)
Alright everyone, show's over (Score:5, Insightful)
Seriously, has the situation come to a place for Microsoft where a month with no patches for IE is actually news?
Pushed out? (Score:5, Informative)
I know you Americans consider "the USA" the same as "the world", but I can assure you that IE7 was NOT pushed out in the Dutch version of Windows XP. It is not even available as an optional package in Windows update.
And I think it is the same in many other countries.
Who owned you today? (Score:1)
In Soviet Union Politburo declare Chernobyl clean.
Enjoy the Zero Day parade, now with improved security.
There is a patch for IE7 available today. (Score:1, Informative)
This update resolves a performance issue with the Phishing Filter.
Why oh why... (Score:5, Informative)
Anyways, you can ask it to bugger off by going to control panel -> administrative tools -> services, find automatic updates, right click and press stop, that will stop it from nagging you about restarting.
This news saddens me (Score:1, Troll)
(http://anguish.ruinations.com/)
Handy tool - Check for insecure software (Score:2, Interesting)
Sans = SANS Internet Storm Center (Score:2, Informative)
(http://shmuel.org/)
When did every exploit become 0-day? (Score:1)
(http://knome.net/)
SANS "recommends" the Offline Update tool? (Score:2)
If I can find this evidence it would go a long way towards convincing my security group that my IT organization can use this to develope iso cds.
What about the Micro Print in Outlook Problem? (Score:1)
http://www.microsoft.com/communities/newsgroups/e
This sure seems like a problem. Maybe not critical but if they ladies in my office dont stop complaining about it then it might become critical.
IE is clean like that girl you know.. (Score:4, Funny)
Then of course you go out with her and the next day you know what falls off? We've all had that experience, haven't we?
Oddly enough that sounds exactly like IE7. I'll stick with my hotter girlfriend, Firefox. It's true she might have "enhancements" and she might be a little "slower" but at least she's not sleeping around like IE.
Windows 98 and ME out in the cold (Score:1)
(http://www.beercur.com/)
Can Zone Alarm, router firewall, along with Ad-Aware, keep things more or less safe for ME, or is it really time to upgrade?
Re:IE7 was a rewrite (Score:1)
(http://thepeer.blogspot.com/)