Printer Friendly
The Free Library
14,538,373 articles and books
Member login
User name  
Password 
 
Join us Forgot password?

Third busy patch month for Microsoft.


As part of its monthly security update cycle, Microsoft have released a dozen security bulletins. Nine & them are tagged critical, the company's highest severity rating. The alerts give details of 20 flaws in The infamous MSBlast worm, which wreaked havoc in 2003, exploited a similar flaw, related to a Windows component called remote procedure call.

The patching rush started in June, when it released 12 bulletins. It came after a patch lull, with only three alerts in May, five in April and two in March. Another of this month's flaws that could be exploited without any user interaction lies in the Windows Domain Name System (DNS (Domain Name System) A system for converting host names and domain names into IP addresses on the Internet or on local networks that use the TCP/IP protocol. For example, when a Web site address is given to the DNS either by typing a URL in a browser or behind the ) client, which is used to help translate URLs into numerical IP addresses. However, an attacker has to be on the same subnetwork See subnet.  as the intended target or must trick the user into making a DNS request to a malicious server.

The bulk of the problems addressed by the August patches could be used for attacks via the Web or e-mail. They include security holes in the Internet Explorer Microsoft's Web browser, which comes with Windows starting with Windows 98. Commonly called "IE," versions for Mac and Unix are also available. Internet Explorer is the most widely used Web browser on the market. It has also been the browser engine in AOL's Internet access software.  Web browser The program that serves as your front end to the Web on the Internet. In order to view a site, you type its address (URL) into the browser's Location field; for example, www.computerlanguage.com, and the home page of that site is downloaded to you. , the Outlook Express e-mail client Same as e-mail program.  and other Windows and Office components.

Microsoft has not addressed all known flaws in its products. For example, a variant of a bug patched last month in a Windows component called "mailslot" is still without a fix. Proof-of-concept code that was posted to the Net last month. Microsoft recommends that people install the critical fixes immediately. The updates are available via the Windows Update An updating service on Microsoft's Web site that enables users to obtain bug fixes and new features for their version of Windows. Windows Update components analyze your PC's configuration and display a list of appropriate downloads for your individual system.  and Automatic Updates tools. Temporary workarounds.

www.microsoft.com
COPYRIGHT 2006 A.P. Publications Ltd.
No portion of this article can be reproduced without the express written permission from the copyright holder.
Copyright 2006, Gale Group. All rights reserved. Gale Group is a Thomson Corporation Company.

 Reader Opinion

Title:

Comment:



 

Article Details
Printer friendly Cite/link Email Feedback
Title Annotation:Security
Publication:Database and Network Journal
Geographic Code:1USA
Date:Aug 1, 2006
Words:254
Previous Article:Security pest found on Blackberry.(Security)
Next Article:USB devices unveiled.(Security)(Universal serial bus)(Brief article)
Topics:



Related Articles
MICROSOFT POSTS REPAIR KIT TO REMEDY SECURITY FLAWS.(News)
Sophos warns of RTF files. (Virus Notes).(Brief Article)
Standardizing the patch experience.(Security Technote)
Oracle monthly patches.(Software News and Products)(Brief Article)
Microsoft releases 10 security updates.(Security)(Brief Article)
St. Bernard Software expands UpdateEXPERT patch management offering for int'l markets.(international)
Boss cautions Microsoft's forced deployment of SP2 for Windows XP computers may cause widespread issues and disrupt business continuity.
Automated patching: an easier approach to managing your network security.(DATABASE & NETWORK JOURNAL INTELLIGENCE)
Dasher-B expoits Windows 2000 PC's.(Security News)
IBM Internet Security Systems shields customers from critical Microsoft vulnerabilities.(Security News and Products)

Terms of use | Copyright © 2009 Farlex, Inc. | Feedback | For webmasters | Submit articles