On CBS MoneyWatch: 10 Most Expensive U.S. Colleges
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 30 of 55:
Next »
« Previous
Is an out-of-band patch really needed for these?
Remember, in order to be infected by these exploits, the user not only needs to browse to / receive a malicious PowerPoint file, the user must also *explicitly* click Yes on the security warning that comes up. This factor (a "mitigating factor" as it is called) reduces the severity quite a bit.

Other scenarios, such as the WMF exploit where all it took was viewing an email on a web page, are much more critical and deserve an out of band release. The PowerPoint scenario is much less severe and it is more important that they take two extra weeks and make sure the fix doesn't break anything.
Posted by: PB_z   Posted on: 07/25/06 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

Patch Tuesday--let the attacks begin  Loverock Davidson | 07/25/06
I call BS...  Patrick Jones | 07/25/06
Heck, I open them just  Hrothgar - PCLinuxOS User | 07/25/06
I don't  Loverock Davidson | 07/26/06
Underestimated user stupidity  superbus | 07/25/06
no, it's just overestimating user's intelligence... n  michael_t | 07/25/06
I appreciate the reminder  CTSTechs.com | 07/25/06
Those were the days...  Zeppo9191 | 07/25/06
wink  nomorems | 07/25/06
Barefoot, of course.  swoopee | 07/26/06
hey...  mypl8s4u2 | 07/26/06
Creating paranoia  mypl8s4u2 | 07/26/06
Are the malware writers...  Anton Philidor | 07/25/06
I think  j.m.galvin | 07/25/06
Is that a third possibility?  Anton Philidor | 07/25/06
Depends on the nature of the exploit  NonZealot | 07/25/06
Maybe they reverse engineer the patch  MacGeek2121 | 07/25/06
Perhaps,  Hrothgar - PCLinuxOS User | 07/25/06
The security companies...  Anton Philidor | 07/26/06
missed the point?  GDF | 07/26/06
Mentioned that alternative in the original post.  Anton Philidor | 07/26/06
MS Always behind in everything, except the icons ... wink  michael_t | 07/25/06
Articles in ZDNet...  Anton Philidor | 07/25/06
ironically, creeps leverage MS's tools more than MS... wink ..  michael_t | 07/25/06
And you know this how?  John Zern | 07/25/06
Fix old or new first?  Anton Philidor | 07/26/06
yes, but....  mypl8s4u2 | 07/26/06
I told you  mypl8s4u2 | 07/26/06
The problem isn't having a regular patching cycle.  enduser_z | 07/25/06
Is an out-of-band patch really needed for these?  PB_z | 07/25/06
Hey, I don't smoke!  Reverend MacFellow | 07/25/06
Hey, neither do I!  ccamp43276@... | 07/25/06
Sounds like a little professional work is needed ....  houchens | 07/25/06
I like your prose...  nomorems | 07/25/06
The solution ...  Resuna | 07/25/06
Word/Exce/Powerpoint viewers?  NonZealot | 07/25/06
or use linux  galileon | 07/25/06
hash the mail  Sam66 | 07/25/06
Yes, SSL or PGP/GPG signed email...  MV_z | 07/26/06
patch the patches  hilda4jc | 07/25/06
Must read for security professionals  BillPStudios | 07/25/06
A tad xenophobic there, Bob ?  Clockwork Computer | 07/25/06
Huh, did I read xenophobic?  peeseebeeb@... | 07/25/06
Don't be silly  Dr_Zinj | 07/26/06
What do you mean by "Industrial ... "  jmusto@... | 07/25/06
Responsibility  mcnuttja@... | 07/25/06
hacked  jan133 | 07/25/06
patch for xp firewall  jan133 | 07/25/06
Dont bother with XP firewall  kokuryu | 07/26/06
We hate Microsoft!  ruud@... | 07/26/06
Get a muff pistol  Loranap1 | 07/26/06
Let's attack each other  Boot_Agnostic | 07/26/06
Windows XP is now Patched!  Dilberter | 07/26/06
The only real solution  gdstark13 | 07/26/06
having to wait  mypl8s4u2 | 07/26/06

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
advertisement

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline