Valhalla Legends Forums Archive | General Discussion | MS04-040 Released

AuthorMessageTime
iago
The patch for the dreaded "IFrame Vulnerability" was FINALLY released.  It took microsoft 29 days to release a patch for arbitrary code execution in their browser that had available exploit code from about 27 days ago.  That was absolutely rediculous.

http://secunia.com/advisories/12959/
December 1, 2004, 8:56 PM
Yoni
According to link, XP SP2 already fixed it. So maybe half or more (correct me if I'm way off) of the patch's "target audience" was already patched.
December 2, 2004, 12:30 AM
iago
[quote author=Yoni link=topic=9742.msg90731#msg90731 date=1101947428]
According to link, XP SP2 already fixed it. So maybe half or more (correct me if I'm way off) of the patch's "target audience" was already patched.
[/quote]

Windows 2k3 and Windows 2000 were still vulnerable.  And there are still a lot of corperations who haven't gotten approval to move to SP2 yet (because of all the incompatilibity issues we know it's going to cause)
December 2, 2004, 1:59 AM
Myndfyr
[quote author=iago link=topic=9742.msg90751#msg90751 date=1101952775]
[quote author=Yoni link=topic=9742.msg90731#msg90731 date=1101947428]
According to link, XP SP2 already fixed it. So maybe half or more (correct me if I'm way off) of the patch's "target audience" was already patched.
[/quote]

Windows 2k3 and Windows 2000 were still vulnerable.  And there are still a lot of corperations who haven't gotten approval to move to SP2 yet (because of all the incompatilibity issues we know it's going to cause)
[/quote]

I recently upgraded my development partition of XP to SP2.  I haven't had any compatibility issues, despite my fear of them.
December 2, 2004, 2:24 AM
iago
[quote author=MyndFyre link=topic=9742.msg90758#msg90758 date=1101954247]
[quote author=iago link=topic=9742.msg90751#msg90751 date=1101952775]
[quote author=Yoni link=topic=9742.msg90731#msg90731 date=1101947428]
According to link, XP SP2 already fixed it. So maybe half or more (correct me if I'm way off) of the patch's "target audience" was already patched.
[/quote]

Windows 2k3 and Windows 2000 were still vulnerable.  And there are still a lot of corperations who haven't gotten approval to move to SP2 yet (because of all the incompatilibity issues we know it's going to cause)
[/quote]

I recently upgraded my development partition of XP to SP2. I haven't had any compatibility issues, despite my fear of them.
[/quote]

We're definately going to have them.  We have some crappy software being used.  We're just hoping it won't go TOO badly.
December 2, 2004, 2:58 AM
Yoni
[quote author=iago link=topic=9742.msg90751#msg90751 date=1101952775]
Windows 2k3 and Windows 2000 were still vulnerable.
[/quote]

Actually,

[quote]
NOTE: The vulnerability does not affect systems running Windows XP with SP2 installed nor Windows Server 2003.
[/quote]

But yes @ Win2k. And yes, I know lots of people didn't install it yet. I just threw a guess (based on absolutely nothing) that half of Windows users use XP SP2. Any based statistics?
December 2, 2004, 10:21 AM
iago
well, the only statistics that I've seen are from Microsoft, "Over xxxx billion people have installed it!", but that doesn't really mean anything.

The odd part is that they fixed the problem in SP2, yet it took them a month to fix it on other platforms.  It's confusing, like, did they manage to lose the bug that caused it or something? :/
December 2, 2004, 1:28 PM
Skywing
[quote author=iago link=topic=9742.msg90788#msg90788 date=1101994083]
well, the only statistics that I've seen are from Microsoft, "Over xxxx billion people have installed it!", but that doesn't really mean anything.

The odd part is that they fixed the problem in SP2, yet it took them a month to fix it on other platforms.  It's confusing, like, did they manage to lose the bug that caused it or something? :/
[/quote]
The fix has to be backported to the older source tree and then there's a huge regression test matrix they have to run everything through to make sure it doesn't break stuff.  But I'm not sure why it took them 27 days to do that when they've done other things much faster.
December 2, 2004, 7:58 PM
Adron
Perhaps it broke something at first?

Your msn icon requires auth Skywing?
December 3, 2004, 2:12 AM
Skywing
[quote author=Adron link=topic=9742.msg90862#msg90862 date=1102039949]
Your msn icon requires auth Skywing?
[/quote]
Nope.
December 3, 2004, 7:32 PM

Search