funsec mailing list archives
New from the MS Advisory
From: "Larry Seltzer" <larry () larryseltzer com>
Date: Tue, 3 Jan 2006 08:19:21 -0500
*What's Microsoft's response to the availability of third party patches for the WMF vulnerability? Microsoft recommends that customers download and deploy the security update for the WMF vulnerability that we are targeting for release on January 10, 2006. As a general rule, it is a best practice to utilize security updates for software vulnerabilities from the original vendor of the software. With Microsoft software, Microsoft carefully reviews and tests security updates to ensure that they are of high quality and have been evaluated thoroughly for application compatibility. In addition, Microsoft's security updates are offered in 23 languages for all affected versions of the software simultaneously. Microsoft cannot provide similar assurance for independent third party security updates. * Why is it taking Microsoft so long to issue a security update? Creating security updates that effectively fix vulnerabilities is an extensive process. There are many factors that impact the length of time between the discovery of a vulnerability and the release of a security update. When a potential vulnerability is reported, designated product specific security experts investigate the scope and impact of a threat on the affected product. Once the MSRC knows the extent and the severity of the vulnerability, they work to develop an update for every supported version affected. Once the update is built, it must be tested with the different operating systems and applications it affects, then localized for many markets and languages across the globe. _______________________________________________ Fun and Misc security discussion for OT posts. https://linuxbox.org/cgi-bin/mailman/listinfo/funsec Note: funsec is a public and open mailing list.
Current thread:
- WMF round-up, updates and de-mystification Gadi Evron (Jan 03)
- Re: WMF round-up, updates and de-mystification Pierre Vandevenne (Jan 03)
- Re: WMF round-up, updates and de-mystification Gadi Evron (Jan 03)
- RE: WMF round-up, updates and de-mystification Larry Seltzer (Jan 03)
- Re: WMF round-up, updates and de-mystification Gadi Evron (Jan 03)
- New from the MS Advisory Larry Seltzer (Jan 03)
- New from the MS Advisory Larry Seltzer (Jan 03)
- New from the MS Advisory Larry Seltzer (Jan 04)
- New from the MS Advisory Larry Seltzer (Jan 04)
- Re[2]: WMF round-up, updates and de-mystification Pierre Vandevenne (Jan 03)
- Re: WMF round-up, updates and de-mystification Gadi Evron (Jan 03)
- Re: Re: WMF round-up, updates and de-mystification dudevanwinkle () gmail com (Jan 03)
- Re: WMF round-up, updates and de-mystification Pierre Vandevenne (Jan 03)
- Re[2]: WMF round-up, updates and de-mystification Pierre Vandevenne (Jan 03)
- Re[2]: WMF round-up, updates and de-mystification Pierre Vandevenne (Jan 04)
- Re[2]: WMF round-up, updates and de-mystification Pierre Vandevenne (Jan 04)