internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet |Refer-It

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Norton AntiVirus 2008

Most Popular Software Downloads
Ad-Aware 2008 Free
Windows XP Service Pack 3
Internet Explorer 7
QuickTime for Windows
Adobe Flash Player
AVG Anti-Virus Free
Paint Shop Pro
Windows Live Suite
CCleaner (Crap Cleaner)
Winamp

Most Popular Software Articles
Windows Vista Tips & Tricks, Part 1
Windows Vista: Worthy of the Hype?
Windows Wireless Zero Configuration: Five Steps to Sanity


Software Reviews

Slow Patch Tuesday Should Not Be Dismissed
Only One Critical Fix in November Batch
Andy Patrizio

Microsoft's monthly patch cycle is about as slow as the company can get while still having a Patch Tuesday. It released two, count 'em, two fixes today, one rated Critical, the most severe kind of fix, and one rated as Important, considered the least severe.

The one Critical fix, MS07-061, addresses a publicly reported vulnerability involving how the Windows shell handles specifically crafted URIs (define) that are passed to it. If the Windows shell did not sufficiently validate these URIs, an attacker could exploit this vulnerability and execute arbitrary code.

Microsoft has only identified ways to exploit this vulnerability on systems using Internet Explorer 7, but the vulnerability also exists in a Windows library file, so all versions of Windows are affected by it. This fix will require a reboot.

MS07-062, the fix rated as Important, is a vulnerability in Windows which could allow an attacker to send specially crafted responses to DNS requests.

Security experts urged administrators to install the 061 patch right away.

"This is a light Patch Tuesday with only one critical Microsoft OS vulnerability, a critical remote code execution that needs to be patched," said Don Leatham, director of solutions and strategy for Lumension Security, in a statement to InternetNews.com.

Leatham said administrators should look into other problems, as several application vulnerabilities have come to light in recent weeks. These include remote code execution holes in QuickTime, a vulnerability in Macrovision's Flexnet product and remote code execution holes in Adobe Acrobat.

Sarwate noted that Microsoft released an out-of-band advisory stating that a patch would be available shortly for the Macrovision vulnerability and that it was "very surprising" that a fix was omitted, although Macrovision has issued its own patch.

Amol Sarwate, manager of the vulnerability research lab at Qualys, also addressed the broader impact beyond Microsoft in an emailed statement.

"Given that URI translation can be done at the operating system shell or the application level, it’s notable that other vendors, including Adobe and Mozilla, released patches in the past weeks to address this issue," noted Sarwate. "Having said that, application vendors will benefit from Microsoft’s operating system ability to sanitize at the shell level."

Microsoft also issued its monthly upgrade to the Malicious Software Removal Tool, this time to recognize the Win32/Conhook line. Conhook is a Trojan downloader. The MSRT can be downloaded from Microsoft's MSRT page.

As is its tradition, Microsoft will hold a webcast to discuss the fixes on Wednesday, November 14, 2007 at 11:00 AM PDT.

News courtesy of internetnews.com

November 13, 2007

Download Windows Live OneCare Now!Download

Download Microsoft Windows Malicious Software Removal Tool Now!Download

View All Microsoft Service & Security Releases

Contents:
1. Only One Critical Fix in November Batch






JupiterOnlineMedia

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

Solutions
Whitepapers and eBooks
Microsoft Article: Will Hyper-V Make VMware This Decade's Netscape?
Microsoft Article: 7.0, Microsoft's Lucky Version?
Microsoft Article: Hyper-V--The Killer Feature in Windows Server 2008
Avaya Article: How to Feed Data into the Avaya Event Processor
Microsoft Article: Install What You Need with Windows Server 2008
HP eBook: Putting the Green into IT
Whitepaper: HP Integrated Citrix XenServer for HP ProLiant Servers
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 1
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 2--The Future of Concurrency
Avaya Article: Setting Up a SIP A/S Development Environment
IBM Article: How Cool Is Your Data Center?
Microsoft Article: Managing Virtual Machines with Microsoft System Center
HP eBook: Storage Networking , Part 1
Microsoft Article: Solving Data Center Complexity with Microsoft System Center Configuration Manager 2007
MORE WHITEPAPERS, EBOOKS, AND ARTICLES
Webcasts
Intel Video: Are Multi-core Processors Here to Stay?
On-Demand Webcast: Five Virtualization Trends to Watch
HP Video: Page Cost Calculator
Intel Video: APIs for Parallel Programming
HP Webcast: Storage Is Changing Fast - Be Ready or Be Left Behind
Microsoft Silverlight Video: Creating Fading Controls with Expression Design and Expression Blend 2
MORE WEBCASTS, PODCASTS, AND VIDEOS
Downloads and eKits
Sun Download: Solaris 8 Migration Assistant
Sybase Download: SQL Anywhere Developer Edition
Red Gate Download: SQL Backup Pro and free DBA Best Practices eBook
Red Gate Download: SQL Compare Pro 6
Iron Speed Designer Application Generator
MORE DOWNLOADS, EKITS, AND FREE TRIALS
Tutorials and Demos
How-to-Article: Preparing for Hyper-Threading Technology and Dual Core Technology
eTouch PDF: Conquering the Tyranny of E-Mail and Word Processors
IBM Article: Collaborating in the High-Performance Workplace
HP Demo: StorageWorks EVA4400
Intel Featured Algorhythm: Intel Threading Building Blocks--The Pipeline Class
Microsoft How-to Article: Get Going with Silverlight and Windows Live
MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES