internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet |Refer-It

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Internet Explorer 8

Most Popular Software Downloads
Opera
Internet Explorer 7
QuickTime for Windows
Winamp
Mozilla Firefox 3
Ad-Aware 2008 Free
Adobe Flash Player
Paint Shop Pro
Adobe Shockwave Player
AVG Anti-Virus Free
7-Zip

Most Popular Software Articles
Windows Vista Tips & Tricks, Part 1
Windows Vista: Worthy of the Hype?
Windows Wireless Zero Configuration: Five Steps to Sanity


Software Reviews

Microsoft Delivers a Plethora of Patches
February's Patch Tuesday Delivers Eleven Security Bulletins
Andy Patrizio

Following its meager security updates in January, Microsoft came back with a huge release for February. The company released 11 security bulletins containing 17 fixes.

If there's any good news in this haul of fixes, it's that only six of the 11 bulletins are listed as "critical," and the five other fixes as "important."

Of the six critical fixes, Jonathan Bitle, manager of technical accounts for security provider Qualys, said MS08-010 stands out because it addresses four severe HTML issues in Internet Explorer. The vulnerabilities in MS08-010 would allow a specially crafted page to perform remote code execution on the user's system.

This vulnerability affects IE from version 5.01 up to 7. "Because it affects so many systems and doesn't require doing anything more than visiting a malicious site, that worries us," Bitle told InternetNews.com.

"Most organizations these days have a fairly good security practice about not opening unknown files from unknown users," he added. "But visiting Web sites that can be exploited is still a biggest area of concern. Here you have a remote code execution with no user interaction. Keeping your users from visiting sites like this is especially difficult."

Three of the critical fixes, MS08-008, MS08-012 and MS08-013, are in Microsoft Office 2000, XP and 2003, and Office for Mac 2004. The fixes do not affect the recently released Office 2007 and Office for Mac 2008. All can allow for remote code execution. The final critical fix, MS08-007, is critical only to Windows XP and Vista but labeled important for Windows Server 2003.

Among the important fixes are two vulnerabilities to a denial of service (define) attack that could cause the systems to restart (MS08-003 and MS08-004). Two others affect Internet Information Services (IIS): One allows an attacker to execute arbitrary code in the context of local system (MS08-005), and the other provides elevated user privilege (MS08-006).

Finally, MS08-011 covers three vulnerabilities in Microsoft Works File Converter, which could allow an attacker to take control of a system.

Today's bulletins also do not affect Windows Vista SP1 and Windows Server 2008.

As with all patch releases, Microsoft has updated its Malicious Software Removal Tool — this time to recognize the Win32/Ldpinch strain of password stealers.

Symantec calls the malware, which dates back to 2006, a low risk.

Microsoft will host a Webcast on Wednesday, Feb. 13 at 11 a.m. Pacific time to discuss the fixes.

News courtesy of internetnews.com

February 13, 2008

Download Windows Live OneCare Now!Download

Download Microsoft Windows Malicious Software Removal Tool Now!Download

View All Microsoft Service & Security Releases

Contents:
1. February's Patch Tuesday Delivers Eleven Security Bulletins






JupiterOnlineMedia

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers