- Growth of Internet slows considerably in September
- A plane spike to cut sonic boom
- Google Code Search peers into programs' flaws
- Terra Soft moves past Apple with first Cell-based supercomputing...
- Vista a 'threat' to the national security of India
- High-def media to dominate home video market by 2012
- AMD schedules 65 nm "Taylor" launch for Q2 2007
- Viewsonic launches DLP projector for less than $1000
- NEC to sample high-brightness 12.1" LCD module
- Asustek rolls out 2ms 22" widescreen LCD monitor
Microsoft releases ten patches in its October security update
Source: Tom's Hardware US – Keywords: microsoft, update, october
Syndication:
Redmond (WA) - Microsoft has released its regular monthly security update and issued a wave of ten patches. Microsoft encountered problems with the initial distribution of the patch yesterday, but the sftware maker's security team was able to fix some problems that were widely publicized.
The October update went live on Microsoft's site early Tuesday, but many users did not get their hands on it for several hours. According to a blog entry from Craig Gehre, a member of Microsoft's security team, "network issues experienced on the Microsoft Update platform" caused a delay of the updates to become available via Microsoft Update, Automatic Updates, Windows Server Update Services, or Windows Update v6.pr.
The October package carries a total of ten updates. Six of these are rated "critical," which include an Excel vulnerability which allows hackers to plant malicious code remotely, as well as a known, already exploited hole in Word. Additionally, three other previously unknown security problems, and one update that fixes general holes throughout Office applications were fixed from the October patch. The update also addresses potential Denial of Service attacks.
The patch also takes care of the WebView security hole in Internet Explorer, which had already been actively exploited.
Finally, of less importance, the remaining updates apply to ASP.Net, Windows Object Packager, and the TCP/IP stack. The .Net-Framework 2.0 update patches a vulnerability that "could allow information disclosure", and for Windows Object Packager, the update closes a hole that allows for remote code execution. The least critical update, as ranked by Microsoft, is in TCP/IP, with mainly general updates. The patch fixes "several vulnerabilities in Windows, the most critical of which could allow a denial of service attack."
Details and the download of the patches can be found on Microsoft's Technet pages.
-
Previous News Article
DVD Forum to offer China-specific HD... -
Next News Article
UPDATE: Google combines spreadsheets...