- Recommend:
- 0 Comments
Microsoft Patches Its Own Security Patch
Software giant replaces last month's fix for its chat software, and moves to repair a browser hole.
Microsoft released two security bulletins late Tuesday, the first updating a patch the company released for a handful of its chat software clients in May and the second detailing a work-around to a flaw in its Internet Explorer Web browser that comes as a result of the aging Gopher protocol.
The vulnerability in MSN Chat, MSN Messenger, and Exchange Instant Messenger addressed by the patch released on May 8 could have allowed an attacker to run code on target machines via a buffer overflow in ActiveX.
The original patch did not, however, stop the affected ActiveX component from being reinstalled on systems in all cases, leaving the potential for patched systems to become vulnerable again, Microsoft says. To address this, the company released a new set of fixes on Tuesday for all three affected products.
Buffer overflows occur when the space reserved for programs or services in memory is overrun, allowing attackers to run code or take over systems.
The new security alert, patches and updated versions of the programs can be found on Microsoft's Web site.
This most recent patch update is not the first time in recent months that Microsoft has needed to fix a security fix. In May, the company released a patch for Internet Explorer that, security researchers charged, did not close all the holes it claimed to.
Microsoft encountered a similar problem in February, when another patch for IE caused the browser to crash.
Potential Problems
The Redmond, Washington, software company Tuesday also released a security bulletin detailing a way for users to protect themselves from attack using the Gopher protocol. Microsoft has not yet released a patch to fix the issue.
The Gopher vulnerability potentially gives a remote user access to a host computer, by exploiting a buffer overflow bug in IE's gopher code.
The company's warning about the Gopher vulnerability marks Microsoft's official acknowledgement of the bug. When Online Solutions, the Finnish company that discovered the flaw, released its advisory, Microsoft said only that it was investigating the issue and did not confirm it.
Microsoft's work-around for the issue is the same as that provided by Online Solutions: that users should select Internet options from within IE's Tools menu, then click Connections and select "LAN settings." From there, users should check "Use proxy server for your LAN," click the "Advanced..." button; type "localhost" into the textbox next to the word "Gopher" and put "1" in the port field.
Would you recommend this story? YES NO
- Recommend:
- 0 Comments
-
Speed Up Everything!
PCWorld shows you the secrets to improve performance on all your hardware.
-
Master Windows 7!
Our expert guide will help you get the most out of Windows 7.
-
ThinkPad Edge E420 Lenovo Style in an Affordable Package
Buy now direct from Lenovo -
ThinkPad X220 Fast and light, with great input ergonomics and battery life, this powerhouse ultraportable is best-of-breed.
Buy now direct from Lenovo -
ThinkPad X120e One of the best netbooks ever, X120e has the best netbook keyboard ever--nothing else comes close
Buy now direct from Lenovo
- Microsoft Slays the BEAST, and Six Other Patch Tuesday Updates
- Critical Patch Tuesday Flaw Easy to Exploit
- Patch Internet Explorer Now
- Emergency IE Patch Fixes Zero-Day Flaw
- Patch Tuesday Fixes Dangerous Flaws with Exploits Imminent
- Patch Tuesday Updates Fix Critical Flaws in IE and DirectShow
- Merry Christmas! Microsoft Plans Massive Patch Tuesday to Close 2011
- 12 Criteria for Selecting the Best ERP System Replacement An ERP system is your information backbone and reaches into all areas of your business and value chain. Replacing it can open unlimited business opportunities. This white paper explains the 12 criteria that allow you to identify and select the solution that will meet these expectations.
- Leveraging Social Computing Technologies for ERP Applications This white paper details how Web 2.0 technologies support business strategies by improving efficiency, productivity, and collaboration.



















