On TV.com: GLEE: Risky Business
BNET Business Network:
BNET
TechRepublic
ZDNet

March 29th, 2006

No endorsement for 3rd party IE patches this time?

Posted by George Ou @ 11:19 am

Categories: Security

Tags:

When the WMF vulnerability hit at the beginning of this year, security groups like SANS endorsed 3rd party patches and Ilfak Guilfanov received global fame.  But this time, there are no such endorsements for similar patches from eEye and Determina from SANS which offers up some strange reasoning.

When eEye became the first to release a 3rd party patch, they were criticized for not releasing any source code for others to verify.  But then when eEye did release the source,  the reason given for not endorsing it is that a workaround from Microsoft is available.  But that’s also bogus since a workaround was given for the WMF exploit last time which arguably had far less impact than the current Active Scripting workaround which breaks a whole bunch of websites that require Active Scripting.

But an even stranger statement from the same SANS advisory states "Based on prior public commitments, we do suspect that Microsoft will issue the patch early once they are convinced that customers require the use of Internet Explorer in production environments".  Call me crazy, but I though Internet Explorer is used in production environments in 90% of all the world’s Internet browsers.  I’m not necessarily endorsing the 3rd party patch myself, but I still think Microsoft needs to come out with an out-of-band patch as soon as possible.

I’m not trying to pick on SANS and they did a great job vetting the 3rd party WMF patch last time, but this most recent advisory just doesn’t make any sense.  If SANS doesn’t want to get in to the business of vetting 3rd party patches, don’t beat around the bush with nonsense and just say so.

George Ou is Technical Director of ZDNet. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 10 Talkback(s)
Microsoft patch available
Per Microsoft Security Advisory 912945, http://www.microsoft.com/technet/security/advisory/912945.mspx, th... (Read the rest)
Posted by: TimC_z Posted on: 03/30/06 You are currently: a Guest | | Terms of Use
Amen. (eom)  BillyG_n_SC | 03/29/06
I suppose IE isn't important.  zdnet reader | 03/29/06
Virus protection?  TimC_z | 03/29/06
Anti-virus or IDS is not an excuse  george_ou | 03/29/06
Matters in mitigation  TimC_z | 03/30/06
Microsoft Delays IE's ActiveX D-Day  D. T. Schmitz | 03/29/06
No, different topic  george_ou | 03/29/06
3rd Party IE Fix problems?  nucrash | 03/30/06
Some minor printing problems  george_ou | 03/30/06
Microsoft patch available  TimC_z | 03/30/06

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

Click Here
advertisement

Recent Entries

Top Rated

    Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
    Reduce risk. Reduce complexity. Increase reliability.
    A simplified IT environment isn't just less complex. It's also more reliable. Standardize on a single Linux platform with SUSE Linux Enterprise from Novell, and get the world's most interoperable Linux
    Learn more >>
    Microsoft Dynamics CRM Online - Free Six-Month Trial for Eligible Organizations
    Microsoft Dynamics CRM Online provides fast online access, simple contact management and better sales performance for a low monthly cost - the best value on the market today.
    Learn more about the free, six-month trial offer>>
    The more you simplify, the more you save
    When you transition from your existing Red Hat environment to SUSE Linux Enterprise from Novell, you can recognize dramatic cost savings, perhaps as much 50%
    Learn more >>
    The best support in the Linux business
    If Linux is going to power your mission-critical applications, you'd better have the best support known to business. Novell was rated the top provider of Linux technical support.
    Learn more >>
    Keep Up With The Latest In Document Management with The DocuMentor.
    Doc delivers the scoop on today's enterprise content management, printer maintenance, and all other issues related to document management. It's the DocuMentor Blog.
    Learn more >>
    Learn more about tools to grow your business
    The Business Essentials Guide provides you useful tools and templates to help grow your business and save you time with automated shipping solutions.
    Save time with the UPS Business Essentials Guide

    Archives

    ZDNet Blogs

    White Papers, Webcasts, and Downloads

    SmartPlanet

    Click Here