Newsletters
The Enterprise Security Supersite NewsFactor Sites:       NewsFactor.com     Enterprise Security Today     CRM Daily     Business Report     Sci-Tech Today  
   
This ad will display for the next 20 seconds. Please click for more information, or scroll down to pass the ad, or Close Ad.
Home Network Security Viruses & Malware Hackers Security Solutions More Topics...
Vblock™ Systems:
Advanced converged infrastructure
increases productivity & lowers costs.

www.vce.com
Windows Security
24/7/365 Network Uptime
Average Rating:
Rate this article:  
Unexpectedly Light Patch Tuesday Sees Only One Critical Bulletin
Unexpectedly Light Patch Tuesday Sees Only One Critical Bulletin

By Jennifer LeClaire
October 5, 2012 10:06AM

Bookmark and Share
"The lightness of last month's Patch Tuesday led many to say that this month would be a horrific Patch Tuesday for IT admins. With only seven bulletins and only one critical, those naysayers may want to retract those statements," said security analyst Paul Henry. "Microsoft is finally starting to see the fruit of its secure coding initiatives."
 


Microsoft on Tuesday will serve up seven security updates to patch 20 vulnerabilities in Office, Windows, SharePoint Server, SQL Server and other product lines. Only one is rated critical, but the other seven bulletins are nevertheless important.

Specifically, the critical bulletin addresses vulnerabilities in Microsoft Word. The six Important-rated bulletins will address issues in Windows, Microsoft Office, and SQL Server. This release will also address the issue in FAST Search Server first described in Security Advisory 2737111.

The October Patch Tuesday comes on the heels of an out-of-band patch to address attacks against Internet Explorer 9 and earlier versions. Most of those patches were delivered through an automated update process. Patch Tuesday will require some elbow grease from IT admins, though analysts are calling it lighter than expected.

Secure Coding Paying Off

"The lightness of last month's Patch Tuesday led many to say that this month would be a horrific Patch Tuesday for IT admins. With only seven bulletins and only one critical, those naysayers may want to retract those statements," said Paul Henry, security and forensic analyst at Lumension. "Microsoft is finally starting to see the fruit of its secure coding initiatives."

Looking back a year or so ago, Henry noted that nearly every Patch Tuesday featured a critical issue in the operating system platforms. That trend has significantly died down. In fact, Microsoft is issuing fewer patches overall. By this time last year, Redmond issued 82 patches. So far this year there have been only 70 patches.

"The biggest issue for this month from Microsoft is the certificate encryption. As we've been saying for the last several Patch Tuesdays, Microsoft is pushing out a patch that will break any encryption that is less than 1024-bit," Henry said. "This patch has been optional since August and we hope you've taken the time to test it and patch it. It will no longer be an option starting on Tuesday. There are still a few days left if you haven't tested it, but don't let this be an 'I told you so' moment."

Third-Party App Fixes

Beyond the critical Microsoft Word patch, Henry pointed to Bulletin 6 as interesting. It's a denial of service issue that affects Windows Authentication for DOS.

Essentially, if your shop accepts Kerberos for Windows authentication, then you are vulnerable to this DOS. Bulletin 2, meanwhile, is for Microsoft Works 9. Henry found this interesting because it is the final patch for Microsoft Works. Microsoft Works is phasing out of support next month.

"Microsoft products are the least of your concerns. We've seen a rash of zero-day vulnerabilities in Oracle's Java, with yet another one uncovered last week," Henry said. "That's three vulnerabilities that people should be concerned with. While Oracle has issued out-of-band patches for two of those vulnerabilities, one is still active in the wild. More concerning still, Apple has only patched one of the three."
 

Tell Us What You Think
Comment:

Name:



Neustar, Inc. (NYSE: NSR) is a trusted, neutral provider of real-time information and analysis to the Internet, telecommunications, information services, financial services, retail, media and advertising sectors. Neustar applies its advanced, secure technologies in location, identification, and evaluation to help its customers promote and protect their businesses. More information is available at www.neustar.biz.


 Windows Security
1.   Patch Tuesday Offers Critical Fixes
2.   Microsoft Pulls Plug on Windows XP
3.   Against a Wall, Some Buy XP Support
4.   Last Fixes Tuesday for XP, Office 2003
5.   Despite Its Age, XP Remains a Favorite


advertisement
Last Fixes Tuesday for XP, Office 2003
Microsoft closing out support for two.
Average Rating:
Windows 8 Updates Expected Soon
Using OS feedback, security concerns.
Average Rating:
Microsoft Pulls Plug on Windows XP
Third-party workarounds abound.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Network Security Spotlight
Heartbleed Could Cost Millions, Could Have Been Prevented
Early estimates of Heartbleed’s cost to enterprises are running in the millions. The reason: revoking all the SSL certificates the bug exposed will come at a very hefty price. Some say it all could have been avoided.
 
Michaels Says Nearly 3M Credit, Debit Cards Breached
Arts and crafts retail giant Michaels Stores has confirmed that a data breach at its POS terminals from May 2013 to Jan. 2014 may have exposed nearly 3 million customer credit and debit cards.
 
Google's Street View Software Unravels CAPTCHAs
The latest software Google uses for its Street View cars to read street numbers in images for Google Maps works so well that it also solves CAPTCHAs, those puzzles designed to defeat bots.
 

Enterprise Hardware Spotlight
Vaio Fit 11A Battery Danger Forces Recall by Sony
Using a Sony Vaio Fit 11A laptop? It's time to send it back to Sony. In fact, Sony is encouraging people to stop using the laptop after several reports of its Panasonic battery overheating.
 
Continued Drop in Global PC Shipments Slows
Worldwide shipments of PCs fell during the first three months of the year, but the global slump in PC demand may be easing, with a considerable slowdown from last year's drops.
 
Google Glass Finds a Home in Medical Education, Practice
The innovative headpiece may find its niche in markets where hands-free access to data can be a big advantage. Glass experiments for doctors are already under way, with some promising results.
 

Mobile Technology Spotlight
Review: Siri-Like Cortana Fills Windows Phone Gap
With the new Cortana virtual assistant, Windows catches up with Apple's iOS and Google's Android in a major way, taking some of the best parts of Apple's and Google's virtual assistants, with new tools too.
 
With Galaxy S5, Samsung Proves Less Can Be More
Samsung has produced the most formidable rival yet to the iPhone 5s: the Galaxy S5. The device is the fifth edition of the company's successful line of Galaxy S smartphones, and shows less can be more.
 
Facebook Rolls Out Potentially Intrusive Location-Sharing
Looking for friends? Facebook users in the U.S. will soon be able to see which of their friends are nearby, using a smartphone's GPS. Could be a cool feature in some cases, or way too much information.
 

Navigation
Enterprise Security Today
Home/Top News | Network Security | Viruses & Malware | Hackers | Security Solutions | Mobile Security | Disaster Recovery | Windows Security
Data Security | EST Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2014 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.