, SecurityFocus 2006-01-12
For four days in January, network administrators and security-savvy home users had a choice: Download and install an unofficial open-source fix for the critical flaw in the Windows Meta File (WMF) format or wait an estimated week for an official patch from Microsoft.
Expand all |
Post comment
The Squander of MS Admins && Users
2006-01-13
Anonymous (1 replies)
Anonymous (1 replies)

Further, I think this vulnerability shows how flawed the "they should audit and review, and not work on new code" argument is. Developers of other technologies (i.e., wine) missed the same erroneous feature in their own implementation of Windows Metafile support.
Further, in a codebase as large as that of Windows, being secure "for the most part" may mean leaving several dozen holes. An attacker finds one before you do... and you're just as hosed as you would be today.
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/articles/11368/32952#32952