Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Zero-day WMF flaw underscores patch problems
Robert Lemos, SecurityFocus 2006-01-12

For four days in January, network administrators and security-savvy home users had a choice: Download and install an unofficial open-source fix for the critical flaw in the Windows Meta File (WMF) format or wait an estimated week for an official patch from Microsoft.

Comments Mode:
What Microsoft needs to be doing... 2006-01-12
Eric (2 replies)
Re: What Microsoft needs to be doing... 2006-01-13
Matthew Murphy (1 replies)
Re: Re: What Microsoft needs to be doing... 2006-01-13
Eric
No, I can't believe that they're driven by large customers. At least when I worked there that was not the case. Neither were they driven by small customers.

I've NOT in favor of "they should audit and review, and not work on new code". What I said was, "an inordinate amount of their resources are spent on Vista..." I base this on the fact that their current reputation in terms of security on their shipping products is awful.

What I would suggest is that they rebalance their development efforts. If the current ratio of Vista:XP devs is 20:1, make it 20:3 or 20:4. Don't get on the "all we care about is the next product" bandwagon that drives software companies into not fixing the crap they produce.

-Eric

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/11368/32960#32960
Alternative solution 2006-01-13
mxb (2 replies)
Re: Alternative solution 2006-01-13
DSMatthews
Re: Alternative solution 2006-01-13
Anonymous
Make'em pay! 2006-01-13
assurbanipal
The Squander of MS Admins && Users 2006-01-13
Anonymous (1 replies)
Re: The Squander of MS Admins && Users 2006-01-16
Anonymous (1 replies)
Does any one see this 2006-01-13
Anonymous
Patch from Guilfanov was not the only one 2006-01-16
Juha-Matti Laurio







 

Privacy Statement
Copyright 2009, SecurityFocus