Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
One Patch to Rule Them All
Tim Mullen, 2002-09-30

A recent XP security hole begs the question, do we really want Microsoft to release individual fixes for every bug?

Comments Mode:
One Patch to Rule Them All 2002-09-30
Anonymous (1 replies)
One Patch to Rule Them All 2002-10-08
Anonymous
Security patchs are diffrent 2002-09-30
Anonymous
One Patch to Rule Them All 2002-10-01
Anonymous (1 replies)
One Patch to Rule Them All 2002-10-02
Anonymous
One Patch to Rule Them All 2002-10-01
Anonymous
One Patch to Rule Them All 2002-10-01
Anonymous
RE: One Patch to Rule Them All 2002-10-01
Piroufreek
One Patch to Rule Them All 2002-10-01
Anonymous (1 replies)
One Patch to Rule Them All 2002-10-04
Anonymous
One Patch to Rule Them All 2002-10-01
Anonymous
You analyse the problem backward : the need is not to break an existing service pack for a partial security update. The need is for a faster single patch which will be consolidated later in a global service pack.

Each time a weakness is exposed, Microsoft should fixe it faster than they are doing right now. A first patch like GRC's one should be their first answer.

Next, if the fix is sufficient for solving the problem, it should be consolidated in the service pack as is. If the fix is not complete, as you suggest for this specific case, the service pack should remove it and replace it with a complete solution developped on a longer period.

At the end, users can protect themselves faster, in a more efficient way, and the service pack will consolidate many smaller fixes or major changes like those required for the help center.

In this case, Microsoft skip the first step. Re-doing it after the second and third is not logical. This don't means that the first step was not needed, like you suggest it. Microsoft must do their job, which include the quick fix first, a deep analysis for confirming it is enough or developping a more complete solution, and finally concatenate all durable fixes in their service pack.

Not doing any of this step reduces the security on the user side.
Not doing the first lets them expose to known exploits, just as they did this time.
Not doing the second does not solve the entire problem.
Not doing the last produces a too large set of fixes for sysadmin.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/112/16656#16656
One Patch to Rule Them All 2002-10-01
Todd Knarr
One Patch to Rule Them All 2002-10-02
security@NOdsia.SPAM.com
One Patch to Rule Them All 2002-10-03
Darkphyber
One Patch to Rule Them All 2002-10-03
iDENTiTY
One Patch to Rule Them All 2002-10-04
Anonymous
He should have called this article "Flame Bait"... 2002-10-09
Anonymouse (1 replies)
"Flame Bait" 2002-10-09
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus