新书推介:《语义网技术体系》
作者:瞿裕忠,胡伟,程龚
   XML论坛     W3CHINA.ORG讨论区     计算机科学论坛     SOAChina论坛     Blog     开放翻译计划     新浪微博  
 
  • 首页
  • 登录
  • 注册
  • 软件下载
  • 资料下载
  • 核心成员
  • 帮助
  •   Add to Google

    >> 最新的技术动态
    [返回] 计算机科学论坛休息区『 最新动态 & 业界新闻 』 → Microsoft leaves some Office XP users patchless 查看新帖用户列表

      发表一个新主题  发表一个新投票  回复主题  (订阅本版) 您是本帖的第 5013 个阅读者浏览上一篇主题  刷新本主题   树形显示贴子 浏览下一篇主题
     * 贴子主题: Microsoft leaves some Office XP users patchless 举报  打印  推荐  IE收藏夹 
       本主题类别:     
     卷积内核 帅哥哟,离线,有人找我吗?
      
      
      威望:8
      头衔:总统
      等级:博士二年级(版主)
      文章:3942
      积分:27590
      门派:XML.ORG.CN
      注册:2004/7/21

    姓名:(无权查看)
    城市:(无权查看)
    院校:(无权查看)
    给卷积内核发送一个短消息 把卷积内核加入好友 查看卷积内核的个人资料 搜索卷积内核在『 最新动态 & 业界新闻 』的所有贴子 访问卷积内核的主页 引用回复这个贴子 回复这个贴子 查看卷积内核的博客楼主
    发贴心情 Microsoft leaves some Office XP users patchless

    For the second time in nine months, Microsoft said it would not patch a vulnerability in an older product because creating a fix was "infeasible."

    The omission leaves users running Office XP vulnerable to attack unless they take additional steps on their own.

    Office XP, which debuted in March 2001, remains on Microsoft's list of supported suites -- users will continue to receive security updates through mid-July 2011. But on Tuesday, Microsoft said a COM (component object model) validation vulnerability in the aged suite couldn't be patched.

    The decision was explained in one of the 10 updates Microsoft issued yesterday that patched a record-tying 34 vulnerabilities.

    "The architecture to properly support the fixes to correct validation does not exist on Microsoft Office XP, making it infeasible to build the fixes for Microsoft Office XP products to eliminate the vulnerability," said Microsoft in the MS10-036 security bulletin. "To do so would require rearchitecting a very significant amount of the Microsoft Office XP products, not just the affected components."

    Even if it managed to rework Office XP, Microsoft said the effort would "sufficiently introduce an incompatibility with other applications that there would be no assurance that these Microsoft Office products would continue to operate as designed."

    "This is another example of old software showing its age," said Amol Sarwate, the manager of Qualys' vulnerabilities research lab. "The interdependencies of those [.dll files] is almost impossible to patch without upgrading the whole platform."

    Instead of an actual patch, Microsoft urged Office XP users to download and run an automated tool from its "Fit it" library. The tool, said Microsoft, "provides similar protections against the vulnerability" as the patch offered to people running Office 2003 and Office 2007.

    "Microsoft built a shim to protect Office XP," said Richie Lai, Qualys' director of vulnerability research. "It's a workaround, but Microsoft's not fixing the vulnerable code.

    The Fix it shim can be downloaded from Microsoft's support site.

    This was the second time since September 2009 that Microsoft has passed on providing a patch. Then, Microsoft declined to patch two bugs in the implementation of TCP/IP in Windows 2000 and Windows XP. TCP/IP is the Web's default suite of connection protocols. Microsoft used the same rationale last September as it did Tuesday to explain why it isn't patching.

    "No, I wouldn't call this a trend," said Sarwate when asked whether the two incidents indicate a decision by Microsoft to refuse to patch older products.

    Additionally, users running Office 2003 or Office 2007 must upgrade those suites before applying Tuesday's patch, Microsoft added. Office 2003 must be at Service Pack 3 (SP3), the latest major update from Microsoft, while Office 2007 must be at SP1 or SP2.

    Microsoft also said that it piggybacked other changes onto the MS10-036 updates for Office 2003 and Office 2007 that address problems that resulted when a Microsoft engineer added a single extraneous "&" character to a critical code development library.

    The company patched Active Template Library (ATL), a code library used by both Microsoft and third-party developers to build software, in an emergency July 2009 update.

    "This update includes a defense-in-depth change ... that helps prevent components and controls built using vulnerable versions of ATL from being exploited in the Microsoft Office products," said Microsoft.

    Although Microsoft didn't tell Office XP users to upgrade, Qualys' researchers did.

    "Older software has the highest number of vulnerabilities," noted Lai. "Of the 14 vulnerabilities in Excel patched [Tuesday in MS10-038] 11 of them applied just to Office XP, but only three to the newer versions."

    Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter


       收藏   分享  
    顶(0)
      




    ----------------------------------------------
    事业是国家的,荣誉是单位的,成绩是领导的,工资是老婆的,财产是孩子的,错误是自己的。

    点击查看用户来源及管理<br>发贴IP:*.*.*.* 2010/6/10 16:14:00
     
     GoogleAdSense
      
      
      等级:大一新生
      文章:1
      积分:50
      门派:无门无派
      院校:未填写
      注册:2007-01-01
    给Google AdSense发送一个短消息 把Google AdSense加入好友 查看Google AdSense的个人资料 搜索Google AdSense在『 最新动态 & 业界新闻 』的所有贴子 访问Google AdSense的主页 引用回复这个贴子 回复这个贴子 查看Google AdSense的博客广告
    2024/4/28 13:49:35

    本主题贴数1,分页: [1]

    管理选项修改tag | 锁定 | 解锁 | 提升 | 删除 | 移动 | 固顶 | 总固顶 | 奖励 | 惩罚 | 发布公告
    W3C Contributing Supporter! W 3 C h i n a ( since 2003 ) 旗 下 站 点
    苏ICP备05006046号《全国人大常委会关于维护互联网安全的决定》《计算机信息网络国际联网安全保护管理办法》
    46.875ms