« Virtualize Servers To Save Big... | Main | Data Security Bill Pops Up Again In Congress »

Software Security Problems: Should you be concerned?

Yet another software security problem has been reported. As of the time it was reported, there was no fix from the manufacturer. The software manufacturer in this case turns out to be Microsoft.

Don't get the impression that just because Microsoft problems are reported often that Microsoft is the only company with problems. All software is the product of imperfect human intellect, and is...therefore...imperfect. Microsoft just gets the bulk of the press because they sell a lot of software. So when a defect like this finds its way into a Microsoft product, it affects a lot of people.

Here's a quote from the eWeek article:

Zero-day refers to a flaw for which there is an exploit but no available fix. The Excel vulnerability is Microsoft's fifth zero-day exploit since December, and part of an increasingly troubling trend.

The zero-day flaw affects Office versions 2000, XP, 2003 and 2004 for the Mac, but not 2007 or Works 2004, 2005 or 2006.

An attacker could exploit the flaw either by enticing a user to click on a file hosted on a Web site or an attachment sent via e-mail. Either exploit would require some end-user interaction.

New Zero-Day Threat Excels

91x17-digg-button.png

TrackBack

TrackBack URL for this entry:
http://www.4dgg.com/mt-admin/mt-tb.cgi/162

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

About

This page contains a single entry from the blog posted on February 7, 2007 4:12 PM.

The previous post in this blog was Virtualize Servers To Save Big....

The next post in this blog is Data Security Bill Pops Up Again In Congress.

Many more can be found on the main index page or by looking through the archives.

Creative Commons License
This weblog is licensed under a Creative Commons License.
Powered by
Movable Type 3.34