Re: My MS04-028 FAQ

From: Karl Levinson [x y] mvp (levinson_k_at_despammed.com)
Date: 09/16/04


Date: Wed, 15 Sep 2004 23:02:49 -0400

It's a confusing bulletin, but mainly because the underlying technologies
and steps required to patch are confusing. The bulletin itself is I think
as usual pretty well written, except that it's so long it's hard to fully
grasp all the issues even after several readings.

Microsoft released a tool to help users find vulnerable files to try to ease
your pain at trying to scan products that Windows Update won't scan. There
are plenty of third party programs [Macromedia software like Flash, WS_FTP,
etc.] that include the vulnerable gdiplus.dll file. If you're blaming
Microsoft and asking them to be able to scan for all those third party
products, that's just never going to happen, in any OS.

MS has heard the complaint that patching is too painful and has made and
continues to make improvements. Granted, it's still painful and it's too
bad those improvements aren't all ready today.

"an_anonymous_opinion" <anonymous@discussions.microsoft.com> wrote in
message news:027d01c49b50$43a285b0$a301280a@phx.gbl...
>-----Original Message by Robb-----<
>The instructional text in this latest MS04-028 Security
>Bulletin seems totally ridiculous for anyone trying to
>effect patch management on more than 3 PC's.
<[message truncated]

I agree 100%: Microsoft really dropped the ball on this
one. It's a completely sloppy and confusing bulletin.

To make matters worse, it would seem Microsoft left all
the work to the user(s) instead of Microsoft doing the
scanning and patching. Why are user(s) stuck doing the
manual labor of patching this and that for products THEY
paid for?

Enjoy those piņa coladas, Mr. Gates.



Relevant Pages

  • Re: Russ Coopers AusCERT Presentation on MS Security Bulletins
    ... We use SMS Server for patch management, and like you said, it's not MS ... I know Russ likes to slam Microsoft whenever he can, ... Patching is a fact of life, ... Patch Automation v6.0 by Mobile Automation, ...
    (NT-Bugtraq)
  • RE: [Full-Disclosure] Support the Sasser-author fund started
    ... > the worm come out AFTER the patch? ... > patched it sooner so that the worm could have come out sooner. ... > The biggest question I have is why all the hostility at Microsoft ... ms is patching a hole but manages to break other things in the process quite frequently. ...
    (Full-Disclosure)