
"Everything with this Microsoft IE debacle was mistake after mistake"
By Joris Evers
Published: 25 August 2006 08:45 GMT
Microsoft has released an updated version of a faulty Internet Explorer patch to fix a serious security flaw introduced by the original version.
The flaw was discovered after users of IE 6 with Service Pack 1 reported that the browser crashed when certain web pages were viewed. That crash turned out to be the result of a buffer overrun vulnerability introduced by the security update, Microsoft said earlier this week. The flaw could be exploited by cyber attackers, it said.
A Microsoft representative said in a statement sent via email on Thursday: "The revised version [of the update]... fully resolves the security vulnerability."
The company originally set Tuesday for the release of a new version of the MS06-042 update that would fix the browser crash problem. However, it postponed delivery because of distribution problems. At the same time, eEye Digital Security disclosed that the crash was actually an exploitable security flaw, sending Microsoft scrambling to push the fixed patch out as soon as possible.
Stephen Toulouse, a Microsoft Security Response programme manager, said in an interview: "Certainly, those are two events that we wish had not occurred but we are learning from those situations, and we're going to work to make sure they don't happen again."
Microsoft sent out the initial MS06-042 security bulletin on 8 August, as part of its monthly patch cycle. The update, deemed "critical" by Microsoft, addresses eight flaws in the widely used browser. It is one of a dozen security updates in this month's Patch Tuesday batch.
Marc Maiffret, chief technology officer at eEye Digital Security, which discovered the security bug introduced by Microsoft's patch, said: "Everything with this Microsoft IE debacle was mistake after mistake. I would have to question who was in charge of strategy at Microsoft for the handling of this situation."
The patch trouble and the security issue only have an impact on users of IE 6.0 with SP1, which may run on Windows XP or Windows 2000. They do not affect other versions of IE, such as that in Windows XP with SP2 or in Windows Server 2003, Microsoft said. The company is urging affected users to download and install the new patch.
Already, the team that develops IE has documented the chain of events, including the code created by the developer who crafted the initial patch, Toulouse said. "They changed some of their tools and procedures," he said.
The developer responsible for the gaffe can expect to be held accountable, he added. "There are definite ramifications for situations like this," he said.
However, it is unclear what action will be taken. Toulouse said: "It is very complex." An investigation into the error is ongoing.
There has been some debate about the reason behind the delay to the updated patch. Microsoft postponed it because of an error that would prevent certain patch management applications from distributing it, Toulouse said. The error was in the associated '.cab' file that contains update details used by those applications.
The patch would have been available on Windows Update and through patch management applications that do not use the '.cab' file but users of Microsoft's patch management tools and other third-party tools would not have been able to deploy it, he said. These tools are used by organisations to do automated patch installations on multiple computers.
Toulouse said: "Our goal is to protect all customers at the same time, and if we run into a situation where there is going to be a significant number of customers who are unable to deploy the update, we can't leave those customers behind."
Joris Evers writes for CNET News.com
Must hold a current driving licence DESIRABLE Juniper SSL VPN RSA SecurID MailSweeper WSUS and patch management Ironport Web Content Filteringo ...
Title: Web Applications Vulnerability Tester / Penetration Tester Salary: market rates but probably 40k to 60k Company: online / ecommerce company ...
Your responsibilities will include; Proactive Server Maintenance through monitoring and patch management and deployment Installation, configuration ...
Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
Tim Ferguson Exclusive: Former MySQL boss Marten Mickos talks open source Why Microsoft could become one of the "biggest friends of open source" and why Oracle getting its hands on MySQL could be "one of the biggest open source coups ever"...
Naked CIO Naked CIO: Cloud computing more expensive than we thought? Smart IT leaders will examine the impact of how they pay for tech