<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>ZDNet: Missing Microsoft patch leaves critical vulnerability in Security</title>
<link>http://www.dslreports.com/forum/r20956014</link>
<description></description>
<language>en</language>
<pubDate>Fri, 04 Dec 2009 05:04:00 EDT</pubDate>
<lastBuildDate>Fri, 04 Dec 2009 05:04:00 EDT</lastBuildDate>

<item>
<title>Re: ZDNet: Missing Microsoft patch leaves critical vulnerability</title>
<link>http://www.dslreports.com/forum/remark,20970218</link>
<description><![CDATA[<A HREF="/useremail/u/879997"><b>dadkins</b></A> : <div class="bquote"><small>said by  Cabal <A HREF="/useremail/u/1432955"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br><div class="bquote"><small>said by  dadkins <A HREF="/useremail/u/879997"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Maybe I'm alone in this, but I would much rather have a patch that works and doesn't break something than have them push one that might be screwed up.<br>Been there before, no thanks! <br>How many of y'all have seen a patch screw something up?  :huh:<br><br>They can keep that patch and FIX IT before I install it and it breaks/loses/kills something.<br><br>YMMV<br> </div>People aren't asking for a broken patch. People are asking for <b>information</b> on what specifically is vulnerable and how they can protect themselves in the absence of a patch. Microsoft isn't obliging.<br> </div>Cool! <br>But, since it appears to be a WMP issue/patch, *I'm* not too worried about it.<br>What people should be asking is what else is vulnerable and workarounds for them.<br><br>Remember the WMF "thing"?<br>People were peeing themselves over it to the point of applying a patch from a more or less unknown source.<br><br>Don't get me wrong, bad is bad.<br>But as I stated, I would rather wait and get the right one and I'm not going to get worked up over a Media Player problem.  ;)<br>I'll uninstall or kill WMP first!<br><br>Does anyone have a screenie or copy of that original report?<br>Got a number to the KB?<br><br>Thanks! :)<br><small>--<br>Think outside the Fox... <A HREF="http://www.opera.com/">Opera</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20970218</guid>
<pubDate>Mon, 18 Aug 2008 17:34:40 EDT</pubDate>
</item>

<item>
<title>Re: ZDNet: Missing Microsoft patch leaves critical vulnerability</title>
<link>http://www.dslreports.com/forum/remark,20968254</link>
<description><![CDATA[<A HREF="/useremail/u/668609"><b>EGeezer</b></A> : <div class="bquote"><small>said by  dadkins <A HREF="/useremail/u/879997"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>... I would much rather have a patch that works and doesn't break something than have them push one that might be screwed up.<br>Been there before, no thanks! <br>How many of y'all have seen a patch screw something up?  :huh:<br><br>They can keep that patch and FIX IT before I install it and it breaks/loses/kills something.<br><br></div>I agree wholeheartedly. As I said in my OP, <br><div class="bquote"><small>said by  EGeezer <A HREF="/useremail/u/668609"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>While it's goodness to remove flawed patches, the vulnerabilty information and workarounds(if any) should not also be removed.<br></div>I just don't believe that it's goodness to remove the public notice with overview and status and workaround(if any). <br><br>On a positive note, this incident did give us a bit of insight on how Microsoft wants to handle its vulnerability notification to affected users. In this case, if there's no patch or the patch needs rework, remove all useful user information on the warning and leave users in the dark. <br><small>--<br>The greatest dangers to liberty lurk in insidious encroachment by men of zeal, well-meaning but without understanding. -- Justice Louis D. Brandeis</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20968254</guid>
<pubDate>Mon, 18 Aug 2008 11:38:41 EDT</pubDate>
</item>

<item>
<title>Re: ZDNet: Missing Microsoft patch leaves critical vulnerability</title>
<link>http://www.dslreports.com/forum/remark,20968186</link>
<description><![CDATA[<A HREF="/useremail/u/1432955"><b>Cabal</b></A> : <div class="bquote"><small>said by  dadkins <A HREF="/useremail/u/879997"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Maybe I'm alone in this, but I would much rather have a patch that works and doesn't break something than have them push one that might be screwed up.<br>Been there before, no thanks! <br>How many of y'all have seen a patch screw something up?  :huh:<br><br>They can keep that patch and FIX IT before I install it and it breaks/loses/kills something.<br><br>YMMV<br> </div>People aren't asking for a broken patch. People are asking for <b>information</b> on what specifically is vulnerable and how they can protect themselves in the absence of a patch. Microsoft isn't obliging.<br><small>--<br>Interested in <A HREF="http://www.romraider.com/">open source engine management</a> for your Subaru?</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20968186</guid>
<pubDate>Mon, 18 Aug 2008 11:24:13 EDT</pubDate>
</item>

<item>
<title>Re: ZDNet: Missing Microsoft patch leaves critical vulnerability</title>
<link>http://www.dslreports.com/forum/remark,20968102</link>
<description><![CDATA[<A HREF="/useremail/u/879997"><b>dadkins</b></A> : They removed the "patch" because of a last minute quality issue?<br>As in, it may be a fried patch?<br><br>Maybe I'm alone in this, but I would much rather have a patch that works and doesn't break something than have them push one that might be screwed up.<br>Been there before, no thanks! <br>How many of y'all have seen a patch screw something up?  :huh:<br><br>They can keep that patch and FIX IT before I install it and it breaks/loses/kills something.<br><br>YMMV<br><small>--<br>Think outside the Fox... <A HREF="http://www.opera.com/">Opera</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20968102</guid>
<pubDate>Mon, 18 Aug 2008 11:09:54 EDT</pubDate>
</item>

<item>
<title>Re: ZDNet: Missing Microsoft patch leaves critical vulnerability</title>
<link>http://www.dslreports.com/forum/remark,20968017</link>
<description><![CDATA[<A HREF="/useremail/u/668609"><b>EGeezer</b></A> : Would you provide us with the missing WMP vulnerability information too? We'd like to know what the workaround to that unpatched vulnerability is. I doubt you'll provide that, but it's worth asking anyway. <br><br>As of the time of the OP, Microsoft has chosen to remove form public access and hide the vulnerability notice,threat evaluation and workaround from users, so I'll use Media Player Classic simply because it's lower profile and less of a target than WMP. <br><small>--<br>The greatest dangers to liberty lurk in insidious encroachment by men of zeal, well-meaning but without understanding. -- Justice Louis D. Brandeis</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20968017</guid>
<pubDate>Mon, 18 Aug 2008 10:55:22 EDT</pubDate>
</item>

<item>
<title>Re: ZDNet: Missing Microsoft patch leaves critical vulnerability</title>
<link>http://www.dslreports.com/forum/remark,20967594</link>
<description><![CDATA[<A HREF="/useremail/u/634007"><b>SUMware</b></A> : Everyone should read this thread:<br>&raquo;<A HREF="/forum/r20967186-critical-flaw-found-in-the-latest-VLC-player-086i">critical flaw found in the latest VLC player 0.8.6i</A><br>You will see there that matunga has intentionally altered the advisory to suit has agenda, and has lied and falsified information.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20967594</guid>
<pubDate>Mon, 18 Aug 2008 09:29:54 EDT</pubDate>
</item>

<item>
<title>Re: ZDNet: Missing Microsoft patch leaves critical vulnerability</title>
<link>http://www.dslreports.com/forum/remark,20967577</link>
<description><![CDATA[<A HREF="/useremail/u/1432955"><b>Cabal</b></A> : Edit: Nevermind, not feeding them.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20967577</guid>
<pubDate>Mon, 18 Aug 2008 09:27:07 EDT</pubDate>
</item>

<item>
<title>Re: ZDNet: Missing Microsoft patch leaves critical vulnerability</title>
<link>http://www.dslreports.com/forum/remark,20967182</link>
<description><![CDATA[<A HREF="/useremail/u/847301"><b>matunga</b></A> : <div class="bquote"><small>said by  SUMware <A HREF="/useremail/u/634007"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>          :</small><br><br>Those wishing to explore a free and excellent replacement for WMP can look at the <A HREF="http://www.videolan.org/">VideoLAN - VLC media player</a>.<br> </div>VLC has an unpatched security flaw, the exploit is public:  :)<br>VLC Media Player Integer Overflow <br>&raquo;<A HREF="http://secunia.com/advisories/31512/" >secunia.com/advisories/31512/</A><br><i>Description:<br>g_ has discovered a vulnerability in VLC Media Player, which can be exploited by malicious people to compromise a user's system. Successful exploitation may allow execution of arbitrary code.<br><i><br>&raquo;<A HREF="http://www.orange-bat.com/adv/2008/adv.08.16.txt" >www.orange-bat.com/adv/2008/adv.08.16.txt</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20967182</guid>
<pubDate>Mon, 18 Aug 2008 05:40:20 EDT</pubDate>
</item>

<item>
<title>Re: ZDNet: Missing Microsoft patch leaves critical vulnerability</title>
<link>http://www.dslreports.com/forum/remark,20966383</link>
<description><![CDATA[<A HREF="/useremail/u/352846"><b>antdude</b></A> : <div class="bquote"><small>said by  SUMware <A HREF="/useremail/u/634007"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Those wishing to explore a free and excellent replacement for WMP can look at the <A HREF="http://www.videolan.org/">VideoLAN - VLC media player</a>.<br><br><i>VideoLAN is a software project, which produces free and open source software for video, released under the GNU General Public License.<br><br>VLC media player is a highly portable multimedia player for various audio and video formats (MPEG-1, MPEG-2, MPEG-4, DivX, mp3, ogg, ...) as well as DVDs, VCDs, and various streaming protocols.<br><br>It can also be used as a server to stream in unicast or multicast in IPv4 or IPv6 on a high-bandwidth network.<br>It doesn't need any external codec or program to work.</i><br><br>BTW - it doesn't spy on its users.<br> </div>Also, Media Player Classic with K-Lite Codecs: &raquo;<A HREF="http://www.codecguide.com/" >www.codecguide.com/</A><br><small>--<br>Ant @ &raquo;<A HREF="http://antfarm.ma.cx" >antfarm.ma.cx</A> and &raquo;<A HREF="http://aqfl.net" >aqfl.net</A>. Please do not IM/e-mail me for technical support. Use the forum! Disclaimer: The views expressed in this posting are mine, and do not necessarily reflect the views of my employer</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20966383</guid>
<pubDate>Sun, 17 Aug 2008 22:54:56 EDT</pubDate>
</item>

<item>
<title>Re: ZDNet: Missing Microsoft patch leaves critical vulnerability</title>
<link>http://www.dslreports.com/forum/remark,20960390</link>
<description><![CDATA[<A HREF="/useremail/u/634007"><b>SUMware</b></A> : Those wishing to explore a free and excellent replacement for WMP can look at the <A HREF="http://www.videolan.org/">VideoLAN - VLC media player</a>.<br><br><i>VideoLAN is a software project, which produces free and open source software for video, released under the GNU General Public License.<br><br>VLC media player is a highly portable multimedia player for various audio and video formats (MPEG-1, MPEG-2, MPEG-4, DivX, mp3, ogg, ...) as well as DVDs, VCDs, and various streaming protocols.<br><br>It can also be used as a server to stream in unicast or multicast in IPv4 or IPv6 on a high-bandwidth network.<br>It doesn't need any external codec or program to work.</i><br><br>BTW - it doesn't spy on its users.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20960390</guid>
<pubDate>Sat, 16 Aug 2008 14:27:25 EDT</pubDate>
</item>

<item>
<title>Re: ZDNet: Missing Microsoft patch leaves critical vulnerability</title>
<link>http://www.dslreports.com/forum/remark,20960097</link>
<description><![CDATA[<A HREF="/useremail/u/1537340"><b>Smokey Bear</b></A> : <div class="bquote"><small>said by  EGeezer <A HREF="/useremail/u/668609"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Thanks for putting out the word -</div>Spreading the word is part of our job: informing and advising the user. ;)<br><div class="bquote"> and for the attribution! :) </div>All credits to you, after all you was the one that took my attention to the WMP non-patch issue :)<br><small>--<br>Smokey's Security Forums &raquo;<A HREF="http://www.smokey-services.eu/forum/" >www.smokey-services.eu/forum/</A><br>Smokey's Security Weblog &raquo;<A HREF="http://smokeys.wordpress.com/" >smokeys.wordpress.com/</A><br>ASAP Site Member &raquo;<A HREF="http://asap.maddoktor2.com" >asap.maddoktor2.com</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20960097</guid>
<pubDate>Sat, 16 Aug 2008 13:10:29 EDT</pubDate>
</item>

<item>
<title>Re: ZDNet: Missing Microsoft patch leaves critical vulnerability</title>
<link>http://www.dslreports.com/forum/remark,20959819</link>
<description><![CDATA[<A HREF="/useremail/u/668609"><b>EGeezer</b></A> : Thanks for putting out the word - and for the attribution! :) <br><br>Edit - BTW re: the linked article in your blog - I've seen MPLAYER2 on the system, but never messed with it. Looks like it could do nicely for those who like Windows player but don't want all the crapola the later versions throw in..]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20959819</guid>
<pubDate>Sat, 16 Aug 2008 11:51:38 EDT</pubDate>
</item>

<item>
<title>Re: ZDNet: Missing Microsoft patch leaves critical vulnerability</title>
<link>http://www.dslreports.com/forum/remark,20959134</link>
<description><![CDATA[<A HREF="/useremail/u/1537340"><b>Smokey Bear</b></A> : <div class="bquote"><small>said by  EGeezer <A HREF="/useremail/u/668609"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Since the information on the missing patch was removed in the advisory, we as users only know that there's a critical vulnerability in WMP out there that's still unpatched, and have no workaround or precautions to take beyond simply not using WMP.</div>Txs for this useful info, i used the info in your post to blog about the issue and adviced accordingly: &raquo;<A HREF="http://smokeys.wordpress.com/2008/08/16/advice-dont-use-wmp-windows-media-player-anymore/" >smokeys.wordpress.com/2008/08/16&middot;&middot;&middot;anymore/</A><br><small>--<br>Smokey's Security Forums &raquo;<A HREF="http://www.smokey-services.eu/forum/" >www.smokey-services.eu/forum/</A><br>Smokey's Security Weblog &raquo;<A HREF="http://smokeys.wordpress.com/" >smokeys.wordpress.com/</A><br>ASAP Site Member &raquo;<A HREF="http://asap.maddoktor2.com" >asap.maddoktor2.com</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20959134</guid>
<pubDate>Sat, 16 Aug 2008 06:51:10 EDT</pubDate>
</item>

<item>
<title>Re: ZDNet: Missing Microsoft patch leaves critical vulnerability</title>
<link>http://www.dslreports.com/forum/remark,20959045</link>
<description><![CDATA[<A HREF="/useremail/u/1371265"><b>daveinpoway</b></A> : I suppose Microsoft could release this patch "out-of-cycle", instead of waiting for September's "Patch Tuesday", but I have no clue as to whether they will do this.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20959045</guid>
<pubDate>Sat, 16 Aug 2008 04:51:28 EDT</pubDate>
</item>

<item>
<title>ZDNet: Missing Microsoft patch leaves critical vulnerability</title>
<link>http://www.dslreports.com/forum/remark,20956014</link>
<description><![CDATA[<A HREF="/useremail/u/668609"><b>EGeezer</b></A> : I was intrigued by <A HREF="http://blogs.technet.com/msrc/archive/2008/08/12/august-2008-monthly-bulletin-release.aspx"><b>this Microsoft Technet blog entry</b></a>, which referenced a patch that was not released for quality reasons. However, the poster did not provide any information on what was missing or what measures users could take until the patch was issued. While it's goodness to remove flawed patches, the vulnerabilty information and workarounds(if any) should not also be removed. <br> <br><div class="bquote"><small>said by blog entry :</small><br><br>You may notice that we removed one of the bulletins that we had mentioned in the &#147;Advanced Notification Service&#148; that we released last week. We did this prior to today&#146;s bulletin release because of a last minute quality issue.<br></div>The present version <A HREF="http://www.microsoft.com/technet/security/bulletin/ms08-aug.mspx"><b>here </b></a> has omitted all references to it. I guess if they feel if they remove references to the vulnerability, it'll go away.. :D  <br><br>A bit of searching yielded <A HREF="http://blogs.zdnet.com/security/?p=1708"><b>this ZDNet blog article</b></a> which described the missing patch as one to address a critical vulnerability in Windows Media Player (WMP). <br><div class="bquote"><small>said by blog entry :</small><br><br>Lost in the shuffle of this month&#146;s Patch Tuesday barrage is the fact that a critical vulnerability in the ever-present Windows Media Player (WMP) was not fixed &#147;because of a last minute quality issue.&#148;<br><br>Microsoft originally listed the WMP update in the advance notice for August but, when the patches dropped on Tuesday, it had slipped because of patch-quality concerns.<br><br>The explanation from Redmond:<br><br>    * Microsoft has heard from customers that the quality of updates is very important and, as part of the process at the Microsoft Security Response Center (MSRC), Microsoft tests these updates continuously until they are ready for distribution to customers through our regularly scheduled security bulletin release.<br><br>This effectively means that millions of Windows users &#151; WMP ships with every version of the desktop operating system &#151; are exposed to a critical, code execution vulnerability that will not be fixed for at least another month.<br></div>The ZDNET article goes on to enumerate several other unpatched vulnerabilities. <br><br>Since the information on the missing patch was removed in the advisory, we as users only know that there's a critical vulnerability in WMP out there that's still unpatched, and have no workaround or precautions to take beyond simply not using WMP. <br><br>Any specific information for affected users, including workarounds, is welcome. <br><small>--<br>The greatest dangers to liberty lurk in insidious encroachment by men of zeal, well-meaning but without understanding. -- Justice Louis D. Brandeis</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20956014</guid>
<pubDate>Fri, 15 Aug 2008 14:45:57 EDT</pubDate>
</item>

</channel>
</rss>
