Tuesday, January 03, 2006

Oompa Loompas in Redmond?

I didn't read much work related email over Christmas but I did follow the Windows Metafile vulnerability story as it played out. I thought it was interested as this isn't really a bug but a feature being taken advantage of - in a way it wasn't really meant to be. Microsoft has announced that a patch will be available as part of the usual Patch Tuesday monthly release. Given how critical this issue is it seems that this is a long time to wait.

The SANS ISC has been doing a great job in covering this event. Up to date reports, 'unofficial' patch testing, and even the discussion of a oxymoron.

Nice thing about this - Mozilla Thunderbird/Firefox users get prompted to open files that may have a ulterior motive...

