Microsoft Plans Largest-Ever Patch Tuesday

timothy posted about 5 years ago | from the 24-hours-but-bigger-minutes dept.

Bug 341

CWmike writes "Microsoft said it will deliver its largest-ever number of security updates on Tuesday to fix 13 flaws in every version of Windows, as well as Internet Explorer (IE), Office, SQL Server, important developer tools and Forefront Security client software. Among the updates will be the first for the final, or release to manufacturing, code of Windows 7, Microsoft's newest operating system. The 13 updates slated for next week, eight of them pegged 'critical,' beat the previous record of 12 updates shipped in February 2007 and again in October 2008." Update Reader Kurt Seifried writes to correct the math a bit, pointing to Microsoft's Advance Notification page for the release, which says that rather than 13 flaws, this Patch Tuesday involves "13 bulletins (eight critical and five important), addressing 34 vulnerabilities ... Most of these updates require a restart so please factor that into your deployment planning."

OMG (0)

Anonymous Coward | about 5 years ago | (#29687533)

It's PDAY!!!

Can't be right (1, Insightful)

Anonymous Coward | about 5 years ago | (#29687697)

EVERY version of windows? Including windoze 95? I don't think so!!

It fixes EVERY bug? (0, Troll)

DeadDecoy (877617) | about 5 years ago | (#29687543)

So it installs linux?

Re:It fixes EVERY bug? (2, Funny)

Mr. Roadkill (731328) | about 5 years ago | (#29687565)

So it installs linux?

Yes, and kills problem users.

Re:It fixes EVERY bug? (1)

davester666 (731373) | about 5 years ago | (#29687753)

Does this include Windows 3.1?

Re:It fixes EVERY bug? (4, Funny)

CannonballHead (842625) | about 5 years ago | (#29687805)

Yes, those users, too. ;)

Re:It fixes EVERY bug? (1)

w0mprat (1317953) | about 5 years ago | (#29688165)

So it installs linux?

Yes, and kills problem users.

Those users are not bugs they are a feature

Re:It fixes EVERY bug? (1)

genner (694963) | about 5 years ago | (#29688303)

So it installs linux?

Yes, and kills problem users.

Can't be it says it only fixes 13 flaws. I have more problem users than that.

Re:It fixes EVERY bug? (1)

von_rick (944421) | about 5 years ago | (#29687905)

So it installs linux?

Yes, and it not only provides support for your hardware, but also provides child support and psychiatric support.

Re:It fixes EVERY bug? (0)

Anonymous Coward | about 5 years ago | (#29688143)

Because Linux has no bugs whatsoever? What a retarded comment.

Re:It fixes EVERY bug? (-1)

But will it let me buy stuff using paypal? (4, Interesting)

randy of the redwood (1565519) | about 5 years ago | (#29687561)

I am still worried about using Ebay to buy my star wars collectables from my Chrome Browser - []

The more crap you add... (0)

iamhigh (1252742) | about 5 years ago | (#29687591)

The more likely you are to have errors. I would love to see a chart of patches released over time... anyone put that together yet?

Re:The more crap you add... (3, Insightful)

CannonballHead (842625) | about 5 years ago | (#29687657)

I'd like to see a comparison between the number of patches to Linux vs. Windows. :)

Which do I think is a better OS in terms of security and stability? Linux. But I tend to get tired of the "Microsoft releases so many patches, their OS is obviously bad" argument when the it seems the whole development model of open source software (e.g., Linux distros) is that anyone can develop both features and patches, thus improving the software.

Re:The more crap you add... (0)

Anonymous Coward | about 5 years ago | (#29687713)

There are plenty of such comparisons out there. Windows tends to win with less vulnerabilities, but linux is faster to patch. It is very hard to do an apples to apples comparison though due to linux and windows distributions both shipping vastly different software stacks and programs. A good independent source is if you want to check some of the numbers.

Re:The more crap you add... (0, Flamebait)

Joce640k (829181) | about 5 years ago | (#29688071)

Maybe Linux is "faster" but at least with Windows I won't have to go in and manually recompile my webcam driver when it's finished updating.

Re:The more crap you add... (0)

Anonymous Coward | about 5 years ago | (#29688191)

Another wintard wearing his ignorance on his sleeve like it's a fucking metal. Why don't you have the sense to STFU when the conversation turns to subjects about which you know nothing?

Re:The more crap you add... (5, Insightful)

Penguinisto (415985) | about 5 years ago | (#29687731)

I'd like to see a comparison between the number of patches to Linux vs. Windows. :)

For just the kernel, or for a whole average distro? Which distro's kernel and which variant (e.g. SMP vs. uniprocessor) and which arch? (x86 vs. say, PPC or ARM)? Do we count all the optional modules, and what about the stuff that is out there which could be compiled-in, but usually isn't (e.g. Win4Lin extensions)? Are patches counted as individual diffs checked in to a CVS/SVN/BK repo source tree, or counted only if distributed .rpm/.apt packages by a vendor?

Otherwise, yeah, I can see your POV. :)

Re:The more crap you add... (1)

Penguinisto (415985) | about 5 years ago | (#29687751)

...and yes, I meant to say git and not BK. Stupid brain farts...

Re:The more crap you add... (1)

CannonballHead (842625) | about 5 years ago | (#29687789)

I blindly followed suit..

Re:The more crap you add... (4, Insightful)

CannonballHead (842625) | about 5 years ago | (#29687781)

Fair questions, but easily answered: for whatever is being compared to in a Windows OS. Windows, as I recall, has a kernel, has components that are necessary, has components that are unnecessary, etc. It seems Linux fans easily lapse into thinking that Windows is one complete mess all bound into one, whereas Linux has messy parts but the core is great... but who installs "Linux" and doesn't install a "Linux distro." To be fair to Windows. I'd have to say you'd have to compare an entire Linux distro default installation to an entire Windows default installation... all software included in the iso, not the latest-updated-version-of-Amarok or whatever comes with it by default. Getting the latest Amarok version is just like getting the latest patch for Windows Media Player...

As for CVS/SVN/BK diff's and whatnot, that's hard to come up with... I have no clue how much code differences there are in a given Windows patch. For all I know, it's one single typo, but since it's a binary, the entire thing is built and sent over in the patch, right? So who knows? I would think, from an end-user perspective, it only counts as a patch if it's distributed in an easily installed format; e.g., as an update or as an rpm or included in the distro, etc.

Thanks for seeing my POV. :) hehe. I'm in an unfortunate position for my life on slashdot; I actually enjoy Windows OS's. And Linux distros. Awful, I know.

I don't like AIX though...

Re:The more crap you add... (1)

vxvxvxvx (745287) | about 5 years ago | (#29687963)

all software included in the iso,

You'd still be making an invalid comparison. The normal linux distribution includes multiple tools to do the same tasks. For example, most come packaged with both Gnome and KDE. It's pretty impossible to compare security by number of patches.

Re:The more crap you add... (2, Insightful)

some_guy_88 (1306769) | about 5 years ago | (#29688059)

Also, a lot of patches for linux software are adding new functionality. Not just fixing bugs.

Furthermore, what exactly is contained in one Windows "update"? As far as we know one windows update contains as many changes to the system as dozens of smaller patches in a linux distro.

But yeah, the idea that more released patches = less secure system isn't a very good one.

Re:The more crap you add... (4, Insightful)

jrumney (197329) | about 5 years ago | (#29688109)

The point the GP is trying to make is that they just aren't directly comparable. Limiting yourself to the Linux kernel is unfair to Windows, as Windows is much more than just a kernel. But comparing with a full distribution is unfair to Linux, as there is much more in a distribution than even Windows + Office + SQL Server + everything else that Microsoft Update covers.

Re:The more crap you add... (2)

powerspike (729889) | about 5 years ago | (#29687903)

Well.... ALL of them, as the 13 updates includes office etc as well. Reguardless if it's SMP or uniprocessor, it's apart of the kernel, if it's a kernel patch it has to be counted, otherwise it wouldn't be linux would it? At the end of the day 13 is for everything "in this batch", so if your going to be counting linux bugs, i would count everything you'd consider linux, just because one distro doesn't include one part of the kernel doesn't mean you don't count a patch for it...

Re:The more crap you add... (2, Informative)

dave562 (969951) | about 5 years ago | (#29688209)

The number of patches and whether or not Windows or *nix requires more is pretty much a moot point. Both systems need to be updated regularly and both are vulnerable to automated vulnerability scanners that are being run 24/7 on compromised boxes. I won't re-tell the tale here, but you can check my journal if you want to read about the most recent tale of an Ubuntu box that I setup getting owned in under a month. Any OS that falls behind on patches becomes an exploitable target.

Re:The more crap you add... (1)

jonadab (583620) | about 5 years ago | (#29688271)

> > I'd like to see a comparison between the
> > number of patches to Linux vs. Windows. :)
> For just the kernel, or for a whole average distro?

Neither is at all fair.

Comparing security track records for all of Windows against just the Linux kernel is grossly unfair to Windows, because it's got a good deal more in it than just a kernel, and many of its bugs are in those other components.

But going the other way (an entire distro -- say, Debian) is even more unfair, in the opposite direction, because Windows includes only a *tiny* fraction of all the software in a typical Linux distro.

I suppose it would be possible to pick out a set of open-source packages that approximately corresponds, in functionality, to what comes with Windows out of the box, but it would exclude so much really *basic* stuff (from the perspective of a Linux user) that it would be extremely atypical and not terribly useful or meaningful. I mean, unless you're trying to fit on a floppy disk or something, what would be the point of a Linux distribution that doesn't even include a perl interpreter?

So all in all I'm not sure there's any really meaningful way to compare the number of bugs noted or patches issued.

You *could* compare the average amount of *time* it takes for a fix to be made available once any given (security-relevant) bug is discovered. I think we all have a fair idea which way *that* would turn out.

Re:The more crap you add... (1)

ROMRIX (912502) | about 5 years ago | (#29688187)

I'd like to see a comparison between the number of patches to Linux vs. Windows. :)

A closer comparison would be between the number of patches to Linux vs. My bicycle tire.

Security & Stability (1)

omb (759389) | about 5 years ago | (#29688223)

There is just NO comparison, Linux especially and all UNIX like systems are hugely more correct and stable than Windoze(TM) will ever be. Two reasons:

Bad and sloppy code gets found, fixed qickly, and is met with hoots of derision from other developers.

Certain FEATURES touted as a + for Windoze eg OLE never made it into Unix since their design required the OS to be broken by design and the developers declined to do it.

A couple of days reading LKML will show you how much chance a really bad idea, eg filetype based on extension, has of making its way in.

I run Internet facing machines with no firewall and get to send about 5 days a year fixing problems eg defend the slow ssh attack.

EVERY version of Windows? (4, Funny)

CSMatt (1175471) | about 5 years ago | (#29687613)

Does this mean that my Windows 3.1 box will finally get the DST update?

Re:EVERY version of Windows? (2, Funny)

Kratisto (1080113) | about 5 years ago | (#29688029)

No, you'll have to move to Arizona. Sorry.

...Patch Tuesday (4, Insightful)

steelscalp (1383757) | about 5 years ago | (#29687629)

Last week's "critical updates" were two copies of Windows Genuine Annoyance.

Re:...Patch Tuesday (4, Interesting)

Fluffeh (1273756) | about 5 years ago | (#29687691)

Well, they can be called critical. It's subjective you see. Critical to you as a user, or critical to Microsoft as a business?

Yes, I think there is something in that for all of us, don't you? *puffs pipe*

Re:...Patch Tuesday (3, Insightful)

Entropius (188861) | about 5 years ago | (#29687711)

It's a very good security strategy to piss off all your customers with WGA and Windows Media bullshit until they all turn off automatic updates.

Re:...Patch Tuesday (0)

Anonymous Coward | about 5 years ago | (#29687831)

How exactly does WGA piss off MS customers? I seem to recall it only nags the 'non-customers'.

Re:...Patch Tuesday (4, Insightful)

Elwood P Dowd (16933) | about 5 years ago | (#29687979)

MS requires customers to install the new WGA on a regular basis. That is also nagging.

Re:...Patch Tuesday (5, Interesting)

Anonymous Coward | about 5 years ago | (#29688053)

I built my system myself which means that I'm more than capable of grabbing a bootleg copy of Windows online. Instead I chose to pay for a copy of WinXP because the OS is a MAJOR part of my system and as such was worth the asking price. (And also because I'm not a thieving schmuck. If you don't want to pay use Linux.)

Ever since I've been hounded by WGA. I just want my system patched. Microsoft wants to verify "something", god knows what, every time I try to access patches. Their checker needs updating quite often. I don't know what it does. I don't know what info it sends them. I just know it's an annoyance, maybe a personal security risk. I can't patch without it. (Officially that is. I'm aware of "alternate" patch sources but how secure is that? Seriously now, come on...)

This is the thanks I get for dropping money on their product. I passed on Vista. I'll pass on Win7. Once this system has aged to the point of uselessness (translation: can't game any more) I'm going to Linux full time. Why? BECAUSE THEY ACT AS IF THEY OWN MY MACHINE, NOT ME. THAT pisses me off.

So f--- them. I'm done.

Fire and forget (0, Flamebait)

westlake (615356) | about 5 years ago | (#29688153)

It's a very good security strategy to piss off all your customers with WGA and Windows Media bullshit until they all turn off automatic updates.

The geek is pissed off by what to anyone else is over and done with one or two clicks of the mouse.

Re:...Patch Tuesday (1)

sconeu (64226) | about 5 years ago | (#29688035)

You forgot Office Genuine Annoyance, too.

Why is it critical?

Long Weekend (3, Insightful)

camperdave (969942) | about 5 years ago | (#29687633)

Isn't Tuesday the first day back from a long weekend? Is that really the best time to do this? We'll be up to our eyeballs in password resets already. (How do people forget a password in three days?)

Re:Long Weekend (1)

CannonballHead (842625) | about 5 years ago | (#29687665)

only if you have Monday off! ;)

Re:Long Weekend (5, Insightful)

Fluffeh (1273756) | about 5 years ago | (#29687707)

How do people forget a password in three days?

Because people are stupid. A person is smart, but people are stupid.

One of the most strangely insightful comments in Men in Black from memory.

Re:Long Weekend (0)

Anonymous Coward | about 5 years ago | (#29688199)

But what about "I make this look good"?

Re:Long Weekend (2, Insightful)

flipper9 (109877) | about 5 years ago | (#29688323)

Because people are required to memorize multiple passwords, between many different systems, that have different password construction requirements, require differing expiration dates on passwords. Not to mention each different system has a different login username and sequence. Then you wonder why people write their login information down on a post-it-note on their desk. Too many passwords and usernames lead to greater insecurity. Don't blame them for forgetting a password amongst so many.

Re:Long Weekend (0)

Anonymous Coward | about 5 years ago | (#29687835)

(How do people forget a password in three days?)
When IT implements some policy that requires your password to be 10 characters long, have at least 2 digits, 2 symbols, no consecutive characters can be next to eachother on the keyboard or in alphabetical or reverse alphabetical order, nor can any 3 consecutive characters have ever occured in that order in your last 40 passwords.

Re:Long Weekend (0)

Anonymous Coward | about 5 years ago | (#29687873)

Password Safe []

Re:Long Weekend (1)

jrumney (197329) | about 5 years ago | (#29688091)

Don't forget "no dictionary words to appear anywhere within the password".

Re:Long Weekend (1)

Azureflare (645778) | about 5 years ago | (#29687847)

"It's hard to remember a password when it isn't written down!"

I'll bet you hear that a lot.

Re:Long Weekend (0)

Anonymous Coward | about 5 years ago | (#29687859)

whoa, dude, Canada-centric much?

Re:Long Weekend (0)

Anonymous Coward | about 5 years ago | (#29687929)

It's not a long weekend for the majority of people you nitwit. Especially not "Microsoft central" (that would be the US).

What's the Canadian holiday? (1)

XanC (644172) | about 5 years ago | (#29688031)

Here in the US it'll be Columbus Day. nitwit.

Re:Long Weekend (3, Insightful)

PrimaryConsult (1546585) | about 5 years ago | (#29688057)

How do people forget a password in three days?

Duh, the janitor who comes in on holidays keeps throwing out the post-its taped to the monitors!

Windows 2000? (2, Interesting)

Azureflare (645778) | about 5 years ago | (#29687639)

I'm guessing windows 2000 isn't one of the operating systems that will be patched?

I couldn't find details in the article, but since extended support has ended... RIP win2k :(

P.S. unless it's not affected by this? but I think there are previous vulnerabilities which haven't been patched too so maybe win2k is already dead and I missed the boat.

Re:Windows 2000? (1)

Fluffeh (1273756) | about 5 years ago | (#29687721)

so maybe win2k is already dead and I missed the boat

so maybe win2k is already dead and I missed the decade
There, fixed that for you.

Re:Windows 2000? (2, Informative)

Opyros (1153335) | about 5 years ago | (#29687933)

Extended support hasn't ended just yet [] .

Autodestruct? (0, Offtopic)

Mishotaki (957104) | about 5 years ago | (#29687643)

Will it make every PC that uses windows ME self-destruct?

Re:Autodestruct? (3, Funny)

BenBoy (615230) | about 5 years ago | (#29687701)

Will it make every PC that uses windows ME self-destruct?

Nope, that doesn't require a patch; it was built into the original release ...

Re:Autodestruct? (5, Funny)

von_rick (944421) | about 5 years ago | (#29687843)

Nope, that doesn't require a patch; it was built into the original release ...

Yup. The hard drive with ME installation will jump out from the chasis, climb the refrigerator and rub itself all over the magnets.

Re:Autodestruct? (0)

Anonymous Coward | about 5 years ago | (#29687993)

hard drive porn!

Re:Autodestruct? (1)

Lulfas (1140109) | about 5 years ago | (#29688051)

You..... you win. There is nothing better to be found on the internets than the image that put in my mind. Good game sir, good game.

Re:Autodestruct? (0)

Anonymous Coward | about 5 years ago | (#29688133)

LOL, funniest thing I read today.

Re:Autodestruct? (3, Funny)

Fluffeh (1273756) | about 5 years ago | (#29687737)

Will it make every PC that uses windows ME self-destruct?

Not likely, PC's running Windows ME probably don't have the power to do more than to self fizzle at most. I would personally be impressed if they let out the smallest little puff of smoke. I think the reality would be that they just refuse to power up due to shame.

Re:Autodestruct? (1)

SilverHatHacker (1381259) | about 5 years ago | (#29687797)

Obviously, you were lucky enough to never encounter the following error message:

Computer will now throw itself out window. Press F1 to continue.

Re:Autodestruct? (1)

siddesu (698447) | about 5 years ago | (#29687817)

No, it will only show the "Autodestruct" button. You still have to kill all monsters and hit it manually (with a fist) to have the PC assplode.

Re:Autodestruct? (1)

dubbayu_d_40 (622643) | about 5 years ago | (#29687895)

I'll wager not just ME, but all versions that are not Windows 7.

Re:Autodestruct? (1)

Spewns (1599743) | about 5 years ago | (#29688023)

I'll wager not just ME, but all versions.


in the last patch supertuesday (2, Interesting)

circletimessquare (444983) | about 5 years ago | (#29687647)

i got this awesome bug fix such that Outlook now says "This copy of Office is not genuine. Click here to learn more online." in an unremoveable toolbar

can't wait to see what gets patched next!

Re:in the last patch supertuesday (0)

Anonymous Coward | about 5 years ago | (#29687767)

Maybe they can patch that hole in your wallet so you can by a legit copy.

yes (1)

circletimessquare (444983) | about 5 years ago | (#29688065)

because as well all know, the concept of exchanging cash for digital content is solid unquestionable morality. meanwhile, if i were to assert that perhaps digital content reaches maximum economic value for its creators when it is valued at $0, that true economic influence is felt in the ancillary benefits surrounding the distribution of digital content, i'm just some sort of a kook

you could say i might even have something valid to say there, but microsoft plainly states it wishes to have cash in exchange for its digital content, and i have no right to abrogate that agreement. right, just like i have no right to question that the great grandchildren of the writer of "happy birthday" still deserve cash for someone playing that song somewhere. just like i have no right to question why a picture of a stupid mouse is still private property. etc.

you know what? i have every right to abrogate an "agreement" i was never consenting party to and see no logical, philosophical, moral, or economic coherence in

Re:yes (1)

DAldredge (2353) | about 5 years ago | (#29688107)

Then why are you begging from money to film a movie?

have you ever filmed a movie? (1)

circletimessquare (444983) | about 5 years ago | (#29688253)

you think strong ip laws makes the begging less necessary? man, i wish

Re:yes (1)

dave562 (969951) | about 5 years ago | (#29688259)

The extent of your vocabulary cannot conceal the fact that you're a cheapskate and a probably pirate. Microsoft software isn't digital content. It is content creation software. Tools are not free unless you want to write your own, or use tools that others provide you for free. There are plenty of them out there and you can feel free to use them. If you find a feature that your free tools don't have, pay for a tool that has the feature you want.

Re:in the last patch supertuesday (2)

Grishnakh (216268) | about 5 years ago | (#29687815)

I wish they'd patch my work computer to do that, and in such a way that the IT department can't fix it. I hate Outlook, and I'd love a good excuse to not use it any more.

Re:in the last patch supertuesday (2, Informative)

Darth_brooks (180756) | about 5 years ago | (#29688041)

I used to say that. Then we got forced onto Lotus Notes.

and when I get to Heaven To St. Peter I will tell: "One more Notes user reporting, Sir -- I've served my time in Hell."

Re:in the last patch supertuesday (1)

Entropius (188861) | about 5 years ago | (#29687837)

Thankfully Office is considered quaint where I work. Anybody who wants to be taken seriously uses vi/emacs/kwrite/textpad and LaTeX.

Re:in the last patch supertuesday (2)

f8l_0e (775982) | about 5 years ago | (#29688043)

Is your employer hiring?

Re:in the last patch supertuesday (3, Insightful)

plague3106 (71849) | about 5 years ago | (#29688063)

Well stop pirating office and you won't have those kinds of problems.

Re:in the last patch supertuesday (1)

AmberBlackCat (829689) | about 5 years ago | (#29688247)

Was it "genuine"? Cause all I got was a message saying the system was being updated. I waited that out and everything worked as usual. The only annoyance was it didn't say what was updated, nor did it ask if I wanted the updates even though my settings are to notify me before updating.

Microsoft plans largest ever patch tuesday (0)

Anonymous Coward | about 5 years ago | (#29687673)

Microsoft plans largest ever patch Tuesday with a ton of awesome features. It will be ready in a few years. Make that 10 years. And actually, scrap the features. By the time it arrives, none of the features are anywhere to be seen, and all they accomplish is add eye candy, a 16 Gb memory footprint and 75% performance cut. Oh, and nobody will install the patch.

Bad luck (4, Funny)

gmuslera (3436) | about 5 years ago | (#29687693)

13 patches released at 13:00 of Tuesday 13. Windows sysadmins that day will have to pass below ladders, see a black cats cross in front of them and then break a mirror. But that will be nothing. The worst part will be when they turn on the computer, and see that windows is still running.

WTF? (0)

Anonymous Coward | about 5 years ago | (#29687715)

Why the fuck is there a story about this? Is Slashdot that lame?

Re:WTF? (0)

Anonymous Coward | about 5 years ago | (#29687775)

You're lamer for reading it.

And also lamer for reading this comment.

And I'm even lamer for writing it.

Le sigh.

among the fixes... (1)

postmortem (906676) | about 5 years ago | (#29687723)

is there a fix for popular '12345' Windows Live passwords ?

Re:among the fixes... (1)

Azureflare (645778) | about 5 years ago | (#29687791)

Sorry, there's no software fix possible for PEBKAC vulnerabilities.

Wring. 13 advisories with 34 issues. RTFM (4, Informative)

seifried (12921) | about 5 years ago | (#29687861) []

For October we are releasing 13 bulletins (eight critical and five important), addressing 34 vulnerabilities, affecting Windows, Internet Explorer, Office, Silverlight, Forefront, Developer Tools, and SQL Server. Most of these updates require a restart so please factor that into your deployment planning.

Re:Wring. 13 advisories with 34 issues. RTFM (2, Funny)

John Hasler (414242) | about 5 years ago | (#29688185)

So you are going to have to reboot more than thirty times to install this?

Re:Wring. 13 advisories with 34 issues. RTFM (1)

seifried (12921) | about 5 years ago | (#29688265)

Fortunately just the once. You can thank Windows insane file locking (easy to establish a lock, hard to make sure everyone let go, so the easiest way to overwrite a file is put it in the queue for overwriting at reboot time when you can be sure no-one is messing with it). Linux is so much saner in this aspect.

Kudos (4, Interesting)

Linker3000 (626634) | about 5 years ago | (#29688039)

Look, I know it's fashionable to make negative remarks about MS round here, but it's only fair to say 'well done' to them for bettering their previous high count. Hopefully they haven't run out of bugs to fix and they'll work hard to find and fix even more next time. Who knows, this time next year they could be fixing hundreds of bugs every month - and if we're lucky, some of them could be quite serious or critical - wouldn't that be just awesome!

Go MS!

13 Patches != 13 Flaws (5, Informative)

Ralish (775196) | about 5 years ago | (#29688045)

I was about to bitch about the submitter/moderator not RTFA, but it turns out, the article doesn't mention it either, so I'll clarify instead: thirteen updates are being released which together address thirty-four security vulnerabilities of varying severity across varying products (ten of which are targetted at Windows). So, that's NOT thirteen flaws (plenty more actually), just thirteen updates, some of which (all?) address multiple flaws in the particular system they are targetted at. Of course, this is just the advance notification, so full details about how many vulnerabilities each update addresses and the general information on them won't be released until the patches are next Tuesday. I think it's also worth nothing (although the summary of course neglects to mention it) that the good aspect of these updates are both major zero-day exploits (targetting IIS & SMB 2.0) are patched with these updates.

And while I'm posting, why does Slashdot insist on linking to shitty tech magazine articles (poorly) summarising the raw and accurate data straight from Microsoft? Seriously, I'm not sure if it's some sort of aversion to linking to MS, but they're the ones doing the patching, so it follows that they have the best, newest, most accurate data on them, and they'll likely be the first to provide updates on their content. These articles are just summarising what Microsoft has published on their various web-sites, and being a summary, they provide a lot more information and raw data:

Microsoft Security Bulletin Advance Notification for October 2009 []
October 2009 Bulletin Release Advance Notification []

Re:13 Patches != 13 Flaws (1)

dave562 (969951) | about 5 years ago | (#29688295)

On some level Slashdot bills itself as a news aggregator. Information taken straight from software vendors aren't necessarily news articles. They often times contains the most accurate information. If the editors start posting articles, then they have to post articles, and articles and pretty soon this isn't News for Nerds, it's Corporate PR Central.

I'm of the opinion (how ever little that is truly worth) that articles about patch counts are completely worthless. Anything short of discussing actual vulnerabilities is pretty much a waste of time. We all know that Microsoft releases batches of patches from time to time. We all know that any article about Microsoft patches will involve comments about how much MS sucks because their software needs to be patched. There will be a bunch of pro-Linux comments, a couple of Apple fanbois and that will be that.

Does it fix Windows 7's problems? (5, Funny)

MBCook (132727) | about 5 years ago | (#29688111)

Does it fix the problems with Windows 7? After reading this review [] of a pre-release download, I'm a bit hesitant to use it.

That curious hidden patch (0)

laanak (1262306) | about 5 years ago | (#29688201)

hmmm....I wonder where's the patch that wipes windows from the hard drive and installs *nix.....

QUESTION about "critical" software (2, Interesting)

yeehaomgyay (1652815) | about 5 years ago | (#29688207)

I am using special exam software to take a grad school exam Wednesday morning. The version of the software which I'll be using was released TODAY. Would I be smart to turn off Automatic Updates on Monday, or is this just paranoia?

Re:QUESTION about "critical" software (1)

yeehaomgyay (1652815) | about 5 years ago | (#29688245)

oh, forgot to mention that if anything goes wrong with the software, i.e. crash, there is no guarantee that you will be allowed to reboot your computer, no guarantee that whatever you've written already can be recovered, and no extra time allowed for any time lost fiddling with the computer, answers lost, etc... So I'm thinking there is a non-trivial chance a big OS patch could introduce an unwelcome issue and so I should avoid applying the patch till after the exam. Does this make sense?

a Linux Live CD (0)

Anonymous Coward | about 5 years ago | (#29688233)

which distribution will they choose, it would be hard to satisfy the typical slashdot user

Oooh! 13 flaws! (0)

Anonymous Coward | about 5 years ago | (#29688235)

We can probably assume that the 34 vulnerabilities are just different OS and browser variations of the same 13 flaws.

Funny thing about Slashdot, though. People complain nonstop about all of the bugs in Windows, but then when Microsoft makes an effort to patch as many of them as possible in one go, they complain about "the biggest patch Tuesday ever!!!!" It shouldn't be a surprise, folks. If you believe that Windows has all these bugs, then you should probably also believe that they will be patched at some point too. Seems like they should be bragging about how many of the bugs their patching.

And by the way, when the previous record holder was 12 flaws, it's not really saying much that the latest is 13 flaws. That's like saying I'm richer than someone with $1,000,000 because I have $1,083,000. In the grand scheme of things, that $83k doesn't really matter.

Windows 7.1 (1)

Kr4u53 (955252) | about 5 years ago | (#29688239)

So does this mean that users who buy windows 7 retail won't need to wait for the service pack as they already have it?

M$ (-1, Redundant)

slowg111 (1652821) | about 5 years ago | (#29688321)

Need I say more?
