Live data from Hacker News

Microsoft fixes '19-year-old' bug with emergency patch

bbc.com

1–10 of 47 posts

Re: Microsoft fixes '19-year-old' bug with emergency patch

#2
Reminds me of this one... http://en.wikipedia.org/wiki/Windows_Metafile_vulnerability

Another long-lived bug that someone finally managed to discover and exploit.

I wonder if it's related to this one 4 years ago: http://www.cvedetails.com/cve/CVE-2010-2566/

Re: Microsoft fixes '19-year-old' bug with emergency patch

#8
> Specifically, it related to Microsoft Secure Channel, known as Schannel, Microsoft's software for implementing secure transfer of data.

I'm confused... The article says this research relates to the SChannel vulnerability being patched this month and cites IBM Researchers[1] finding it, but the link to the blog post showing the work is towards OLE and not SChannel. Also, Microsoft has mentioned that they found[2] the SChannel vulnerability through an internal audit. To me, it seems the research is talking about CVE-2014-6332[3], which shows the patch as MS14-064. MS14-066 is the patch for the SChannel vulnerability.

Either BBC is confused on which patch they're trying to report on, or I am.

Anyone similarly confused as I am?

[1] http://securityintelligence.com/ibm-x-force-researcher-finds...

[2] http://blogs.technet.com/b/srd/archive/2014/11/11/assessing-...

[3] http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-633...

Re: Microsoft fixes '19-year-old' bug with emergency patch

#10
BBC technology reporting at its usual standard.

"In computer security, a drive-by attack typically means making users download malicious software."

That's really not clear. It means that you'll get infected by simply passing by [a website] rather than actively doing anything.

Post reply on HN