MacDailyNews - Where Mac news comes first

 MacDailyNews Poll

Deal of the Day

5 Day Most Commented

Opinion Archive

Current Headlines

Latest Joy of Tech

  • Latest Joy of Tech!

MacNN

AppleInsider

Macworld UK

TUAW

MacRumors

Yahoo! Finance AAPL

iTunes Top 10 Albums

Mac OS X Downloads

Sun, Nov 08, 2009 - 06:25 AM EST  —  AAPL: 194.34 (+0.3099, +0.16%)  |  NASDAQ: 2112.44 (+7.12, +0.34%)

Microsoft confirms yet another Word zero-day flaw
Wednesday, December 13, 2006 - 01:08 PM EST

"Microsoft's security response center has confirmed that a second zero-day vulnerability in its Word software program is being targeted by unknown attackers," Ryan Naraine reports for eWeek.

"The latest flaw comes just days after the software maker issued a security advisory to warn customers against opening Word documents from untrusted sources. The two vulnerabilities are entirely unrelated," Naraine reports.

Naraine reports, "The flaws were discovered during actual code execution attacks against select targets and highlight the Redmond, Wash., vendor's struggle to cope with gaping holes in one of its most widely used products."

Naraine reports, "According to a US-CERT advisory, the latest bug is a memory corruption issue that occurs when a Word file is rigged with malformed data structures. No other details were made available. Microsoft has not yet issued a formal prepatch advisory but, in a blog entry, Security Program Manager Scott Deacon listed affected software versions as Word 2000, Word 2002, Word 2003 and the Word Viewer 2003."

"Microsoft plans to issue six security bulletins as part of its December batch of patches, but there are no Office fixes on tap. Unless an out-of-cycle update is shipped, the Word flaws will remain unpatched until at least Jan. 9, 2007," Naraine reports.

Full article here.

MacDailyNews Take: One can only hope that the poor bastards who are stuck in "Microsoft's security response center" qualify for overtime. What a job; a more perfect hell has yet to be constructed. We wonder, has a more inept company ever had so much undeserved success as Microsoft?

Send us links! Email: webmaster@macdailynews.com

Apple Store Advertisements
iPhone 3G S: From $199. Free shipping.
New 13-inch MacBook: From $999. Free shipping.
13-inch Macbook Pro: From $1199. Free shipping.
13-inch MacBook Air: From $1499. Free shipping.
15-inch Macbook Pro: From $1699. Free shipping.
17-inch MacBook Pro: From $2499. Free shipping.
New Mac mini: From $599. Free shipping.
New iMac 21.5-inch: From $1199. Free shipping.
New iMac 27-inch: From $1699. Free shipping.
Mac Pro: From $2499. Free shipping.
iPod touch: From $199. Free Shipping.
iPod nano: Now shoots video! From $149. Free shipping.
iPod shuffle: From $59. Free engraving. Free shipping.
Apple TV: From $229. Free shipping.

MacDailyNews on Twitter

MacDailyNews app for iPhone and iPod touch

Related MacDailyNews articles:
Microsoft releases Office 2004 for Mac 11.3.1 Update - December 13, 2006
Unpatched Microsoft Word flaw affects Macs too - December 06, 2006
Microsoft says Office 2007 XML support coming to Macs eventually - December 06, 2006
Microsoft’s Office 2007 for Windows saves documents in Mac-incompatible format - December 05, 2006
CodeWeavers releases CrossOver Mac 6.0 Beta 3 - November 14, 2006
RUMOR: Apple to take on Microsoft Office, add ‘Lasso’ spreadsheet app to iWork ‘07 - October 11, 2006
Free NeoOffice 2.0 Aqua Beta 3 now available - August 28, 2006
CodeWeavers brings low-cost way of running Windows apps on Mac OS X sans Windows - August 14, 2006
Mac users should not buy Microsoft software (or hardware) - May 16, 2003

Bookmark and Share

Always -- Free ground shipping with orders over $50 at the Apple Store.

Reader Feedback: = registered.
Unregistered users: Feedback from multiple usernames are subject to deletion. Off-topic and posts from suspected astroturfers will be removed.

Dec 13, 06 - 01:11 pm Comment from: Damacles

In answer to your question--and in one word--NO.

Where are the class-action lawsuits when you need them?

Dec 13, 06 - 01:13 pm Comment from: wandering joe

I love this companyyyyyyyyy....developers..developers..etc.....

Dec 13, 06 - 01:28 pm Comment from: Donovan MACnabb

Give it up for me..................!!!!!!!!!!!!

Dec 13, 06 - 01:30 pm Comment from: Macaday

Even the most naive must begin to detect a pattern here..

Dec 13, 06 - 01:34 pm Comment from: Anti-Balmer

I... LOVE... THIS... WEBSITE!!!

Dec 13, 06 - 01:58 pm Comment from: Drunk Cheney

I say - someone at Microsoft needs to light a match.

Dec 13, 06 - 02:00 pm Comment from: Always Right

On another note-
Peter Boyle died today. (Actor in the Young Frankenstien movie), of which is Ballmerized here:

http://youtube.com/results?search_query=steve+ballmer+young+frankenstein&search=Search

Dec 13, 06 - 02:12 pm Comment from: foto-ace

Just love reading the MacdailyNews "Take"!
Whoever writes that every hour of every day has a wicked sense of humor! I start every day laughing, especially when MST is the target! Keep it up!

Dec 13, 06 - 04:12 pm Comment from: rasterbator

I believe Mi¢ro$oft holds the patent for bloated code full of security holes, otherwise they would just start from scratch.
smile

Dec 13, 06 - 06:02 pm Comment from: Micro Me

The problems just keep coming and coming and coming and coming (at least I hope that's the way Ballmer would spell it).

Dec 13, 06 - 07:09 pm Comment from: Wise Guy

As my uncle from New York would say f*ck 'em.

Dec 13, 06 - 09:06 pm Comment from: Less is More

Microsofr needs to start from scratch:

1) A whole new board with enough teeth to...

2) Fire top management;

3) Come up with a whole new business philosophy...

4) that is transparent, ethical, sensible and prescient;

5) Clean out the excess staff/bureaucracy getting in the way of development;

6) Develop a Unix-based secure new OS from scratch, using...

7) Translation software to read/write/convert/secure legacy files...

8) into industry-standard formats;

9) Dump all proprietary media and file formats in favor of open standards...

10) or de-proprietize their own formats in consultation with industry;

11) Compete by real product innovation, and...

12) discard the restrictive monopolistic philosophy that drives the corporation;

13) Simplify product versions to basic types: consumer/pro; client/server, client/authoring;

14) Return 25% of cash reserves to shareholders as a mea-culpa dividend,

15) and 25% of cash reserves to buyers of their new products as a mea-culpa cash-back;

16) etc., etc., etc. I could go on and on...



...OR...



Takeover Apple computer and transition to the Mac Operating System and Apple management,
committing hara-kiri when the process is complete.



My bill will be in the mail. MW: "specific"

Dec 14, 06 - 12:17 am Comment from: Fred

Fsck Windows. Let's talk about something else. Life is too short.

Dec 14, 06 - 12:58 am Comment from: dogfriend

eEye just announced a (possible) third Word zero day vulnerability:

http://research.eeye.com/html/alerts/zeroday/20061212.html

Dec 14, 06 - 12:04 pm Comment from: Holy Mackerel

Why do we never hear of security alerts for other company's products?

To paraphrase wandering joe:
I love this companyyyyyyyyy… security alerts… security alerts… security alerts…

Dec 16, 06 - 06:36 am Comment from: Sure

"Whoever writes that every hour of every day has a wicked sense of humor! I start every day laughing, especially when MST is the target! Keep it up!"

Yeah MDN's so smart and witty, given that most MDN takes can be distilled down to: Microsoft Sucks, Microsoft Sucks, My PC's so much better than any other PC, I can't understand why almost the whole world uses another type, Microsoft Sucks.

Reader feedback page 1 of 1 pages:

Always -- Free ground shipping with orders over $50 at the Apple Store.

Add Your Feedback:

Register or Login

Name:

Email: (optional)

Emoticons | Allowed HTML Tags

Remember my info   Notify me of follow-up comments?

Please enter the "MDN Magic Word" you see in the image below: