Feeds

Microsoft Patch Tuesday: The '90s called. It wants its 'Ping of Death' back

Wobbly IPv6 Windows stack gets extra support

Choosing a cloud hosting partner with confidence

Microsoft has pushed out eight advisories as part of the August edition of its regular Patch Tuesday update cycle. With just three critical patches, the most interesting thing about this week's batch is the return of the "Ping of Death" in the form of a stability bug in the Windows IPv6 stack.

The critical updates offer new versions of IE and Exchange, as well as critical fixes for the soon-to-be-retired Windows XP. Collectively, this week's rollout covers 23 vulns.

The highest priority for patching is MS13-059, a cumulative update for Microsoft's browser software that fixes 11 vulnerabilities in all versions of IE – from IE6 to IE10 – including on Windows RT.

Redmond warns that creating exploits to attack unpatched systems would not be difficult, even though the flaws are yet to come under active attack.

A second critical update (MS13-061) addresses three vulnerabilities in Microsoft Exchange stemming from bugs in a third-party library, Outside In from Oracle, included in Redmond's enterprise-focused email server software.

Last of the critical batch is a security update for Windows XP (MS13-060). Windows XP loses support in April 2014, at which point there will be no more security updates. Up until then the soon-to-be-pensioned-off OS needs security updating like a Linux fan needs a date. The vulnerable Unicode Scripts Processor components patched by the update also appears in Server 2003.

The remaining five bulletins lower severity, and are all rated "important". Noteworthy in the quintet is an update that grapples with a Windows kernel vulnerability involving a flaw in address space layout randomisation (ASLR), a defence-in-depth measure, and a separate patch that tackles a stability problem in the Windows IPv6 stack that might easily lend itself to denial-of-service attacks against vulnerable networks.

Wolfgang Kandek, CTO of cloud security firm Qualys, said the flaw is akin to the type that facilitated the infamous late '90s vintage "Ping of Death" attack, which involved sending elongated packets to crash vulnerable web servers.

Kandek adds:

A few ICMPv6 packets with router advertisements requests can cause a denial-of-service vulnerability reminiscent of the famous "Ping of Death". It’s a good illustration of how much we still do not know about the stability of IPv6. We continue to recommend turning off IPv6 on workstations if your network is not engineered for its use.

The remaining three important bulletins cover "important" security bugs in Windows and Active Directory.

Microsoft's August bulletin is here. A much-easier-to-fathom graphical overview from the SAN Institute's Internet Storm Centre is here.

Ross Barrett, senior manager of security engineering at Rapid7, described the overall patch load this month from Redmond as "moderate".

"The August 2013 Patch Tuesday advance notification includes a slightly higher volume of fixes than last month, but only three of eight are critical, which is down from July’s six of seven critical fixes," Barrett said. "However, in a reversal from last month, the advisories are focused on Windows operating system patches, plus one Exchange issue." ®

Providing a secure and efficient Helpdesk

More from The Register

next story
Preview redux: Microsoft ships new Windows 10 build with 7,000 changes
Latest bleeding-edge bits borrow Action Center from Windows Phone
Google opens Inbox – email for people too thick to handle email
Print this article out and give it to someone tech-y if you get stuck
Microsoft promises Windows 10 will mean two-factor auth for all
Sneak peek at security features Redmond's baking into new OS
UNIX greybeards threaten Debian fork over systemd plan
'Veteran Unix Admins' fear desktop emphasis is betraying open source
Google+ goes TITSUP. But WHO knew? How long? Anyone ... Hello ...
Wobbly Gmail, Contacts, Calendar on the other hand ...
DEATH by PowerPoint: Microsoft warns of 0-day attack hidden in slides
Might put out patch in update, might chuck it out sooner
Redmond top man Satya Nadella: 'Microsoft LOVES Linux'
Open-source 'love' fairly runneth over at cloud event
prev story

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.