Skip to navigation
   
Davey Winder's Blog

Not for ostriches: Patch Tuesday Risk Analysis

By Davey Winder in Editorial

Posted in Blog, Security, Microsoft on September 10, 2008 at 12:51 pm

Permalink | Author Profile

Has Patch Tuesday really been and gone again already? Oh lawdy yes, it has. Which means that you need to know the impact that those updates are going to have on your business. Indeed, I know of some folk who take a twisted ‘if it ain’t too broken don’t let a Microsoft fix break something else’ approach to patch management. Sorry, but that really is Ostrich Security in action if you ask me.

So, assuming your head is not buried in the sand, or firmly stuck somewhere else that I cannot mention in mixed company, what do you do about it? The answer is, of course, let someone else determine the risk and reward process of updating. Which is where those lovely chaps over at ChangeBASE enter the patch management equation. This ain’t no advert, so if you want to find out more about the application come patch management stuff it provides, go Google or visit the website.

Why I mention ChangeBASE at all is because they also issue Patch Tuesday application compatibility labs testing results which can help determine just what the impact on your business of quickly updating will be. This month, so I am informed, the patches and updates fall into the ‘relatively light’ band.

“The updates MS08-055 and MS08-053 relate to Windows Media player which has a minimal impact on the Operating system and few applications have a direct dependency on Windows Media player” ChangeBASE told me, adding “More importantly, MS08-052 includes an update to a core element of the operating system (GDIPLUS.DLL). This file is part of the graphics library for Window XP. Several applications run through AOK can load a version of this file from their source media/download process when they are installed and there is a danger that if this happens the installation will result in an out of date version of this file being loaded and overwriting the version in the patch update this month.”

ChangeBASE tested the following updates this month:

MS08-052: updates key components of Microsoft Messenger and Digital Imager
Impact: MS08-052 updates a core OS level DLL that is responsible for Windows XP/2000 graphics interface. A number of applications contain this file in their application installation routine including; Reuters Messaging, Microsoft Messenger, Macromedia Dreamweaver and Microsoft Digital Image which could cause application compatibility issues when these packages are deployed. In addition, a significant portion of our testing portfolio had a file level dependency on this updated DLL.

MS08-053: Marginal impact and negligible testing profile
Impact: This update had a marginal impact on the AOK Workbench application package portfolio through direct file and configuration overlaps with the update payload and the portfolio packages.

MS08-054: Marginal impact and negligible testing profile
Impact: This update had a marginal impact on the AOK Workbench application package portfolio through direct file and configuration overlaps with the update payload and the portfolio packages.

MS08-055: Updates key Microsoft Office components - full application test required
Impact: This Microsoft security update, while not affecting a large portion of the AOK application portfolio did directly affect a number of Microsoft application packages including Office 2003 (standard and professional), Microsoft Visual Basic, and Microsoft Project.

12345
Rated: 100% (1 votes)
Loading ... Loading ...

Previous Post | Next Post

 
 
Comments
This article has no comments yet.

Make a comment

* required

* required

We stop spam using reCaptcha.
Type the words below and click Submit Comment.

   
Tag cloud

worker scan technology Google books InfoSec archiving library office remote working banking Application payments virtual world MSN chips Kill Switch virus XP Bill Gates compromise Rant Ballmer fool carbon copy fun web fraud HPC Software millions Performance computing open source museum banks Digg IP Apple email Finjan Funny size Eee PC credit card fraud Hack VPN migration Jesus Phone mobile search FBI adware shopping terrorism exploit hardware standards betting Top 500 students CAPTCHA Adobe Texting sick debian avatar Twitter Health Flash Research Vista Deal Microchip VM Russia BOFH Steve Jobs Death hacking copyright remote Space Zango malware China teleworking black hat surveys IBM Video work Gartner SMS Trojan biometrics transactional security botnet gaming MessageLabs NBC hubdub economics hypervisor phishing Government holidays rootkits MSNBC Windows 7 Silverlight service development report data protection Linux storage Business Microsoft man-in-the-middle dumb prison AMD Facebook Windows documentation theft digitise policy Yahoo USA printing MiniBook worm privacy tech symantec politics Battery Blogging Paris Hilton stupidity payment server hacker Web Development Energy ecommerce NASA christmas productivity ID Theft scareware help virtual machine SSL broadband Mobile Phone home OS Internet Noro trust Firefox scam iPhone 3G ISPA outsourcing network Programming linkedin Eee e-commerce universe data Olympics ASUS computing Rumour workplace web 2.0 global patch management code spam graphics Lotus news Texas Instruments stupid Mars Obama crime green money second life IDC world of warcraft computer staffing survey security Project Supercomputer BSI environment statistics The Federation social networking iPhone xmas OCR DNS Big Brother science
Advertisement
Advertisement
Advertisement