Showing posts with label updates. Show all posts
Showing posts with label updates. Show all posts

Wednesday, 18 September 2013

Microsoft updates display 'worrisome' decline in quality

September 15, 2013 03:27 PM ETComputerworld - Microsoft on Friday acknowledged it had rewritten four of its security updates issued just three days earlier after customers reported never-ending demands that they be installed, even though they had been.

The flawed updates were just the latest in a disturbing trend of quality problems in Microsoft's security and stability updates. The repeated installation requests followed Microsoft's yanking of a non-security update last week, as well as buggy fixes shipped in August and April that blocked access to server-based email mailboxes and crippled Windows 7 PCs.

"Worrisome," is how Andrew Storms, director of DevOps at San Francisco-based cloud-oriented security vendor CloudPassage, put it when asked about the trend in an interview conducted via instant messaging Friday. "Are we starting to see a shift back to when people called Microsoft the necessary PITA [pain in the ass]?"

According to Microsoft, it's already fixed the four updates that were dunning customers with installment demands. "We have received reports of updates being offered for installation multiple times, or certain cases where updates were not offered via Windows Server Update Services (WSUS) or System Center Configuration Manager (SCCM)," the company said on an Office engineering blog. "We have investigated the issue, established the cause, and we have released new updates that will cease the unnecessary re-targeting of the updates or the correct offering of these updates."

Microsoft identified four of last Tuesday's 13 security updates as flawed, including one for SharePoint Server, one that affected Office 2007 and Office 2010, another that impacted Office 2013, and a fourth that patched Excel 2003 and Excel 2007.

A non-security update for PowerPoint 2010 also exhibited the same behavior.

Almost immediately after Microsoft issued September's slate of security updates, customers reported the recurring install snafu on the company's support forums.

Some were caustic about their experiences dealing with the endless loop, and their time on the telephone with Microsoft support representatives. "I've spent more than 3 hours chatting with MS Answer desk with people who were unable to comprehend this simple issue," wrote "choisington" on Sept. 10, the day Microsoft delivered the updates.

"I am so fed up with Microsoft, their ability to totally take over a machine's ability to function," ranted "Ffaith" on Thursday.

The frustration was understandable: Also last week, an Office 2013 stability and performance update blanked the folder pane in Outlook 2013, the suite's email client. After fielding scores of complaints from customers, Microsoft acknowledged the update was flawed, yanked the original, began working on a corrected re-release, and urged users to uninstall the update.

September's update blunders were the latest in a series of embarrassments for Microsoft. In August, the Redmond, Wash. company yanked an Exchange security update, admitting it had not properly tested the patches. In April, Microsoft urged Windows 7 users to uninstall an update that crippled PCs with the infamous "Blue Screen of Death"; it re-released the update two weeks later.

Other security professionals weighed in on Microsoft's inability to produce top-quality updates. Paul Ducklin, the head of technology for Sophos' Asia-Pacific region, dubbed Sept. 13 "Patch Horror Day" in a post to his company's blog.

"Microsoft is killing their record," said CloudPassage's Storms, referring to the company's hard-won reputation for issuing flawless updates. "Their record had been so good that people were starting to relax on their own internal testing."

Storms, joined by some of those who reported the over-and-over installation demands by the four Office updates, wondered whether Microsoft's focus on the cloud, and the subscription model for Office 365, was to blame for the lack of attention to detail on the traditional "perpetual" license versions of the suite.

"I think they recognize that's where the market demand is moving," said Storms of Office 365 and its continuous, behind-the-scenes updating. "But at what cost?"

Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at Twitter @gkeizer, on Google+ or subscribe to Gregg's RSS feed Keizer RSS. His email address is gkeizer@computerworld.com.

See more by Gregg Keizer on Computerworld.com.

Read more about Malware and Vulnerabilities in Computerworld's Malware and Vulnerabilities Topic Center.

How Cloud Communications Reduce Costs and Increase ProductivitySmall and midsize businesses are moving to the cloud to host their communications capabilities. Learn how enterprise-quality phone benefits, online management, conferencing, auto attendant, and ease of use are built into a system that is half the cost of a PBX.

Read now.


View the original article here

Monday, 16 September 2013

Microsoft updates display 'worrisome' decline in quality

September 15, 2013 03:27 PM ETComputerworld - Microsoft on Friday acknowledged it had rewritten four of its security updates issued just three days earlier after customers reported never-ending demands that they be installed, even though they had been.

The flawed updates were just the latest in a disturbing trend of quality problems in Microsoft's security and stability updates. The repeated installation requests followed Microsoft's yanking of a non-security update last week, as well as buggy fixes shipped in August and April that blocked access to server-based email mailboxes and crippled Windows 7 PCs.

"Worrisome," is how Andrew Storms, director of DevOps at San Francisco-based cloud-oriented security vendor CloudPassage, put it when asked about the trend in an interview conducted via instant messaging Friday. "Are we starting to see a shift back to when people called Microsoft the necessary PITA [pain in the ass]?"

According to Microsoft, it's already fixed the four updates that were dunning customers with installment demands. "We have received reports of updates being offered for installation multiple times, or certain cases where updates were not offered via Windows Server Update Services (WSUS) or System Center Configuration Manager (SCCM)," the company said on an Office engineering blog. "We have investigated the issue, established the cause, and we have released new updates that will cease the unnecessary re-targeting of the updates or the correct offering of these updates."

Microsoft identified four of last Tuesday's 13 security updates as flawed, including one for SharePoint Server, one that affected Office 2007 and Office 2010, another that impacted Office 2013, and a fourth that patched Excel 2003 and Excel 2007.

A non-security update for PowerPoint 2010 also exhibited the same behavior.

Almost immediately after Microsoft issued September's slate of security updates, customers reported the recurring install snafu on the company's support forums.

Some were caustic about their experiences dealing with the endless loop, and their time on the telephone with Microsoft support representatives. "I've spent more than 3 hours chatting with MS Answer desk with people who were unable to comprehend this simple issue," wrote "choisington" on Sept. 10, the day Microsoft delivered the updates.

"I am so fed up with Microsoft, their ability to totally take over a machine's ability to function," ranted "Ffaith" on Thursday.

The frustration was understandable: Also last week, an Office 2013 stability and performance update blanked the folder pane in Outlook 2013, the suite's email client. After fielding scores of complaints from customers, Microsoft acknowledged the update was flawed, yanked the original, began working on a corrected re-release, and urged users to uninstall the update.

September's update blunders were the latest in a series of embarrassments for Microsoft. In August, the Redmond, Wash. company yanked an Exchange security update, admitting it had not properly tested the patches. In April, Microsoft urged Windows 7 users to uninstall an update that crippled PCs with the infamous "Blue Screen of Death"; it re-released the update two weeks later.

Other security professionals weighed in on Microsoft's inability to produce top-quality updates. Paul Ducklin, the head of technology for Sophos' Asia-Pacific region, dubbed Sept. 13 "Patch Horror Day" in a post to his company's blog.

"Microsoft is killing their record," said CloudPassage's Storms, referring to the company's hard-won reputation for issuing flawless updates. "Their record had been so good that people were starting to relax on their own internal testing."

Storms, joined by some of those who reported the over-and-over installation demands by the four Office updates, wondered whether Microsoft's focus on the cloud, and the subscription model for Office 365, was to blame for the lack of attention to detail on the traditional "perpetual" license versions of the suite.

"I think they recognize that's where the market demand is moving," said Storms of Office 365 and its continuous, behind-the-scenes updating. "But at what cost?"

Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at Twitter @gkeizer, on Google+ or subscribe to Gregg's RSS feed Keizer RSS. His email address is gkeizer@computerworld.com.

See more by Gregg Keizer on Computerworld.com.

Read more about Malware and Vulnerabilities in Computerworld's Malware and Vulnerabilities Topic Center.

How Cloud Communications Reduce Costs and Increase ProductivitySmall and midsize businesses are moving to the cloud to host their communications capabilities. Learn how enterprise-quality phone benefits, online management, conferencing, auto attendant, and ease of use are built into a system that is half the cost of a PBX.

Read now.


View the original article here

Thursday, 12 September 2013

Adobe issues critical security updates for Flash Player, Reader and Shockwave Player

Adobe released security updates for Flash Player, Adobe Reader and Shockwave Player on Tuesday to address critical vulnerabilities that could allow attackers to take control of systems running vulnerable versions of those programs.

The Flash Player updates address four memory corruption vulnerabilities that can lead to arbitrary code execution. The updates are version numbers 11.8.800.168 for Windows and Mac OS X; 11.2.202.310 for Linux; 11.1.115.81 for Android 4.x; and 11.1.111.73 for Android 3.x and 2.x.

[ InfoWorld's expert contributors show you how to secure your Web browsers in a free PDF guide. Download it today! | Learn how to protect your systems with Roger Grimes' Security Adviser blog and Security Central newsletter, both from InfoWorld. ]

Users of Google Chrome and Internet Explorer 10 on Windows 8 will automatically receive updates for the Flash Player plug-in bundled with those browsers through their respective update mechanisms.

The same Flash Player vulnerabilities were patched in Adobe AIR, a runtime for rich Internet applications that also bundles Flash Player. Adobe released version 3.8.0.1430 of AIR and AIR SDK (software development kit) for Windows, Mac OS X and Android.

New versions of Adobe Reader and Adobe Acrobat XI and X were released to address eight arbitrary code execution vulnerabilities: three memory corruption issues, two buffer overflows, two integer overflows and one stack overflow.

Users of Adobe Reader or Acrobat XI for Windows and Mac OS X are advised to upgrade to Adobe Reader XI (11.0.04) or Adobe Acrobat XI (11.0.04), respectively. Adobe Reader and Acrobat X for Windows and Mac have also been updated to version 10.1.8.

Adobe's Shockwave Player, an application required to display online content created with Adobe's Director software was updated to version 12.0.4.144 for Windows and Mac to address two memory corruption vulnerabilities that can lead to arbitrary code execution.

While not as popular as Flash Player, Shockwave Player is installed on 450 million Internet-enabled desktops, according to statistics from Adobe, which potentially makes it an attractive target for attackers.


View the original article here

Wednesday, 11 September 2013

Adobe issues critical security updates for Flash Player, Reader and Shockwave Player

Adobe released security updates for Flash Player, Adobe Reader and Shockwave Player on Tuesday to address critical vulnerabilities that could allow attackers to take control of systems running vulnerable versions of those programs.

The Flash Player updates address four memory corruption vulnerabilities that can lead to arbitrary code execution. The updates are version numbers 11.8.800.168 for Windows and Mac OS X; 11.2.202.310 for Linux; 11.1.115.81 for Android 4.x; and 11.1.111.73 for Android 3.x and 2.x.

[ InfoWorld's expert contributors show you how to secure your Web browsers in a free PDF guide. Download it today! | Learn how to protect your systems with Roger Grimes' Security Adviser blog and Security Central newsletter, both from InfoWorld. ]

Users of Google Chrome and Internet Explorer 10 on Windows 8 will automatically receive updates for the Flash Player plug-in bundled with those browsers through their respective update mechanisms.

The same Flash Player vulnerabilities were patched in Adobe AIR, a runtime for rich Internet applications that also bundles Flash Player. Adobe released version 3.8.0.1430 of AIR and AIR SDK (software development kit) for Windows, Mac OS X and Android.

New versions of Adobe Reader and Adobe Acrobat XI and X were released to address eight arbitrary code execution vulnerabilities: three memory corruption issues, two buffer overflows, two integer overflows and one stack overflow.

Users of Adobe Reader or Acrobat XI for Windows and Mac OS X are advised to upgrade to Adobe Reader XI (11.0.04) or Adobe Acrobat XI (11.0.04), respectively. Adobe Reader and Acrobat X for Windows and Mac have also been updated to version 10.1.8.

Adobe's Shockwave Player, an application required to display online content created with Adobe's Director software was updated to version 12.0.4.144 for Windows and Mac to address two memory corruption vulnerabilities that can lead to arbitrary code execution.

While not as popular as Flash Player, Shockwave Player is installed on 450 million Internet-enabled desktops, according to statistics from Adobe, which potentially makes it an attractive target for attackers.


View the original article here

Wednesday, 21 August 2013

Microsoft updates Windows Phone App Studio after developer projects soar

Microsoft is updating the recently launched beta of Windows Phone App Studio to improve performance and scalability after the new app development tool crossed 55,000 active projects.

The hosted service was launched two weeks ago in a bid by Microsoft to increase the number of applications available on Windows Phone by allowing users to create apps without writing any code. The service lets users choose from a number of templates to get started, then add content such as images, videos, RSS, and Twitter feeds.

[ Learn how to work smarter, not harder with InfoWorld's roundup of all the tips and trends programmers need to know in the Developers' Survival Guide. Download the PDF today! | Keep up with the latest developer news with InfoWorld's Developer World newsletter. ]

So far, the response has been well above what Microsoft expected, according to a blog post on Monday. In the first 48 hours, Microsoft saw more than 20,000 people from all over the world starting more than 30,000 projects, and on Monday it crossed 55,000 active projects. To help manage demand, the company implemented a temporary access code system, it said.

Microsoft is also making some fundamental changes to improve App Studio's overall performance and the scalability of the system. There have been a few hiccups in the first two weeks of availability, according to Microsoft. The company is also adding new functionality; users can choose from new templates and there are connections to more external data sources, including Flickr, which users have been asking for.

The company didn't provide any details on when Windows Phone App Studio would become generally available.

The availability of more apps is key for Windows Phone's continued growth, according to Anshul Gupta, principal research analyst at Gartner. Sales of Windows Phones to end-users increased to 7.4 million during the second quarter, which was enough to surpass sales of BlackBerry for the first time. But the OS still only has a 3.3 percent market share, according to Gartner.

"While Microsoft has managed to increase share and volume in the quarter, Microsoft should continue to focus on growing interest from app developers to help grow its appeal among users," Gupta said.

Send news tips and comments to mikael_ricknas@idg.com


View the original article here