No. 1 Story

HP job cuts loom for Australian employees

A number of Australian employees of Hewlett-Packard are facing the loss of their jobs as the global computer giant looks to slash its worldwide workforce by up to 30,000.

read more

Related Articles

Microsofts, February, security, updates, include, nonsecurity, update
Australian businesses are becoming soft targets for malicious hackers and they lag significantly behind...
To address the ever growing concerns of CIOs around security of mobile devices, US...
Juniper Networks has extended its SSL VPN security to the iPad with the release...
A recent survey by security company Sophos exposes the dilemma to business posed by...
A security vulnerability in Adobe's ColdFusion has been identified and fixed through a configuration...

Microsoft's February security updates include a 'non-security update'

Business IT - Security

Microsoft this week issued a dozen security bulletins addressing 22 vulnerabilities in Windows, Internet Explorer, Internet Information Service and Internet Explorer. The company also released a so-called non-security update that has everything to do with security.


Of the 12 security bulletins issued in February, three are rated critical. They affect Windows (a Windows Shell vulnerability affecting most versions excluding Windows 7 and Server 2008 R2, and a vulnerability in the OpenType Compact Font Format driver affecting all currently supported versions) and Internet Explorer (all currently supported versions).

According to Angela Gunn, security response communications manager at Microsoft, the company's ability to monitor the threat landscape allowed it to determine that attempts to attack the Internet Explorer vulnerability were very low, so there was no need for an out-of-cycle patch.

The other Windows issues are rated important or moderate.

The Office bulletin concerns Visio 2002, 2003 and 2007. It addresses a vulnerability that allows a maliciously crafted file to trigger remote code execution.

Microsoft also released a number of non-security updates, but one of them is all about security. Adam Shostack, program manager in Microsoft's Trustworthy Computing Security operation explained that "we reserve the term 'Security Update' to mean 'a broadly released fix for a product-specific security-related vulnerability.'"

So the update that changes the operation of Windows' Autorun feature is instead described as an "Important, non-security update."

CONTINUED