Microsoft has finally begun patching a severe security flaw in its implementation of digital-certificate basic-constraints checking which we've been ranting about for nearly a month. The stuff-up makes it possible for SSL and e-mail signature certs to be forged.
Currently, Win-NT and XP users have fixes available for their kit. This leaves Win-98, 98-SE, ME, and 2K users waiting for patches which will be 'issued shortly,' the company says. There will also be patches for numerous versions of Internet Explorer, MS-Office, and Outlook Express for the Mac. On Windows it's necessary only to fix CryptoAPI for each OS version, but on Macs the situation is reversed; each Microsoft application needs to be fixed separately -- so if you're using more than one, you'll need more than one patch.
Interestingly, MS rates this Trustworthy Computing stuff-up 'Critical', in contradiction to their earlier whitewash of the issue.
|