Follow Slashdot blog updates by subscribing to our blog RSS feed

 



Forgot your password?
typodupeerror

Submission Summary: 0 pending, 6 declined, 3 accepted (9 total, 33.33% accepted)

×
Microsoft

Submission + - ISO publishes final Open XML specification (iso.org)

shutdown -p now writes: "ISO/IEC 29500:2008, better known as Office Open XML, is now a published ISO International Standard. Major changes since last public drafts include splitting the standard into "strict conformance" and "transitional conformance" parts, with all the Microsoft Office compatibility hacks going into the latter, "for Office Open XML consumers and producers that comply to the transitional conformance category ... provide support for legacy Microsoft Office applications". The complete standard, including the transitional part, is still rather unwieldy at 7,228 pages; of those, the transitional elements take up only 1,475 pages.

In addition, the ISO press release explicitly references something called "Microsoft Office 2008" at least one time. Presumably, it would be a Microsoft Office release fully compliant with the newly released specification in its final form; however, there haven't been any announcements from Microsoft about a product named "Office 2008" yet."

Security

Submission + - Exploits generated autpmatically from patches (lambda-the-ultimate.org)

shutdown -p now writes: "A group of researchers wrote a paper (PDF) on automatic generation of exploits from security patches. It works by performing flow analysis on the code that is changed by the code to find the boundary conditions that lead to vulnerability in an unpatched version. It's not just theory, either: they have successfully generated exploits for 5 known vulnerabilities in Microsoft products using their algorithm. The authors note that a successful attack using this method is particularly likely when vendor deliberately delays releasing security patches to the general public, to push them in a single bundle on a regular schedule — as is the case with Windows Update and its infamous Patch Tuesday."

Slashdot Top Deals

Thus spake the master programmer: "After three days without programming, life becomes meaningless." -- Geoffrey James, "The Tao of Programming"

Working...