Pirates@Home logo

Pirates@Home

Berkeley Open Infrastructure
BOINC!
for Network Computing
Home Help Status Forums Glossary Account

Microsoft Security Bulletin Advance Notification

log in

Advanced search

Questions and Answers : Windows : Microsoft Security Bulletin Advance Notification

Author Message
Profile Wormholio
Captain
Avatar
Send message
Joined: 6 Jun 04
United States
Away
Credit: 4,009.8
RAC: 0.00
Joined: Jun 6, 2004
Verified: Mar 13, 2008
Dubloons: 3
Pieces of Eight: 10
Punishment: Aztec curse
Message 1214 - Posted: 5 Feb 2005 | 22:21:51 UTC
Last modified: 5 Feb 2005 | 22:24:13 UTC

On February 8, 2005, the Microsoft Security Response Center is planning to release 9 Security Bulletins affecting Windows. All pirates are advised to update theirr systems. Repel all borders!

Details here


____________
-- Eric Myers

"Education is not the filling of a pail, but the lighting of a fire." -- William Butler Yeats

Profile NeoGen
Send message
Joined: 18 Oct 04
Portugal
AMD Users
Credit: 9,146.3
RAC: 0.00
Joined: Oct 18, 2004
Verified: Sep 26, 2009
Dubloons: 3
Pieces of Eight: 2
Punishment: Canon Fodder
Message 1216 - Posted: 6 Feb 2005 | 0:23:06 UTC

If there's anything with more holes than a swiss cheese, it's got to be Windows... :|
____________


You can join our Team too!
Click the image above and visit our website!

Profile OlaV_Ouafouaf
Avatar
Send message
Joined: 17 Oct 04
France
The Pirate Fleet
Credit: 5,813.4
RAC: 0.00
Joined: Oct 17, 2004
Verified: NEVER
Dubloons: 3
Punishment: Mess Duty
Message 1217 - Posted: 6 Feb 2005 | 1:28:30 UTC - in response to Message 1216.

> If there's anything with more holes than a swiss cheese, it's got to be
> Windows... :|

lol !!!

and much more undigest ;)
____________
riding too fast on highway to stop smoking

one eye
Send message
Joined: 19 Sep 04
Switzerland
Credit: 40,405.3
RAC: 0.00
Joined: Sep 19, 2004
Verified: NEVER
Punishment: Walk Plank
Message 1235 - Posted: 7 Feb 2005 | 1:28:43 UTC - in response to Message 1217.

swiss cheese!

May I ask you kindly to not abuse the wonderfull swiss cheese?

Swiss cheese (about 450 types) is a high level quality product, can you imagine the efforts taken to dig the holes in a proper way?

And mostly swiss cheese isn't needed to update or service pack. ot to service pack the service pack.

It's well like it is.

Could it be, the understanding of "windows" is not everywhere the same?

Windows basicaly means windows. An open window. Opened windows. Open for all.

Thats like, bying a convertible car and installing a hard top, or how it's called.

In a german pc magazine was written some hints, one I found fine (for me) is automated download of new service packs or fixes, but manualy installation.




unfortunately windows doesn't offer the quality of swiss cheese, so follow the repel..

But it's very kind, to remember to do it.



Profile Contact
Volunteer tester
Avatar
Send message
Joined: 29 Aug 04
Canada
BOINC Synergy
Credit: 26,644.6
RAC: 0.00
Joined: Aug 29, 2004
Verified: Nov 10, 2011
Dubloons: 3
Pieces of Eight: 3
Punishment: Misfit
Message 1277 - Posted: 9 Feb 2005 | 1:10:33 UTC

This advisory contains information about all security updates
released this month. It is broken down by security bulletin severity.

Critical Security Bulletins
===========================

MS05-005 - Vulnerability in Office Could Allow Remote Code
Execution (873352)

- Affected Software:
- Microsoft Office XP Service Pack 2
- Microsoft Office XP Service Pack 3
- Microsoft Project 2002
- Microsoft Visio 2002
- Microsoft Works Suite 2002
- Microsoft Works Suite 2003
- Microsoft Works Suite 2004

- Impact: Remote Code Execution
- Version Number: 1.0

MS05-009 - Vulnerability in PNG Processing Could Allow Remote Code
Execution (890261)

- Affected Software:
- Microsoft Windows Media Player 9 Series
- Microsoft Windows Messenger version 5.0
- MSN Messenger 6.1
- MSN Messenger 6.2

- Affected Components:
- Microsoft Windows Messenger 4.7.2009
(when running on Windows XP Service Pack 1)
- Microsoft Windows Messenger 4.7.3000
(when running on Windows XP Service Pack 2)

- Review the FAQ section of bulletin MS05-009 for
information about these operating systems:
- Microsoft Windows 98
- Microsoft Windows 98 Second Edition (SE)
- Microsoft Windows Millennium Edition (ME)

- Impact: Remote Code Execution
- Version Number: 1.0

MS05-010 - Vulnerability in the License Logging Service Could
allow Remote Code Execution (885834)

- Affected Software:
- Microsoft Windows NT Server 4.0 Service Pack 6a
- Microsoft Windows NT Server 4.0 Terminal Server
Edition Service Pack 6a
- Microsoft Windows 2000 Server Service Pack 3
- Microsoft Windows 2000 Server Service Pack 4
- Microsoft Windows 2003
- Microsoft Windows 2003 for Itanium-based Systems

- Impact: Remote Code Execution
- Version Number: 1.0

MS05-011 - Vulnerability in Server Message Block Could Allow
Remote Code Execution (885250)

- Affected Software:
- Microsoft Windows 2000 Service Pack 3
- Microsoft Windows 2000 Service Pack 4
- Microsoft Windows XP 64-Bit Edition Service Pack 1
(Itanium)
- Microsoft Windows XP 64-Bit Edition Version 2003
(Itanium)
- Microsoft Windows Server 2003
- Microsoft Windows Server 2003 for Itanium-based
Systems

- Impact: Remote Code Execution
- Version Number: 1.0

MS05-012 - Vulnerability in OLE and COM Could Allow Remote Code
Execution (873333)

- Affected Software:
- Microsoft Windows 2000 Service Pack 3
- Microsoft Windows 2000 Service Pack 4
- Microsoft Windows XP Service Pack 1
- Microsoft Windows XP Service Pack 2
- Microsoft Windows XP 64-Bit Edition Service Pack 1
(Itanium)
- Microsoft Windows XP 64-Bit Edition Version 2003
(Itanium)
- Microsoft Windows Server 2003
- Microsoft Windows Server 2003 for Itanium-based
Systems

- Review the FAQ section of bulletin MS05-012 for
information about these operating systems:
- Microsoft Windows 98
- Microsoft Windows 98 Second Edition (SE)
- Microsoft Windows Millennium Edition (ME)

- Microsoft Exchange 2000 Server Service Pack 3
- Microsoft Exchange Server 2003
- Microsoft Exchange Server 2003 Service Pack 1
- Microsoft Exchange Server 5.0 Service Pack 2
- Microsoft Exchange Server 5.5 Service Pack 4
- Microsoft Office XP Service Pack 3
- Microsoft Office XP Service Pack 2
- Microsoft Office 2003 Service Pack 1
- Microsoft Office 2003

- Impact: Remote Code Execution
- Version Number: 1.0

MS05-013 - Vulnerability in the DHTML Editing Component ActiveX
Control Could Allow Remote Code Execution (891781)

- Affected Software:
- Microsoft Windows 2000 Service Pack 3
- Microsoft Windows 2000 Service Pack 4
- Microsoft Windows XP Service Pack 1
- Microsoft Windows XP Service Pack 2
- Microsoft Windows XP 64-Bit Edition Service Pack 1
(Itanium)
- Microsoft Windows XP 64-Bit Edition Version 2003
(Itanium)
- Microsoft Windows Server 2003
- Microsoft Windows Server 2003 for Itanium-based
Systems

- Review the FAQ section of bulletin MS05-013 for
information about these operating systems:
- Microsoft Windows 98
- Microsoft Windows 98 Second Edition (SE)
- Microsoft Windows Millennium Edition (ME)

- Impact: Remote Code Execution
- Version Number: 1.0

MS05-014 - Cumulative Security Update for Internet Explorer
(867282)

- Affected Software:
- Microsoft Windows 2000 Service Pack 3
- Microsoft Windows 2000 Service Pack 4
- Microsoft Windows XP Service Pack 1
- Microsoft Windows XP Service Pack 2
- Microsoft Windows XP 64-Bit Edition Service Pack 1
(Itanium)
- Microsoft Windows XP 64-Bit Edition Version 2003
(Itanium)
- Microsoft Windows Server 2003
- Microsoft Windows Server 2003 for Itanium-based
Systems

- Review the FAQ section of bulletin MS05-014 for
information about these operating systems:
- Microsoft Windows 98
- Microsoft Windows 98 Second Edition (SE)
- Microsoft Windows Millennium Edition (ME)

- Affected Components:
- Internet Explorer 5.01 Service Pack 3
- Internet Explorer 5.01 Service Pack 4
- Internet Explorer 5.5 Service Pack 2
- Internet Explorer 6 Service Pack 1
- Internet Explorer 6 for Windows XP Service Pack 1
(64-Bit Edition)
- Internet Explorer 6 for Windows Server 2003
- Internet Explorer 6 for Windows Server 2003 64-Bit
Edition and Windows XP 64-Bit Edition Version 2003
- Internet Explorer 6 for Windows XP Service Pack 2

- Impact: Remote Code Execution
- Version Number: 1.0

MS05-015 - Vulnerability in Hyperlink Object Library Could Allow
Remote Code Execution (888113)

- Affected Software:
- Microsoft Windows 2000 Service Pack 3
- Microsoft Windows 2000 Service Pack 4
- Microsoft Windows XP Service Pack 1
- Microsoft Windows XP Service Pack 2
- Microsoft Windows XP 64-Bit Edition Service Pack 1
(Itanium)
- Microsoft Windows XP 64-Bit Edition Version 2003
(Itanium)
- Microsoft Windows Server 2003
- Microsoft Windows Server 2003 for Itanium-based
Systems

- Review the FAQ section of bulletin MS05-015 for
information about these operating systems:
- Microsoft Windows 98
- Microsoft Windows 98 Second Edition (SE)
- Microsoft Windows Millennium Edition (ME)

- Impact: Remote Code Execution
- Version Number: 1.0

Important Security Bulletins
============================

MS05-004 - Vulnerability in ASP.Net May Lead to Authentication
Bypass (887219)

- Affected Software:
- Microsoft .NET Framework 1.0
- Microsoft .NET Framework 1.1

- Impact: Information Disclosure, and possible
Elevation of Privilege
- Version Number: 1.0

MS05-007 - Vulnerability in Windows Could Allow Information
Disclosure (888302)

- Affected Software:
- Microsoft Windows XP Service Pack 1
- Microsoft Windows XP Service Pack 2
- Microsoft Windows XP 64-Bit Edition Version 2003
(Itanium)

- Impact: Information Disclosure
- Version Number: 1.0

MS05-008 - Vulnerability in Windows Shell Could Allow Remote Code
Execution (890047)

- Affected Software:
- Microsoft Windows 2000 Service Pack 3
- Microsoft Windows 2000 Service Pack 4
- Microsoft Windows XP Service Pack 1
- Microsoft Windows XP Service Pack 2
- Microsoft Windows XP 64-Bit Edition Service Pack 1
(Itanium)
- Microsoft Windows XP 64-Bit Edition Version 2003
(Itanium)
- Microsoft Windows Server 2003
- Microsoft Windows Server 2003 for Itanium-based
Systems

- Impact: Remote Code Execution
- Version Number: 1.0

Moderate Security Bulletins
============================

MS05-006 - Vulnerability in Windows SharePoint Services and
SharePoint Team Services Could Allow Cross-Site
Scripting and Spoofing Attacks (887981)

- Affected Software:
- Windows SharePoint Services for Windows Server 2003
- SharePoint Team Services from Microsoft

- Impact: Remote Code Execution
- Version Number: 1.0

Update Availability:
===================
Updates are available to address these issues.
For additional information, including Technical Details,
Workarounds, answers to Frequently Asked Questions,
and Update Deployment Information please read
the Microsoft Security Bulletin Summary for this
month at: http://go.microsoft.com/fwlink/?LinkId=42105

Acknowledgments:
================
Microsoft thanks the following for working with us to protect
customers:

* Rafel Ivgi of Finjan (http://www.finjan.com) for reporting an issue
described in MS05-005.

* Jean-Baptiste Marchand of Herve Schauer Consultants
(http://www.hsc.fr) for reporting an issue described in MS05-007.

* Carlos Sarraute of Core Security Technologies
(http://www.corest.com) for reporting an issue described in
MS05-009.

* Kostya Kortchinsky (kostya.kortchinsky@renater.fr) of CERT RENATER
for reporting an issue described in MS05-010.

* eEye (http://www.eeye.com) for reporting an issue described in
MS05-012.

* Michael Krax (http://www.mikx.de) for working with us responsibly
on an issue described in MS05-014.

* Andreas Sandblad of Secunia (http://www.secunia.com) for reporting
an issue described in MS05-014.

* Jouko Pynnönen (http://jouko.iki.fi/index-en.html) for reporting an
issue described in MS05-014.

* Anna Hollingzworth (s53ur9ty_0x1ee1@yahoo.co.uk) for reporting an
issue described in MS05-015.
____________

Click and enter your name for your BOINC Statistics

Post to thread

Questions and Answers : Windows : Microsoft Security Bulletin Advance Notification

Home Help Status Forums Glossary Account


Return to Pirates@Home main page


Copyright © 2013 Capt. Jack Sparrow