Previous Thread
Next Thread
Print Thread
Rate Thread
Joined: Jun 2001
Posts: 2,849
Spotlight Winner
Spotlight Winner
Offline
Joined: Jun 2001
Posts: 2,849
Got this in my inbox today. Seems that they DO proactively release patches. Sorry, but it's true.

Quote
quote:
- --------------------------------------------------------------------
Title: Microsoft Windows Security Bulletin Summary for
January 2004
Issued: January 13, 2004
Version Number: 1.0
Bulletin:
http://www.microsoft.com/technet/security/bulletin/winjan04.asp

- --------------------------------------------------------------------

Summary:
========
Included in this advisory is an update for a newly discovered vulnerability in Microsoft Data Access Components (MDAC).
This vulnerability is rated Important.

MS04-003 - Buffer Overrun in MDAC Function Could Allow Code
Execution (832483)

- Affected Software:
- Microsoft Data Access Components 2.5 (included with
Microsoft Windows 2000)
- Microsoft Data Access Components 2.6 (included with
Microsoft SQL Server 2000)
- Microsoft Data Access Components 2.7 (included with
Microsoft Windows XP)
- Microsoft Data Access Components 2.8 (included with
Microsoft Windows Server 2003)

- Impact: Remote Code Execution
- Version Number: 1.0


Update Availability:
===================
An update is available to fix this vulnerability.
For additional information, including Technical Details, Workarounds, answers to Frequently Asked Questions, and Update Deployment Information please read the Microsoft Windows Security Bulletin Summary for January at:
http://www.microsoft.com/technet/security/bulletin/winjan04.asp

Support:
========
Technical support is available from Microsoft Product Support Services at 1-866-PC SAFETY (1-866-727-2338). There is no charge for support calls associated with security patches.
International customers can get support from their local Microsoft subsidiaries. Phone numbers for international support can be found
at:
http://support.microsoft.com/common/international.aspx

Additional Resources:
=====================
* Microsoft has created a free monthly e-mail newsletter containing
valuable information to help you protect your network. This
newsletter provides practical security tips, topical security
guidance, useful resources and links, pointers to helpful
community resources, and a forum for you to provide feedback
and ask security-related questions.
You can sign up for the newsletter at:

http://www.microsoft.com/technet/security/secnews

* Join our Microsoft webcast for a live discussion of the technical
details of the January security bulletins and steps you can take
to protect your environment. Details can be found at:

http://msevents.microsoft.com/CUI/EventDetail.aspx?
EventID=1032241586&Culture=en-US

* Protect your PC: Microsoft has provided information on how you
can help protect your PC at the following locations:

http://www.microsoft.com/security/protect/

If you receive an e-mail that claims to be distributing a
Microsoft security patch, it is a hoax that may be distributing a
virus. Microsoft does not distribute security patches via e-mail.
You can learn more about Microsoft's software distribution
policies here:

http://www.microsoft.com/technet/security/policy/swdist.asp


Revisions:
==========
* V1.0 January 13, 2004: Bulletin Created.
********************************************************************
Protect your PC: Microsoft has provided information on how you can help protect your PC at the following locations:
http://www.microsoft.com/security/protect/

If you receive an e-mail that claims to be distributing a Microsoft security patch, it is a hoax that may be distributing a virus. Microsoft does not distribute security patches via e-mail.
You can learn more about Microsoft's software distribution policies here:
http://www.microsoft.com/technet/security/policy/swdist.asp
********************************************************************
- --------------------------------------------------------------------
THE INFORMATION PROVIDED IN THE MICROSOFT KNOWLEDGE BASE IS PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE.
IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING LIMITATION MAY NOT APPLY.
- --------------------------------------------------------------------

Sponsored Links
Joined: Nov 2003
Posts: 61
Power User
Power User
Offline
Joined: Nov 2003
Posts: 61
Yikes, OMG, I run Windows XP, I just got a Hotfix update from Microsoft. Am I at risk now??

Joined: Jun 2001
Posts: 2,849
Spotlight Winner
Spotlight Winner
Offline
Joined: Jun 2001
Posts: 2,849
No, this is the notification for the hotfix you just got.

Joined: Nov 2003
Posts: 61
Power User
Power User
Offline
Joined: Nov 2003
Posts: 61
Thanks Randy for the Clarification!!

Joined: Jan 2000
Posts: 5,833
Likes: 20
UBBDev / UBBWiki Owner
Time Lord
UBBDev / UBBWiki Owner
Time Lord
Joined: Jan 2000
Posts: 5,833
Likes: 20
heh, I dl hotfixes once a week :x... thinking about formatting completely and going to FreeBSD...


UBB.Dev - Putting Dev into UBB.threads
Company: VNC Web Services - UBB.threads Scripts and Scripting, Install and Upgrade Services, Site and Server Maintenance.
Forums: A Gardeners Forum, Scouters World, and UGN Security
UBB.Threads: My UBB Themes, My UBB Scripts
Sponsored Links

Link Copied to Clipboard
Donate Today!
Donate via PayPal

Donate to UBBDev today to help aid in Operational, Server and Script Maintenance, and Development costs.

Please also see our parent organization VNC Web Services if you're in the need of a new UBB.threads Install or Upgrade, Site/Server Migrations, or Security and Coding Services.
Recommended Hosts
We have personally worked with and recommend the following Web Hosts:
Stable Host
bluehost
InterServer
Visit us on Facebook
Member Spotlight
Gizmo
Gizmo
Portland, OR, USA
Posts: 5,833
Joined: January 2000
Forum Statistics
Forums63
Topics37,573
Posts293,925
Members13,849
Most Online5,166
Sep 15th, 2019
Today's Statistics
Currently Online
Topics Created
Posts Made
Users Online
Birthdays
Top Posters
AllenAyres 21,079
JoshPet 10,369
LK 7,394
Lord Dexter 6,708
Gizmo 5,833
Greg Hard 4,625
Top Posters(30 Days)
Top Likes Received
isaac 82
Gizmo 20
Brett 7
WebGuy 2
Morgan 2
Top Likes Received (30 Days)
None yet
The UBB.Developers Network (UBB.Dev/Threads.Dev) is ©2000-2024 VNC Web Services

 
Powered by UBB.threads™ PHP Forum Software 8.0.0
(Preview build 20221218)