Re: URGENT MICROSOFT SECURITY ANNOUNCEMENT

From: Eric (ewsat_private)
Date: Mon Jul 30 2001 - 14:05:09 PDT

  • Next message: Eric Lackey: "cold fusion 5.0 cfrethrow exploit"

    Patch has not been updated or re-released.  The NT4 patch should have a 
    file size of around 242,616.  Try expanding the hotfix with the /x 
    switch.  If it doesn't expand, you have a corrupted download - could be 
    something in a caching proxy server between you and the download server.
    
    The specific file in the patch is idq.dll - dated 5-25-2001 - with a file 
    version of 5.00.1781.3
    
    The NT4 post SP6a Security Rollup Package also contains the fix - the 
    idq.dll has been version incremented - but it is the same file - no 
    additional changes (version number incremented to aid in the installation 
    process to ensure that it gets on the box.)  The version number of the file 
    in the SRP is 5.00.1782.4
    
    More info on SRP:
    http://www.microsoft.com/technet/treeview/default.asp?url=/technet/itsolutions/security/news/nt4srp.asp
    
    --eric
    
    At 03:35 PM 7/30/2001 -0500, Andrew Greenburg wrote:
    >At 11:13 PM 7/30/2001 +0300, Dan Uscatu wrote:
    >>is anyone able to run that patch on winnt4 ? mine just says "error executing
    >>program" or "this is not a valid win32 application"... and yes i have tried
    >>several times to download it, including plain "save as...", reget, getright
    >>etc.
    >>
    >>duscatuat_private
    >
    >It worked fine for me, but they may have put a different revision in place 
    >since I downloaded it.
    >This patch is included in the Microsoft post-SP6a security rollup; You 
    >might try installing it instead:
    >http://support.microsoft.com/support/kb/articles/q299/4/44.asp?ID=299444
    >--
    >  Andrew M. Greenburg                   |   agreenbu  @  indianaone  .  net
    >  Web Site Administrator                |   (317)234-1001     (317)234-1328
    >  Indiana Web Academy                   |   Phone             Fax
    



    This archive was generated by hypermail 2b30 : Mon Jul 30 2001 - 19:45:25 PDT