myITforum.com Community Forum myITforum.com Community Forum

Home  Forums  Blogs  Live Support chat  Search Articles  Wiki  FAQ  Email Lists  Register  Login  My Profile  Inbox  Address Book  My Subscription  My Forums 

Photo Gallery  Member List  Search  Calendars  FAQ  Ticket List  Log Out

All Forums RSS Feed Subscription:


  


Updated 21/08: Microsoft Security Patches - August 2008

 
View related threads: (in this forum | in all forums)

Logged in as: Guest
  Printable Version
All Forums >> [Security, AntiVirus, and Patching] >> Breaking Virus & Security News >> Updated 21/08: Microsoft Security Patches - August 2008 Page: [1]
Login
Message << Older Topic   Newer Topic >>
Updated 21/08: Microsoft Security Patches - August 2008 - 8/12/2008 6:08:37 PM  1 votes
awenlock


Posts: 352
Score: 186
Joined: 3/8/2005
Status: offline
Well after a quiet few months its a busy Patch Tuesday for August.  A total of 11 patches have been released today, 6 Critical and 5 Important.  It looks like the patch for Media Player that would have made it 12 patches this month was not released.

This months patches are:

>MS08-041  Vulnerability in the ActiveX Control for the Snapshot Viewer for Microsoft Access Could Allow Remote Code Execution (955617)

Affects: Microsoft Access 2000/XP/2003
Link: http://www.microsoft.com/technet/security/Bulletin/MS08-041.mspx


>MS08-042  Vulnerability in Microsoft Word Could Allow Remote Code Execution (955048)

Affects: Microsoft Word XP/2003
Link: http://www.microsoft.com/technet/security/Bulletin/MS08-042.mspx


>MS08-043  Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (954066)

Affects: Microsoft Excel 2000/XP/2003/2007, Excel Viewer 2003, Office Compatibility Pack 2007, Office Sharepoint Server & Office 2004/8 for Mac
Link: http://www.microsoft.com/technet/security/Bulletin/MS08-043.mspx


>MS08-044  Vulnerabilities in Microsoft Office Filters Could Allow Remote Code Execution (924090)

Affects: Office 2000/XP/2003, Project 2002, Office Converter Pack, Works 8
Link: http://www.microsoft.com/technet/security/Bulletin/MS08-044.mspx


>MS08-045  Cumulative Security Update for Internet Explorer (953838)

Affects: Internet Explorer
Link: http://www.microsoft.com/technet/security/Bulletin/MS08-045.mspx


>MS08-046  Vulnerability in Microsoft Windows Image Color Management System Could Allow Remote Code Execution (952954)

Affects: Windows 2000, XP, XP x64, Server 2003 (Inc x64)
Link: http://www.microsoft.com/technet/security/Bulletin/MS08-046.mspx


>MS08-047  Vulnerability in IPsec Policy Processing Could Allow Information Disclosure (953733)

Affects: Vista, Microsoft Server 2008 (inc x64)
Link: http://www.microsoft.com/technet/security/Bulletin/MS08-047.mspx


>MS08-048  Security Update for Outlook Express and Windows Mail (951066)

Affects: Outlook Express/Windows Mail
Link: http://www.microsoft.com/technet/security/Bulletin/MS08-048.mspx


>MS08-049  Vulnerabilities in Event System Could Allow Remote Code Execution (950974)

Affects: Microsoft Windows
Link: http://www.microsoft.com/technet/security/Bulletin/MS08-049.mspx


>MS08-050  Vulnerability in Windows Messenger Could Allow Information Disclosure (955702)

Affects: Windows Messenger 4.7 / 5.1
Link: http://www.microsoft.com/technet/security/Bulletin/MS08-050.mspx


>MS08-051  Vulnerabilities in Microsoft PowerPoint Could Allow Remote Code Execution (949785)

Affects: Powerpoint 2000/XP/2003/2007
Link: http://www.microsoft.com/technet/security/Bulletin/MS08-051.mspx   


Time to go and dust down those extra test machines and get testing all these patches.  The most critical patch this month appears to be the one for Internet Explorer, MS08-045, so if you need a priority I'd start with that one.

Useful Links: 

Microsoft: http://www.microsoft.com/technet/security/bulletin/ms08-aug.mspx
MS Blog: http://blogs.technet.com/msrc/archive/2008/08/12/august-2008-monthly-bulletin-release.aspx
ISC: http://isc.sans.org/diary.html?storyid=4876



Regards
Alan

< Message edited by awenlock -- 9/9/2008 4:23:57 PM >
Post #: 1
RE: Microsoft Security Patches - August 2008 - 8/13/2008 4:30:23 PM   
hwaldron


Posts: 3586
Score: 264
Joined: 9/12/2002
From: Roanoke VA, USA
Status: offline
Thanks Alan - Excellent summary as always ... The IE update is rated as "PATCH NOW" by the ISC, and this is a very beneficial patch for MS/Office as many components got needed updates. 

This "bumper crop" of updates this month should be applied promptly.  I almost called it the "Dirty Dozen"    

So far, so good on my three XP SP3 systems at work and home 

< Message edited by hwaldron -- 8/13/2008 4:31:36 PM >


_____________________________


Harry Waldron - Security News & Best Practices Blog

(in reply to awenlock)
Post #: 2
RE: Microsoft Security Patches - August 2008 - 8/21/2008 2:58:38 PM   
awenlock


Posts: 352
Score: 186
Joined: 3/8/2005
Status: offline
Just to update that Microsoft have today re-released the MS08-051 update for Microsoft Powerpoint 2003.

quote:


Microsoft has posted new update packages, labeled Version 2, to the Microsoft Download Center for Microsoft Office PowerPoint 2003 Service Pack 2 and Microsoft Office PowerPoint 2003 Service Pack 3. Customers who manually installed Version 1 of this update from Microsoft Download Center need to reinstall Version 2 of this update. Customers who have installed this update using Microsoft Update or Office Update do not need to reinstall.

Why was this bulletin revised on August 20, 2008? 
Microsoft revised this bulletin to note that new update packages have been posted to the Microsoft Download Center for Microsoft Office PowerPoint 2003 Service Pack 2 and Microsoft Office PowerPoint 2003 Service Pack 3. The bulletin has also been revised to remove erroneous mitigations from the vulnerability information sections for Memory Allocation Vulnerability - CVE-2008-0120 and Memory Calculation Vulnerability - CVE-2008-0121.

How do I know whether I have the latest version of the update for Microsoft Office PowerPoint 2003 Service Pack 2 and Microsoft Office PowerPoint 2003 Service Pack 3 installed on my system?
Customers can check the file version of powerpnt.exe on their systems to determine whether the latest version of the update is installed. Customers with version 11.0.8227.0 of powerpnt.exe on their systems have the latest version of the update and do not need to take any further action. Customers with version 11.0.8212.0 of powerpnt.exe on their systems have the incorrect version of the update installed

The incorrect version of the update for Microsoft Office PowerPoint 2003 Service Pack 2 and Microsoft Office PowerPoint 2003 Service Pack 3 is installed on my system. What are the options for protecting my system? 
The initial packages that were released to the Microsoft Download Center earlier on August 12, 2008, labeled Version 1, contained incorrect versions of the binaries. While these versions did protect against the vulnerabilities discussed in the bulletin, they lacked other important security and reliability updates. This only affected the packages on the Microsoft Download Center; Microsoft Update and Office Update contained and were distributing the correct versions of the binaries and did not need to be updated. Customers who successfully deployed these updates through Microsoft Update or Office Update need not take any action. Those customers who deployed the update manually from the Microsoft Download Center prior to this update of the package (labeled Version 2) need to perform one of the following actions:

•Reinstall this latest version of the update, labeled Version 2, from the Microsoft Download Center manually. Please refer to the Affected Software table for the location of the latest packages for Microsoft Office PowerPoint 2003 Service Pack 2 and Microsoft Office PowerPoint 2003 Service Pack 3 on the Microsoft Download Center.

•Reinstall the update by using Microsoft Update or Office Update to automatically scan and offer the correct update.

•If you choose to not reinstall the update, you must manually set the registry key as described in Microsoft Knowledge Base Article 938810 in order to block PowerPoint file types as a workaround.


You can read the full details of MS05-058 here: http://www.microsoft.com/technet/security/Bulletin/MS08-051.mspx

So in Summary if you rolled out version 1 by downloading it via the download centre then you will need to get V2.


Regards
Alan

(in reply to hwaldron)
Post #: 3
Page:   [1]
All Forums >> [Security, AntiVirus, and Patching] >> Breaking Virus & Security News >> Updated 21/08: Microsoft Security Patches - August 2008 Page: [1]
Jump to:





New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts



  
Forum Software © ASPPlayground.NET Advanced Edition 2.4.5 ANSI

0.250