Re: Windows Critical Update

From: Eric (ews@TELLURIAN.NET)
Date: 12/19/01


Date:         Wed, 19 Dec 2001 12:54:42 -0800
From: Eric <ews@TELLURIAN.NET>
To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM

The 01-058 patch is not yet included in Windows Update. Sometimes it takes
a while after the patch is released before it appears on Windows
Update. It looks like the 01-05 patch was just added to
WindowsUpdate. Since WIndows Update doesn't understand that 01-058 exists,
it doesn't know that 01-055 was superseded by 01-055. When WU scans your
machine, it doesn't see the reg entries for 01-055, (and it doesn't know
that it's been superseded), so it tells you you need the patch. False
positive in this case.

HFNetChk uses the mssecure.xml file which is updated with patch information
usually 4 to 6 hours after a patch is released. The XML file notes that
01-055 is superseded by 01-058 and hence won't even look for it if you're
running a version that has been superseded (in the default hfnetchk
configuration) It will report that you need 01-058, unless you've already
installed it, which you did, in which case you are up to date.

At 08:41 AM 12/19/2001 -0800, Bil Corry wrote:
>Russ,
>
>This is odd. I have the Windows Critical Updates Alert installed on my
>W2K box (which directs you to windowsupdate.microsoft.com when a "critical
>update" is available). It just alerted me to install:
>
> > Security Update, November 13, 2001 (Internet Explorer 6)
> > 447 KB/ Download Time: 1 min
> > This update resolves the "13 November 2001 Cumulative Patch for
> Internet Explorer"
> > security vulnerability in Internet Explorer 6, and is discussed in
> Microsoft
> > Security Bulletin MS01-055. Download now to prevent a malicious user
> from reading
> > or altering the cookies on your computer.
>
>However, HFNETCHK shows that I'm fully patched:
>
> > * Internet Explorer 6 Gold
> >
> > INFORMATION
> > All necessary hotfixes have been applied.
>
>Yesterday I installed IE6.0 (upgraded from IE5.5) then installed
>MS01-58. I never did install MS01-55 since MS01-58 was "Cumulative" and
>HFNETCHK showed that I was patched.
>
>So which is right? Critical Update or HFNETCHK?
>
><sigh>
>
>- Bil
>
>Delivery co-sponsored by VeriSign - The Internet Trust Company
>Protect your servers with 128-bit SSL encryption!
>Get VeriSign's FREE guide, "Securing Your Web Site for Business." You will
>learn everything you need to know about using SSL to encrypt your e-commerce
>transactions for serious online security. Click here!
>http://www.verisign.com/cgi-bin/go.cgi?a16065650057000

============================================================================
Delivery co-sponsored by VeriSign - The Internet Trust Company
============================================================================
Protect your servers with 128-bit SSL encryption!
Get VeriSign's FREE guide, "Securing Your Web Site for Business." You will
learn everything you need to know about using SSL to encrypt your e-commerce
transactions for serious online security. Click here!
http://www.verisign.com/cgi-bin/go.cgi?a=n016065650057000
============================================================================



Relevant Pages

  • Using Windows Update "SteppingMode" to grab patches and see silen t install switches.
    ... > I have received numerous messages about these two Security ... > Bulletins. ... Having the patch only be available on Windows Update is highly annoying ...
    (NT-Bugtraq)
  • RE: IIS on 443 replaced by serv-u
    ... It sounds like your system was compromised before installing the patch. ... More information on creating slip-streamed installs of Windows can ... Download the Security Patch Management Guide: ... It's important to not that not all security patches are offered by the ...
    (microsoft.public.inetserver.iis.security)
  • MS02-065 patch download
    ... Tell me where to download the said patch please! ... What You Should Know About Microsoft Security Bulletin ... Anyone using Microsoft Windows 2000, Windows Me, Windows ...
    (microsoft.public.security)
  • Just Released! Official Microsoft Security Update (KB12919)
    ... Microsoft Security Bulletin MS06-001 ... Vulnerability in Graphics Rendering Engine Could Allow Remote Code Execution ... Security Update for Windows XP ... | I plan on rolling this patch out to my organizaton and wanted to know if this ...
    (microsoft.public.windowsupdate)
  • Re: MS02-065 patch download
    ... >The following patch can be installed on all affected ... >> What You Should Know About Microsoft Security Bulletin ... >> Anyone using Microsoft Windows 2000, Windows Me, Windows ...
    (microsoft.public.security)