MS silently changing security patches

From: Francis Favorini (francis.favorini@DUKE.EDU)
Date: 04/10/02


Date:         Wed, 10 Apr 2002 16:34:35 -0400
From: Francis Favorini <francis.favorini@DUKE.EDU>
To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM

Hi,
        Just thought I'd pass this along. Microsoft has silently changed
the patch in MS02-008 (at least the MSXML 3.0 version). The old patch I
downloaded on 2/22/02 had version 8.20.9307.0 of msxml3.dll. The version I
downloaded today has version 8.20.9415.0. There is no indication in the
security bulletin that anything has changed. HFNetChk alerted me that the
file version did not match.
        The same thing happened last month with MS02-009. The patch
silently changed, although the bulletin did get updated later. It's
possible that this is simply due to a delay in the revised bulletin getting
propagated to all the web servers. I hope this is the case.
        On a semi-related note, does anyone know why HFNetChk complains that
MS02-016 is not applied to a Win2K server that is not a domain controller?
Is it just because it can't identify DC's, or is there some reason to apply
it?

-Francis



Relevant Pages

  • Re: Q822925 problem
    ... Here's a link to the bulletin for this patch, ... Microsoft originally issued this bulletin on August 20th, ... systems that are configured as web servers serving ASP.NET web pages and ...
    (microsoft.public.security)
  • Re: Q822925 problem
    ... Here's a link to the bulletin for this patch, ... Microsoft originally issued this bulletin on August 20th, ... systems that are configured as web servers serving ASP.NET web pages and ...
    (microsoft.public.security)
  • Re: Conflicting info between the global Security Bulletin and some SPi Security Bulletin
    ... According the Security Bulletin for the release of SP4, ... you will see that the updated patch was first included in SP3 ... Later, install of an older ...
    (microsoft.public.win2000.security)
  • Re: Microsoft Security Bulletin MS02-057
    ... For everyone's information, the patch is already available, and the issue is ... Flaw in Services for Unix 3.0 Interix SDK Could Allow Code ... > The Microsoft Security Response Center has released Microsoft Security ... > Bulletin MS02-057 ...
    (microsoft.public.security)
  • Re: Microsoft Security Bulletin MS02-057
    ... For everyone's information, the patch is already available, and the issue is ... Flaw in Services for Unix 3.0 Interix SDK Could Allow Code ... > The Microsoft Security Response Center has released Microsoft Security ... > Bulletin MS02-057 ...
    (microsoft.public.win2000.security)