Problems with Hyperion and MS03-045

From: Russ (Russ.Cooper_at_RC.ON.CA)
Date: 10/28/03

  • Next message: James Foster: "Foundstone Labs to Release Absolutely FREE Tool"
    Date:         Tue, 28 Oct 2003 12:08:00 -0500
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    I received the following today;

    -----
    Russ,
            I just received this from the company who makes Hyperion:

    ------------------------------------------------------------------------
    ----------------------------------
    Microsoft Security Bulletin MS03-045
    ------------------------------------
    Buffer Overrun in the ListBox and in the ComboBox Control Could Allow
    Code Execution (824141)

    Issue: After installing this hotfix, multiple digits appear when you
    enter a single digit. For example, In Data Entry, enter a 1 in a cell
    and it will appear as 11. Occurs in Enterprise 5.X versions and higher.
    Not an issue with Enterprise SE.

    Cause:
    The hotfix patch addresses an issue with the User32.dll file, and this
    affects keystrokes, which is where the issue is occurring.

    Resolution:
    The only resolution at the moment is to completely remove the hotfix. It
    needs to be removed at both the server(s) (including Citrix) and the
    workstation(s) for all users.
    It can be removed via the Control Panel->Add/Remove Programs->and
    clicking the Hotfix kb824141 and choosing Remove.
    The servers/workstations will need to be re-booted after removed.

    To receive more detailed information, including a possible workaround as
    opposed to installing the patch, you can click on the following link and
    look for the workaround expansion. The below link lists all the detailed
    information related to this issue, as well as contact information for
    Microsoft.
    http://www.microsoft.com/technet/treeview/default.asp?url=/technet/secur
    ity/bulletin/MS03-045.asp

    ------------------------------------------------------------------------
    -------------------------------------

    The only solution now is to uninstall the patch

    -----
    Cheers,
    Russ - NTBugtraq Editor

    ----
    NTBugtraq subscribers save $103.00 off the TICSA exam by using promo
    code "NT1003" when registering to take the TICSA exam at www.2test.com.
    Prove to your employer and peers that you have the knowledge and
    abilities to be an active stakeholder in today's enterprise security.
    Become TICSA certified www.trusecure.com/ticsa.  Promotion expires
    12/31/03 and cannot be used in combination with other offers.
    ----
    

  • Next message: James Foster: "Foundstone Labs to Release Absolutely FREE Tool"

    Relevant Pages

    • Re: Potential MAJOR bug in KB969604?
      ... Word MVP web site http://word.mvps.org ... possible hotfix ID is KB970942 and I think it will be published soon. ... issue after installing the update KB969604 on my test machine. ... document variables in the document become corrupt. ...
      (microsoft.public.word.docmanagement)
    • Re: Potential MAJOR bug in KB969604?
      ... this with KB969604 installed resolves the issue (no uninstall required). ... found and our Product Team is testing a hotfix. ... installing the update KB969604 on my test machine. ... document variables in the document become corrupt. ...
      (microsoft.public.word.docmanagement)
    • RE: MS03-031 on WS03 SP1
      ... Based on my test, after installing WSS SP1 on Windows Server 2003 SP1, MBSA ... The build number of SQLSERVR.EXE and HotFix package did not match. ... Microsoft provides third-party contact information to help you find ... Microsoft Online Partner Support ...
      (microsoft.public.sqlserver.security)
    • Re: Publisher Cannot Open the File
      ... I have experienced the same problems after installing Office updates. ... This is Publisher 2007 (thus the reason I applied the hotfix after ... with no success. ... listed and still receive the same "Publisher cannot open the file" error. ...
      (microsoft.public.publisher)
    • Re: USB Drive not recognized - Driving me crazy!!!
      ... to obtain a hotfix from MS you must call product support. ... machines where the system wants to look for a driver then can't find one. ... I am having a very similar problem installing a USB phone for a USB 2.0 port ... There is a software problem and mine was caused by Windows Update. ...
      (microsoft.public.windowsxp.help_and_support)