Problems with MS03-042 (KB826232) patch?

From: Jerry Heidtke (jheidtke_at_FMLH.EDU)
Date: 10/17/03

  • Next message: Mullins, Walter A.: "MS 03-041 and SSL Certificates"
    Date:         Fri, 17 Oct 2003 16:32:25 -0500
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    On a variety of computers ranging from Windows 2000 SP2 to SP4 plus all
    previous patches, whenever the KB826232 patch is installed, then other
    patches/service packs/whatever is installed, while attempting to remove
    the KB826232 patch results in warning messages that whatever was
    installed after this patch may no longer work.

    We found this because we always test backout procedures before deploying
    patches to the entire enterprise.

    For example, on one computer that had Windows 2000 SP2, we installed
    KB826232 and then the other critical patches from 10/15. We then
    installed SP4. When attempting later to uninstall KB826232, we get a
    warning that Internet Explorer, Windows Media Player, and other patches
    installed after KB826232 might be non-functional if we proceeded. We
    tested Windows Media Player and it was, in fact, non-functional (it
    could download a video clip and display that it was playing, it just
    couldn't display any video... a minor inconvenience I guess).

    The same symptoms were found on a freshly installed Win2k with SP4 and
    IE6 SP1, and no other software installed.

    Has anyone else found any issues with this patch?

    Jerry

    Confidentiality Notice: This e-mail message, including any attachments,
    is for the sole use of the intended recipient(s) and may contain
    confidential and privileged information. Any unauthorized review, use,
    disclosure or distribution is prohibited. If you are not the intended
    recipient, please contact the sender by reply e-mail and destroy all
    copies of the original message.

    ----
    NTBugtraq subscribers save $103.00 off the TICSA exam by using promo
    code "NT1003" when registering to take the TICSA exam at www.2test.com.
    Prove to your employer and peers that you have the knowledge and
    abilities to be an active stakeholder in today's enterprise security.
    Become TICSA certified www.trusecure.com/ticsa.  Promotion expires
    12/31/03 and cannot be used in combination with other offers.
    ----
    

  • Next message: Mullins, Walter A.: "MS 03-041 and SSL Certificates"

    Relevant Pages

    • Re: Conflicting info between the global Security Bulletin and some SPi Security Bulletin
      ... The MS02-050 is explicitly listed as included in SP4 AND in Rollup 1 ... I think the correct answer is that it depends on the era of the patch. ... installers do not always use such ... patches later than the end of 2002 are ...
      (microsoft.public.win2000.security)
    • Re: Learning process
      ... a million users on Windows would be ... Most of the patches are fixes for problems in security and a lot of ... pile of games or the SQL blaster which required 2 patchs - patch 1, ... holes *aren't* patched almost immediately. ...
      (alt.comp.lang.learn.c-cpp)
    • So Windows Update is a dog, now what?
      ... extension, that means that the soon-to-be-released Windows Update, ... How about someone getting serious about patch management over at ... In their explanation of the severity rating scheme, the Microsoft ... incredibly reliable mechanism for getting patches onto systems, ...
      (NT-Bugtraq)
    • Re: Windows patch mgmt.
      ... Subject: Windows patch mgmt. ... St. Benard's Update Expert to push out the patches and to verify they've ... to facilitate one-on-one interaction with one of our expert instructors. ...
      (Security-Basics)
    • RE: [Full-Disclosure] Whos to blame for malicious code?
      ... >> windows admins were and remain just plain lazy, ... > deploying patches to an enterprise in a timely manner. ... the problem is solved and the malicious code has no impact. ... this patch undoes what last weeks patches did. ...
      (Full-Disclosure)