Re: Alert: Microsoft Security Bulletin MS04-028 - Buffer Overrun in JPEG Processing (GDI+) Could Allow Code Execution (833987)

From: Barry Dorrans (barryd_at_IDUNNO.ORG)
Date: 09/14/04

  • Next message: Louis Solomon [SteelBytes]: "Re: Alert: Microsoft Security Bulletin MS04-028 - Buffer Overrun in JPEG Processing (GDI+) Could Allow Code Execution (833987)"
    Date:         Tue, 14 Sep 2004 20:15:08 +0100
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    What a bonus, the patch is not on windowsupdate, instead it downloads a GDI+
    detector, which then redirects you (once) to the actual bulletin at
    http://www.microsoft.com/technet/security/bulletin/ms04-028.mspx

    And lo, the Windows 2003 patch isn't actually there, the custom 404 is
    displayed.

    Even better, there's an update to both .net frameworks, but for me, on 3
    servers, the update to v1.0 does not install, claiming in the event log

    Product: Microsoft .NET Framework (English) -- Error 1706.No valid source
    could be found for product Microsoft .NET Framework (English). The Windows
    installer cannot continue.

    -----
    NTBugtraq Editor's Note:

    Want to reply to the person who sent this message? This list is configured such that just hitting reply is going to result in the message coming to the list, not to the individual who sent the message. This was done to help reduce the number of Out of Office messages posters received. So if you want to send a reply just to the poster, you'll have to copy their email address out of the message and place it in your TO: field.
    -----


  • Next message: Louis Solomon [SteelBytes]: "Re: Alert: Microsoft Security Bulletin MS04-028 - Buffer Overrun in JPEG Processing (GDI+) Could Allow Code Execution (833987)"

    Relevant Pages

    • Re: Video editing in Linux?
      ... >> this is an absolute world of difference from windows. ... but theres so much to take in just to install an audio app. ... I was under the impression that you sent the source code and a patch ...
      (alt.linux)
    • Re: Security update 823559
      ... I've figured out how to install the patch on Windows XP. ... that it created a temporary directory which was deleted as ...
      (microsoft.public.security)
    • Compass Rule Manger
      ... The errors above are caused by a known Worm Virus issue. ... patch to fix the issue for all of the effected systems ... effected Windows 2000 or Windows XP operating system. ... then download and install the MS04-011 patch from the ...
      (microsoft.public.windowsxp.security_admin)
    • Re: MS02-065 patch download
      ... The following patch can be installed on all affected platforms: ... > letting Microsoft probe my ass. ... > Anyone using Microsoft Windows 2000, Windows Me, Windows ... > install the patch immediately: ...
      (microsoft.public.security)
    • Re: Virus in microsoft Patch
      ... "Windows must restart because the Remote Procedure Call ... your system and install the patch mentioned above. ... You can also configure Automatic Updates to automatically ...
      (microsoft.public.windowsxp.security_admin)