SUS broken upon installing KB867460 (.NET Framework 1.1 SP1)

From: Joe Conner (JoeC_at_GSIINC.COM)
Date: 09/14/04

  • Next message: Bjarne Carlsen: "Re: Alert: Microsoft Security Bulletin MS04-028 - Buffer Overrun in JPEG Processing (GDI+) Could Allow Code Execution (833987)"
    Date:         Tue, 14 Sep 2004 14:23:46 -0400
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    Subject: MS Incident SRZ040913003548. BKUP01 SUS error
    Date: Mon, 13 Sep 2004 20:46:40 +0000

    SRZ040913003548 <javascript:{if (typeof(Page_ClientValidate) != 'function'
    || Page_ClientValidate()) __doPostBack('IncNo','')}>
    Windows Server 2003 Standard
    Problem Description: Working perfectly for months. All latest applicable
    updates applied. Via Windows Update site, updated only one update, KB867460
    (.NET Framework SP1) (which was offered in critical updates). Restarted as
    requested.

     Now, trying to access SUSAdmin website (this server is an SUS server),
    several errors in Event Viewer,
    Application log: ID: 2269, The worker process failed to initialize the
    http.sys communication or the W3svc communication layer and therefore could
    not be started. The data field contains the error number. Data: (Word):
    80070005.

     Tried uninstalling this update via $ folder in \Windows, restarted, similar
    errors. Reinstalled the update.
    Tried removing / adding IIS (Application Services) again, error is back
    exactly.
    Tried re-installing SUS, same error.
    Of note, in IIS Admin, "Application Pools",. . . DefaultAppPool is started.
    Trying to run SUS, webpage gives only "Service Unavailable" after about 5
    seconds. At that time, the "DefaultAppPool" is stopped, and the Event ID
    2269 is repeated 5 times in the Application log, about 1 second apart.
    All other functions are okay so far, have not had been able to test
    everything yet.

    This is a rather simple server, main installed software is Symantec
    Anti-Virus corp. edition 9.0.0.338, Veritas BackupExec (latest version) 9.1

    The problem appears to be associated with the update I applied, no prior
    significant problems with SUS, or the server in general really.
    Problem Area: Other
    Frequency of problem: Always Happens
    Operating system / version: Windows 2003
    ---------------------
    Spoke with MS tech support. Problem solved by adding local IIS_WPG group to
    have "Bypass Traverse Checking" user right. Tech support also had me add
    local "Everyone" group to "Bypass Traverse Checking", citing this would be
    no problem, although it is unclear whether this is needed to resolve this
    issue.

      _____

    Joe Conner, MCSE(NT4,2003), MCSA 2003
    JoeC@gsiinc.com <mailto:JoeC@gsiinc.com>

    -----
    NTBugtraq Editor's Note:

    Want to reply to the person who sent this message? This list is configured such that just hitting reply is going to result in the message coming to the list, not to the individual who sent the message. This was done to help reduce the number of Out of Office messages posters received. So if you want to send a reply just to the poster, you'll have to copy their email address out of the message and place it in your TO: field.
    -----


  • Next message: Bjarne Carlsen: "Re: Alert: Microsoft Security Bulletin MS04-028 - Buffer Overrun in JPEG Processing (GDI+) Could Allow Code Execution (833987)"

    Relevant Pages

    • Re: Microsoft SUS on Apache?
      ... Group Policy which tells domain member machines to get their Windows ... believe by default with Windows XP (SUS doesn't provide patches for OS's ... way that client machines can get updates from an SUS server that I'm ... > for a Microsoft Server license to run it. ...
      (Security-Basics)
    • RE: Deploying Microsoft patches
      ... Try SUS from M$. ... windows update server for your organization. ... You can't use SUS to deploy your own updates (you can use this tool to ...
      (Security-Basics)
    • Re: Upgrading from SUS to WSUS
      ... About those policies for WSUS, ... How to install Windows Server Update Services on SBS 2003: ... Well i never got SUS to actually update my ... > Config, then Admin, Temp, ten Windows Components, and Windows Update. ...
      (microsoft.public.windows.server.sbs)
    • Re: User autentification and access to "sister" domain resources
      ... As to SUS... ... I don't see why it wouldn't work as long as the host can resolve the server ... > siteA and another rootDC2 in siteB. ... > - link to all DCs from domain A is suddenly broken, ...
      (microsoft.public.win2000.active_directory)
    • Re: SUS Group Policy
      ... I would suggest that you take a look at the Softwareupdatesvcs NG as there ... This is the homepage for SUS. ... it on a server of your choice. ... > running under a Windows 2000 Active Directory. ...
      (microsoft.public.win2000.active_directory)