RE: Question: Buffer Overrun in Microsoft Data Access Components Could Lead to Code Execution (Q329414)

From: Brian W. Spolarich (bspolarich@nephrostherapeutics.com)
Date: 11/26/02

  • Next message: Andras Vass: "Re: Secure / Encrypt Terminal Services"
    Date: Tue, 26 Nov 2002 08:46:21 -0500
    From: "Brian W. Spolarich" <bspolarich@nephrostherapeutics.com>
    To: "Harris, Ken" <KHarris@HIPUSA.com>, <focus-ms@securityfocus.com>
    

    Harris, Ken wrote:

    > The reason I ask is that Microsoft does not seem to show much
    > confidence in this patch; e.g. in the Caveats section, it is implied
    > that if a webpage references the older, pre-patch RDS control,
    > dependent upon the IE security settings they will either be prompted
    > to install the control, or it will be installed silently if Microsoft
    > is added to the Trusted Publishers list.

      According to the MS docs:
     
      "Web server administrators who are running an affected version of MDAC should either install the patch, disable MDAC and/or RDS, or upgrade to MDAC 2.7, which is not affected by the vulnerability."

      Instead of applying the patch ato , why not just install MDAC 2.7 on the clients and servers (certainly starting w/ the server)? Is there something in the version of MDAC that you're running that will be broken by 2.7?

      -bws



    Relevant Pages

    • Re: Critical Alert Update - W32.Slammer
      ... The .net SDK 1.0 sp1 comes with a very basic SQL Server engine for testing ... >> Microsoft SQL Desktop ... >>>cumulative SQL security patch, is completely safe from ... >> may install SQL ...
      (microsoft.public.security)
    • Critical Alert Update - W32.Slammer
      ... It's not clear if SQL Server 2000 SP1/SP2 includes the ... Microsoft SQL Desktop ... and all applications that install ... >most recent cumulative SQL Server security patch, ...
      (microsoft.public.security)
    • Re: Problems installing critical update
      ... this patch (Security Update for Microsoft XML Core Services 4.0 for Service ... the message is still there when I reboot. ... Microsoft Update to require me to install both KB936181 and KB933579. ...
      (microsoft.public.windowsupdate)
    • Re: Microsoft notice on W32.Slammer
      ... >PSS Security Response Team Alert - New Worm: ... >1434 utilizing a vulnerability that was patched in Microsoft Security ... > Microsoft, however, recommends that customers install the most recent ... >cumulative security patch for Microsoft SQL Server 2000 which is Microsoft ...
      (microsoft.public.sqlserver.security)
    • Re: Shame on Microsoft
      ... Download the patch and remind the user to install. ... every Start Menu since, when, Windows 98? ... Microsoft can't be blamed for ...
      (microsoft.public.security)