Re: Q811114 and Q815021

From: Anthony Kim (Anthony.Kim_at_VWCREDIT.COM)
Date: 07/03/03

  • Next message: Celeste Hilliard: "Re: SP4 installation failure"
    Date: Thu, 3 Jul 2003 16:19:15 -0500
    To: focus-ms@securityfocus.com
    
    

    On Thu, Jul 03, 2003, Floyd Russell wrote:

    > I'm confused by Windows Update ( not suprising ). According to Windows
    > Update I need to install Q815021 however, Q811114 is installed. Should the
    > latter, being a "Cumulative Patch", already include Q815021? I would think
    > so. Anyone else notice this - Windows NT Server 4.0 only.

    Q811114 does not contain the updated ntdll.dll patch found in
    Q815021.

    The WebDAV/ntdll.dll patch (815021) was not built for NT back in
    March... Even though the original attack vector for the
    vulnerability, WebDAV, which prompted the patch, is not
    available for NT, the core vulnerability in ntdll.dll still
    exists in NT and as they found out also in XP.

    The revised 815021 which came out a little later than the
    811114 cumulative IIS patch addresses these issues.

    http://support.microsoft.com/?kbid=815021

    -----------------------------------------------------------------------------
    ------------------------------------------------------------------------------


  • Next message: Celeste Hilliard: "Re: SP4 installation failure"

    Relevant Pages

    • Re: [alsa-devel] [regression] 2.6.25-rc4 snd-es18xx broken on Alpha
      ... The current arch/alpha/kernel/Makefile build logic shows es1888.o built ... I have never relied on this routine for anything. ... without the alternative es188xx interupt patch) associated with either ... I *seldom* use the Debian generic kernel. ...
      (Linux-Kernel)
    • Re: LKEvent situation on Tru64 5.1b win Ingres 2.6 0305
      ... there has not been any patch built for axp.osf - looking at you issue ... once it happened the only was forward was a bounce of Ingres. ... *Sessions Stuck in LKEVENT State* ...
      (comp.databases.ingres)
    • Re: [PATCH] gpiolib: Allow user-selection
      ... architecture code didn't request to get it built in. ... I assume this patch was prepared against some ancient out-of-date ...
      (Linux-Kernel)
    • Permissions not being inherited from parent directory to certain f
      ... We have a number of Windows 2003 servers, basically those built from around ... It's causing an issue with users logon scripts ... My thoughts were that maybe a patch could be causing ... As an aside a colleagues XP laptop also has the same setting. ...
      (microsoft.public.platformsdk.security)
    • Re: What is the motivation for Virus Writers?
      ... Speak to the shop that built it. ... >> more write them and send them to virus companies and don't let them ... > every patch at microsoft. ...
      (microsoft.public.security.virus)