MS-065 (q329414) and MDAC 2.7
From: Trevor Metzger (trevorm_xcg@yahoo.ca)
Date: 11/22/02
- Next message: Wes Tanney: "Re: MS02-065 patch download"
- Previous message: Ron: "Certificate Revocation List (CRL) problem w/ Outlook XP"
- In reply to: Cees: "MS-065 (q329414) and MDAC 2.7"
- Next in thread: mapsonx: "Re: MS-065 (q329414) and MDAC 2.7"
- Reply: mapsonx: "Re: MS-065 (q329414) and MDAC 2.7"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: "Trevor Metzger" <trevorm_xcg@yahoo.ca> Date: Fri, 22 Nov 2002 06:32:29 -0800
I had a similar experience. On Nov. 21 I noticed the MS-
065 (q329414) security update (It said MDAC2.5) for my
Win98se box.
After reading q329414 (especially the part about the lack
of a kill bit and the vulnerability to a malicious silent
re-introduction of the old version, I decided NOT to do
the patch but rather install MDAC 2.7. (The MS-065
(q329414) document DOES say that updating to MDAC 2.7 is
an option. It also says that MDAC 2.7 is not vulnerable.)
First I downloaded and ran the MDAC component checker and
it said I had "MDAC 2.5 RTM (2.50.4403.12). I installed
MDAC 2.7 (2.70.9001.0). It installed successfully and I
rebooted and ran MDAC component checker to confirm. All
seemed OK.
But then when I went to Windows Update, it flagged that I
needed "Q329414 Security Update (MDAC 2.1)" Note that
before updating to MDAC 2.7, Windows update had said MDAC
2.5 (correctly).
Just in hope of getting the "Q329414" off my critical
update list, I tried installing it. It said that install
was successful and I rebooted. After rebooted I tried
Windows update. The "Q329414" critical update was still
there! What's up with this?
I often do a file date/time/size compare before and after
updates and I noticed that the Q329414 update seems to
replace the contents of c:\windows\dahotfix.log. An
examination of this files shows lines that says the
following:
[start of file excerpts]
[13:48:05]: Detected an MDAC installation, but it is
newer than 2.1.
[13:48:05]: Loading function (CheckMDACVersionExact) from
internal function list.
[13:48:05]: Checking version of Microsoft Data Access
Components that is currently installed on the machine.
[13:48:05]: An error occurred while setup was trying to
verify the version of Microsoft Data Access Components
current installed on the machine.
Either the version currently installed does not
match the version of this hotfix package, or setup was
unable to determine the version currently installed.
[13:48:05]: The action (NULL!CheckMDACVersionExact)
returned FALSE.
[13:48:05]: The action NULL!CheckMDACVersionExact returned
FALSE.
[end of file excerpts]
(my entire dahotfix.log file is attached to this message)
My hypothesis is that Windows update Q329414 does not do
an adequate check for the possiblity of a non XP box
having MDAC 2.7.
I have had the same trouble with another Win98se box that
was initially at MDAC 2.1.3711.11 (GA).
So far MS and Google searches for Q329414 and MDAC 2.7
don't turn up anything helpful yet.
I'm hoping MS reads these groups and follows up on this.
>-----Original Message-----
>Although I have installed MDAC 2.7 for al long time (and
reinstalled it, to
>be certain), Windows update still comes with the
following critical update
>(tested on 98 and NT):
>
>
>Q329414: Security Update (MDAC 2.1)
>813 KB/ Download Time: < 1 min
>This security update applies to a component of Windows
known as the
>Microsoft Data Access Component (MDAC).
>
>
>
>The security bulletin is quit clear:
>Customers using Windows XP, or who have installed MDAC
2.7 on their systems
>are at no risk and do not need to take any action.
>
>Does anybody have the same experience and maybe has a
solution?
>
>Thank you in advance,
>
>Cees
>
>
>.
>
- application/octet-stream attachment: dahotfix.log
- Next message: Wes Tanney: "Re: MS02-065 patch download"
- Previous message: Ron: "Certificate Revocation List (CRL) problem w/ Outlook XP"
- In reply to: Cees: "MS-065 (q329414) and MDAC 2.7"
- Next in thread: mapsonx: "Re: MS-065 (q329414) and MDAC 2.7"
- Reply: mapsonx: "Re: MS-065 (q329414) and MDAC 2.7"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|