Admin: Official patch issued for Windows WMF Vulnerability

From: Ted Molczan (seesat@rogers.com)
Date: Thu Jan 05 2006 - 19:32:02 EST

  • Next message: Scott Campbell: "Satobs 6 Jan 2006"

    Today, Microsoft issued its official patch for the security vulnerability,
    involving WMF type graphics files:
    
    http://www.microsoft.com/technet/security/bulletin/ms06-001.mspx
    
    If you have previously installed Ilfak Guilfanov's unofficial patch, you can
    uninstall it (via add/remove programs), either before or after installing the
    official patch. I did so after, with no problem.
    
    Note that Microsoft has not issued a patch for Windows 95, 98, and ME. If
    Microsoft does not produce an update to repair those older versions of Windows,
    GRC (Gibson Research Corporation) has promised to make one available:
    
    http://www.grc.com/sn/notes-020.htm
    
    GRC reports that "all current WMF exploits appear to be non-functional on the
    older Win9x vintage platforms", so the immediate risk seems to be much less than
    for later platforms.
    
    Please send any responses to this post, to me, off-list.
    
    Ted Molczan
    
    
    -------------------------------------------------------------------------
    Subscribe/Unsubscribe info, Frequently Asked Questions, SeeSat-L archive:  
    http://www.satobs.org/seesat/seesatindex.html
    



    This archive was generated by hypermail 2b29 : Thu Jan 05 2006 - 19:35:06 EST