The MEAC Fan Page    MEAC Fans Community    Forums  Hop To Forum Categories  Life Style Forums  Hop To Forums  Technology Room    ‘Critical’ Vista, IE 7 patches highlight MS security updates
Go
New
Find
Notify
Tools
Reply
  
-star Rating Rate It!  Login/Join 
Head Coach
Picture of TechRattler
Posted
This month’s batch of patches from Microsoft includes six bulletins covering at least 15 vulnerabilities, including several critical code execution holes in Windows Vista and Internet Explorer 7.

In all, Redmond pushed out four critical bulletins with fixes for flaws that could put Windows users at risk of complete PC takeover attacks.

The most serious is a cumulative Internet Explorer update (MS07-033) that affects all versions of the dominant browser — IE 5.01 on Windows 2000 through IE 7 on Windows Vista.

The mega IE update addresses a total of six flaws, including one that was publicly discussed prior to Patch Tuesday. Interestingly, all six IE bugs are rated “critical” across the board, except for some versions of Windows Server 2003.

(NOTE: Click on image at right for step-by-step instructions on some key configuration changes you can make to run/use IE securely)

Another high-priority update to pay special attention to is MS07-035, which touches a “critical” vulnerability in the way that the Win32 API validates parameters. This bug does not affect Windows Vista.

Microsoft provides a dire warning:

An attacker could exploit the vulnerability by constructing a specially crafted Web page that could potentially allow remote code execution if a user viewed the Web page. An attacker who successfully exploited this vulnerability could take complete control of an affected system.

Windows Vista is also immune to MS07-031, a “critical” bulletin that covers a flaw in the Secure Channel (Schannel) security package in Windows. “This vulnerability could allow remote code execution if a user viewed a specially crafted Web page using an Internet Web browser or used an application that makes use of SSL/TLS,” according to the bulletin. Affected software includes Windows 2000, Windows XP and Windows Server 2003.

However, the built-in Windows Mail client in Vista didn’t escape unscathed. The MS07-034 update contains fixes for four vulnerabilities (two publicly discussed before today) that could lead to code execution attacks. This update also affects Outlook Express.

The gaping hole that dings Windows Vista comes with this warning:

A remote code execution vulnerability results from the way local or UNC navigation requests are handled in Windows Mail. An attacker could exploit the vulnerability by constructing a specially crafted e-mail message that could potentially allow execution of code from a local file or UNC path if a user clicked on a link in the e-mail message. An attacker who successfully exploited this vulnerability could take complete control of an affected system.

Windows Vista users will also see an automatic update for MS07-032, a “moderate” bulletin that fixes an information disclosure issue. The bug “could allow non-privileged users to access local user information data stores including administrative passwords contained within the registry and local file system,” Microsoft warned.

The last bulletin this month (MS07-030) fixes two “important” bugs in Microsoft Visio 2002 and Microsoft Office Visio 2003.

_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _


 
Posts: 24464 | Location: Now arriving... | Registered: December 04, 2001Reply With QuoteEdit or Delete MessageReport This Post
All-American
Picture of Ft. Pierce Rattler
Posted Hide Post
Everyone say it with me....

M-O-Z-I-L-L-A Laugh

_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _
..When disturbed, a rattler will try and withdraw on most occasions. However, if it feels cornered, the startling, sizzling buzz of its rattle is an unmistakable warning....
 
Posts: 3179 | Location: The City Wit No Pity.....Ft. Pierce,FL / Tallahassee,FL | Registered: September 23, 2002Reply With QuoteEdit or Delete MessageReport This Post
Head Coach
Picture of TechRattler
Posted Hide Post
Laugh Laugh Laugh F'real...

And, I still use IE on those rare occasions where a site doesn't support Foxfire...

_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _


 
Posts: 24464 | Location: Now arriving... | Registered: December 04, 2001Reply With QuoteEdit or Delete MessageReport This Post
All-American
Picture of Ft. Pierce Rattler
Posted Hide Post
I haven't ran across a site yet that it doesn't work on. Even Microsoft's website work with it.

Hmmm.. what type of website are you visiting young man? Big Grin

_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _
..When disturbed, a rattler will try and withdraw on most occasions. However, if it feels cornered, the startling, sizzling buzz of its rattle is an unmistakable warning....
 
Posts: 3179 | Location: The City Wit No Pity.....Ft. Pierce,FL / Tallahassee,FL | Registered: September 23, 2002Reply With QuoteEdit or Delete MessageReport This Post
Head Coach
Picture of TechRattler
Posted Hide Post
quote:
Originally posted by Ft. Pierce Rattler:
I haven't ran across a site yet that it doesn't work on. Even Microsoft's website work with it.

Hmmm.. what type of website are you visiting young man? Big Grin


Laugh Laugh Laugh You nut!


I haven't been on Microsoft's site in a while, but for a long time, it would support Mozilla. Razzer

_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _


 
Posts: 24464 | Location: Now arriving... | Registered: December 04, 2001Reply With QuoteEdit or Delete MessageReport This Post
All-American
Picture of Ft. Pierce Rattler
Posted Hide Post
Laugh Laugh Laugh I see you didn't answer the question! Devil

_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _
..When disturbed, a rattler will try and withdraw on most occasions. However, if it feels cornered, the startling, sizzling buzz of its rattle is an unmistakable warning....
 
Posts: 3179 | Location: The City Wit No Pity.....Ft. Pierce,FL / Tallahassee,FL | Registered: September 23, 2002Reply With QuoteEdit or Delete MessageReport This Post
Head Coach
Picture of TechRattler
Posted Hide Post
quote:
Originally posted by Ft. Pierce Rattler:
Laugh Laugh Laugh I see you didn't answer the question! Devil


I did! The Microsoft site! Razzer

The potential for getting viruses and trojans exist to much on those other ones... Handicap

_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _


 
Posts: 24464 | Location: Now arriving... | Registered: December 04, 2001Reply With QuoteEdit or Delete MessageReport This Post
 Previous Topic | Next Topic powered by eve community  
 

The MEAC Fan Page    MEAC Fans Community    Forums  Hop To Forum Categories  Life Style Forums  Hop To Forums  Technology Room    ‘Critical’ Vista, IE 7 patches highlight MS security updates

The team names, logos and uniform designs are registered trademarks of the teams indicated.
The MEAC Fan Page is in no way associated with the Mid-Eastern Athletic Conference
© 1999-2006 www.MEACfans.com. All rights reserved.