<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>The OS Quest &#187; &#187; Patches</title>
	<atom:link href="http://www.theosquest.com/category/patches/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.theosquest.com</link>
	<description>A Frustrating Journey</description>
	<pubDate>Tue, 22 Jul 2008 00:01:34 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
			<item>
		<title>Microsoft Security Updates</title>
		<link>http://www.theosquest.com/2007/08/19/microsoft-security-updates/</link>
		<comments>http://www.theosquest.com/2007/08/19/microsoft-security-updates/#comments</comments>
		<pubDate>Mon, 20 Aug 2007 00:58:13 +0000</pubDate>
		<dc:creator>ray</dc:creator>
		
		<category><![CDATA[Patches]]></category>

		<category><![CDATA[ie]]></category>

		<category><![CDATA[microsoft]]></category>

		<category><![CDATA[security_update]]></category>

		<category><![CDATA[vulnerabilities]]></category>

		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.theosquest.com/2007/08/19/microsoft-security-updates/</guid>
		<description><![CDATA[Microsoft released nine security updates this past Tuesday.
When it came time to run Automatic Update on my Windows XP SP2 virtual machine (running under Parallels) I got 12 updates, so Microsoft pushed more than the security updates. The updates broke down as follows (all links are to the Microsoft Knowledge Base article number listed):

Security Update [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.theosquest.com/wp-content/uploads/2007/06/ms_security_alert.gif" title="MS Security Alert" alt="MS Security Alert" align="left" /><strong>Microsoft</strong> released <a href="http://www.microsoft.com/technet/security/bulletin/ms07-aug.mspx" title="Jump to the Microsoft bulletin about the August security updates at Microsoft.com">nine security updates</a> this past Tuesday.</p>
<p>When it came time to run <strong>Automatic Update </strong>on my <strong>Windows XP SP2</strong> virtual machine (running under <strong>Parallels</strong>) I got 12 updates, so Microsoft pushed more than the security updates. The updates broke down as follows (all links are to the Microsoft Knowledge Base article number listed):</p>
<ol>
<li>Security Update for Media Player 11 (<a href="http://support.microsoft.com/?kbid=936782" title="Jump to the Microsoft Support Bulletin">KB936782</a>)</li>
<li>Security Update for IE 7 on Windows XP (<a href="http://support.microsoft.com/?kbid=938127" title="Jump to the Microsoft Support article">KB938127</a>)</li>
<li>Security Update for Microsoft .NET Framework 2.0 (<a href="http://support.microsoft.com/?kbid=928365" title="Jump to the Microsoft Support Bulletin">KB928365</a>)</li>
<li>Cumulative Security Update for IE7 on Windows XP (<a href="http://support.microsoft.com/?kbid=937143" title="Jump to the Microsoft Support bulletin">KB937143</a>)</li>
<li>Security Update for Microsoft .NET Framework 1.1 (<a href="http://support.microsoft.com/?kbid=928366" title="Jump to the Microsoft Support Bulletin">KB928366</a>)</li>
<li>Windows Malicious Software Removal Tool - August 2007 (<a href="http://support.microsoft.com/?kbid=890830" title="Jump to the Microsoft Support Bulletin">KB890830</a>)</li>
<li>Security Update for Windows XP (<a href="http://support.microsoft.com/?kbid=938829" title="Jump to the Microsoft Support Bulletin">KB938829</a>)</li>
<li>Security Update for Windows XP (<a href="http://support.microsoft.com/?kbid=921503" title="Jump to the Microsoft Support Bulletin">KB921503</a>)</li>
<li>Definition Update for Windows Defender</li>
<li>Update for Windows XP (<a href="http://support.microsoft.com/?kbid=936357" title="Jump to the Microsoft Support Bulletin">KB936357</a>)</li>
<li>Update for Windows XP (<a href="http://support.microsoft.com/?kbid=938828" title="Jump to the Microsoft Support Bulletin">KB938828</a>)</li>
<li>Security Update for Windows XP (<a href="http://support.microsoft.com/?kbid=936021" title="Jump to the Microsoft Support Bulletin">KB936021</a>)</li>
</ol>
<p>The updates to Windows Vista Ultimate (also running under Parallels) through Automatic Update included:</p>
<ol>
<li> Update Windows Mail Junk E-Mail Filter (<a href="http://support.microsoft.com/?kbid=905866" title="Jump to the Microsoft Support Bulletin">KB905866</a>)</li>
<li>Update for Windows Vista (<a href="http://support.microsoft.com/?kbid=938127" title="Jump to the Microsoft Support Bulletin">KB938127</a>)</li>
<li>Cumulative Security Update for IE 7 in Vista (<a href="http://support.microsoft.com/?kbid=937143" title="Jump to the Microsoft Support Bulletin">KB937143</a>)</li>
<li>Security Update for Windows Vista (<a href="http://support.microsoft.com/?kbid=933579" title="Jump to the Microsoft Support Bulletin">KB933579</a>)</li>
<li>Malicious Software Removal Tool - August 2007 (<a href="http://support.microsoft.com/?kbid=890830" title="Jump to the Microsoft Support Bulletin">KB890830</a>)</li>
<li>Security Update for Windows Vista (<a href="http://support.microsoft.com/?kbid=936021" title="Jump to the Microsoft Support Bulletin">KB936021</a>)</li>
<li>Security Update for Windows Vista (<a href="http://support.microsoft.com/?kbid=936782" title="Jump to the Microsoft Support Bulletin">KB936782</a>)</li>
<li>Definition Update for Windows Defender</li>
<li>Security Update for Windows Vista (<a href="http://support.microsoft.com/?kbid=938123" title="Jump to the Microsoft Support Bulletin">KB938123</a>)</li>
</ol>
<h3>Patching Results (both platforms)</h3>
<p>The download and patching was straight-forward. A single reboot at the end of the patching was required. Windows didn&#8217;t have any problems starting up or running after being patched. But, I don&#8217;t use Windows enough to encounter any but the most severe problems. I also run very few applications so wouldn&#8217;t encounter any conflicts. I don&#8217;t run any versions of MS Office so I haven&#8217;t tried the Office updates.</p>
<p>Have you applied the updates yet? Any problems?</p>
<p class="akst_link"><a href="http://www.theosquest.com/?p=363&amp;akst_action=share-this"  title="Email, post to del.icio.us, etc." id="akst_link_363" class="akst_share_link" rel="noindex nofollow">ShareThis</a>
</p>]]></content:encoded>
			<wfw:commentRss>http://www.theosquest.com/2007/08/19/microsoft-security-updates/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Microsoft July Patch Tuesday Updates</title>
		<link>http://www.theosquest.com/2007/07/13/microsoft-july-patch-tuesday-updates/</link>
		<comments>http://www.theosquest.com/2007/07/13/microsoft-july-patch-tuesday-updates/#comments</comments>
		<pubDate>Fri, 13 Jul 2007 15:02:55 +0000</pubDate>
		<dc:creator>ray</dc:creator>
		
		<category><![CDATA[Patches]]></category>

		<category><![CDATA[microsoft]]></category>

		<category><![CDATA[vulnerabilities]]></category>

		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.theosquest.com/2007/07/13/microsoft-july-patch-tuesday-updates/</guid>
		<description><![CDATA[There&#8217;s a couple of updates to last Tuesday&#8217;s Microsoft patches that are worth mentioning.
First, Microsoft updated MS07-036 to include Microsoft Office 2004 for Mac as a vulnerable application. So if you run Microsoft Office 2004 for Mac you&#8217;ll need to patch it. I don&#8217;t run the software so can&#8217;t say how the patch works. The [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.theosquest.com/wp-content/uploads/2007/06/ms_security_alert.gif" title="MS Security Alert" alt="MS Security Alert" align="left" />There&#8217;s a couple of updates to <a href="http://www.theosquest.com/2007/07/11/microsoft-patch-tuesday-for-july-2007/" title="Jump to my posting about Microsoft's July 2007 patches">last Tuesday&#8217;s Microsoft patches</a> that are worth mentioning.</p>
<p>First, <strong>Microsoft</strong> updated <a href="http://www.microsoft.com/technet/security/Bulletin/MS07-036.mspx" title="Jump to the Microsoft MS07-036 bulletin">MS07-036</a> to include <strong>Microsoft Office 2004 for Mac</strong> as a vulnerable application. So if you run Microsoft Office 2004 for Mac you&#8217;ll need to patch it. I don&#8217;t run the software so can&#8217;t say how the patch works. The vulnerability is rated as &#8220;Important&#8221; for Microsoft Office 2004 for Mac.<br />
Also, Slashdot has a posting about <a href="http://developers.slashdot.org/article.pl?sid=07/07/13/1227225" title="JUmp to the Slashdot article">people experiencing problems</a> with the <strong>.NET</strong> updates from last Tuesday. This was bulletin <strong>MS07-040</strong>. Most problems are related to high cpu usage after the update. This isn&#8217;t a problem I experienced on my Windows PC or on Windows running under Parallels.</p>
<p class="akst_link"><a href="http://www.theosquest.com/?p=298&amp;akst_action=share-this"  title="Email, post to del.icio.us, etc." id="akst_link_298" class="akst_share_link" rel="noindex nofollow">ShareThis</a>
</p>]]></content:encoded>
			<wfw:commentRss>http://www.theosquest.com/2007/07/13/microsoft-july-patch-tuesday-updates/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Apple Patches on Tuesday</title>
		<link>http://www.theosquest.com/2007/07/11/apple-patches-on-tuesday/</link>
		<comments>http://www.theosquest.com/2007/07/11/apple-patches-on-tuesday/#comments</comments>
		<pubDate>Thu, 12 Jul 2007 00:25:26 +0000</pubDate>
		<dc:creator>ray</dc:creator>
		
		<category><![CDATA[Patches]]></category>

		<category><![CDATA[itunes]]></category>

		<category><![CDATA[quicktime]]></category>

		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.theosquest.com/2007/07/11/apple-patches-on-tuesday/</guid>
		<description><![CDATA[Apple joins the the Tuesday patch party and releases updates to Quicktime and iTunes. The patches are for the software on both Windows and OS X.
The Quicktime update, to version 7.2 includes eight security vulnerability fixes in addition to updates to the H.264 codec, support for full screen viewing and &#8220;numerous bug fixes&#8221;. As with [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.theosquest.com/wp-content/uploads/2007/07/quicktimeupdate.png" title="Quicktime and iTunes in Software Update"><img src="http://www.theosquest.com/wp-content/uploads/2007/07/quicktimeupdate.thumbnail.png" title="Quicktime and iTunes in Software Update" alt="Quicktime and iTunes in Software Update" align="left" /></a><strong>Apple</strong> joins the the Tuesday patch party and releases updates to <strong>Quicktime</strong> and <strong>iTunes</strong>. The patches are for the software on both <strong>Windows</strong> and <strong>OS X</strong>.</p>
<p>The Quicktime update, to version 7.2 includes <a href="http://docs.info.apple.com/article.html?artnum=305947" title="Jump to the Apple article on the security fixes">eight security vulnerability fixes</a> in addition to updates to the H.264 codec, support for full screen viewing and &#8220;numerous bug fixes&#8221;. As with all other Quicktime updates if you&#8217;ve purchased a Quicktime Pro version prior to 7 and you install this update your older Quicktime Pro will stop working and you&#8217;ll have to buy the new version. The update requires a reboot on both Mac and Windows.</p>
<p>The iTunes update brings iTunes to 7.3.1 and fixes a problem with iTunes 7.3 accessing the library. I installed this on both Mac and Windows without incident. As a test I played a short podcast on Windows. I successfully synced my iPod and Apple TV after the update. I didn&#8217;t have the access problem this update was supposed to fix so I can&#8217;t say whether or not it resolved that specific problem.</p>
<p class="akst_link"><a href="http://www.theosquest.com/?p=287&amp;akst_action=share-this"  title="Email, post to del.icio.us, etc." id="akst_link_287" class="akst_share_link" rel="noindex nofollow">ShareThis</a>
</p>]]></content:encoded>
			<wfw:commentRss>http://www.theosquest.com/2007/07/11/apple-patches-on-tuesday/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Microsoft Patch Tuesday for July 2007</title>
		<link>http://www.theosquest.com/2007/07/11/microsoft-patch-tuesday-for-july-2007/</link>
		<comments>http://www.theosquest.com/2007/07/11/microsoft-patch-tuesday-for-july-2007/#comments</comments>
		<pubDate>Thu, 12 Jul 2007 00:00:32 +0000</pubDate>
		<dc:creator>ray</dc:creator>
		
		<category><![CDATA[Patches]]></category>

		<category><![CDATA[ie]]></category>

		<category><![CDATA[microsoft]]></category>

		<category><![CDATA[vulnerabilities]]></category>

		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.theosquest.com/2007/07/11/microsoft-patch-tuesday-for-july-2007/</guid>
		<description><![CDATA[It&#8217;s the second Tuesday of July and that means patches from Microsoft. This month brings six patches, three rated critical, two important, and one moderate. Only five patches are for desktop software and  Windows Vista also gets its own unique patch although it&#8217;s the one rated moderate. Of these, only the .NET patches and [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.theosquest.com/wp-content/uploads/2007/06/ms_security_alert.gif" title="MS Security Alert" alt="MS Security Alert" align="left" />It&#8217;s the second Tuesday of July and that means patches from <strong>Microsoft</strong>. This month brings <strong>six patches</strong>, three rated critical, two important, and one moderate. Only five patches are for desktop software and  Windows Vista also gets its own unique patch although it&#8217;s the one rated moderate. Of these, only the .NET patches and the Vista patch were needed on my PCs. In addition to these security updates I also received a update (through automatic update) related to Intel processors. This was called a &#8220;microcode reliability update&#8221;.</p>
<p>My test PCs include Windows XP SP2, Windows Vista Business Premium and Windows Vista Ultimate Edition. The Windows Vista OS&#8217;s are running under Parallels on my iMac. All my test PCs were patched through automatic update and required a reboot after applying the patches.</p>
<p><a href="http://www.microsoft.com/technet/security/Bulletin/MS07-040.mspx" title="Jump to the MS07-040 bulletin">MS07-040</a> is rated critical and affects <strong>.NET</strong> versions 1.x and 2.x, version 3.x is not affected. All operating systems are affected if they have a vulnerable version of .NET installed. There are no known issues listed in the bulletin. If you have both versions of .Net on the PC you need a separate patch for each version. I have .NET 1.x and 2.x on Windows XP SP2, Windows Vista Business Premium and Windows Vista Ultimate. I did not have problems with any of the .Net patches.</p>
<p class="alert">[Update July 13th]<a href="http://developers.slashdot.org/article.pl?sid=07/07/13/1227225"> Slashdot</a> has a posting about people seeing high CPU usage and other issues with the MS07-040 patches.</p>
<p><a href="http://www.microsoft.com/technet/security/Bulletin/MS07-038.mspx" title="Jump to the MS07-038 bulletin">MS07-038</a> is rated <strong>moderate</strong> and affects <strong>Windows Vista</strong>, both 32-bit and 64-bit versions. This patches a vulnerability in the Windows Vista firewall that could allow an attacker to gather information about a host. There are no known issues listed in the bulletin. I did not have any problems installing the patch on either of my Vista systems.</p>
<p>The <a href="http://support.microsoft.com/kb/936357" title="Jump to the Microsoft bulletin"><strong>Microcode Reliability Update</strong> (936357)</a> was also installed through automatic update as a required patch. This was run on my older HP laptop which uses a Pentium 4 which leads me to believe the patch runs and then determines the CPU since Pentium 4&#8217;s aren&#8217;t in the bulletin as needing the patch. This patch also ran on Windows under Parallels.</p>
<p>I couldn&#8217;t install the remaining security patches but they are:</p>
<p>Two of the patches affect <strong>Microsoft Office</strong> software. I did not install either of these patches since I don&#8217;t have the affected products.</p>
<p><a href="http://www.microsoft.com/technet/security/Bulletin/MS07-036.mspx" title="Jump to the MS07-036 bulletin at Microsoft">MS07-036</a> is rated <strong>critical</strong> and affects all versions of <strong>Microsoft Excel </strong>from Excel 2000 on up. It also applies to the Office 2007 compatibility pack. It&#8217;s only rated critical for Excel 2000. Microsoft rates the other versions as &#8220;important&#8221;. The bulletin does not list any known issues.</p>
<p class="alert">[Updated July 13th] Microsoft has updated MS07-036 to include Microsoft Office 2004 for Mac in the list of vulnerable software that must be patched. I don&#8217;t run this software so won&#8217;t be installing this patch either.</p>
<p><a href="http://www.microsoft.com/technet/security/Bulletin/MS07-037.mspx" title="Jump to the MS07-037 bulletin">MS07-037</a> is rated <strong>important</strong> and affects <strong>Microsoft Office Publisher 2007</strong> only. The bulletin does not list any known issues.</p>
<p><a href="http://www.microsoft.com/technet/security/Bulletin/MS07-041.mspx" title="Jump to the MS07-041 bulletin">MS-07-041</a>, is rated important and affects <strong>Microsoft Internet Information Server</strong> (IIS) when running on Windows XP SP2. Earlier versions of Windows XP may be affected but Microsoft only supports service pack 2. IIS is not installed by default on Windows XP.</p>
<p>The server patch is is <a href="http://www.microsoft.com/technet/security/Bulletin/MS07-039.mspx" title="Jump to the MS07-039 bulletin">MS07-039</a> and is a vulnerability in Active Directory that&#8217;s rated critical.</p>
<p>The patches are available through automatic update or can be downloaded individually from Microsoft.</p>
<p class="akst_link"><a href="http://www.theosquest.com/?p=286&amp;akst_action=share-this"  title="Email, post to del.icio.us, etc." id="akst_link_286" class="akst_share_link" rel="noindex nofollow">ShareThis</a>
</p>]]></content:encoded>
			<wfw:commentRss>http://www.theosquest.com/2007/07/11/microsoft-patch-tuesday-for-july-2007/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Apple OSX Security Update 2007-006</title>
		<link>http://www.theosquest.com/2007/06/23/apple-osx-security-update-2007-006/</link>
		<comments>http://www.theosquest.com/2007/06/23/apple-osx-security-update-2007-006/#comments</comments>
		<pubDate>Sat, 23 Jun 2007 23:42:15 +0000</pubDate>
		<dc:creator>ray</dc:creator>
		
		<category><![CDATA[Patches]]></category>

		<category><![CDATA[apple]]></category>

		<category><![CDATA[os_x]]></category>

		<category><![CDATA[security_update]]></category>

		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.theosquest.com/2007/06/23/apple-osx-security-update-2007-006/</guid>
		<description><![CDATA[Apple has released a security-only update for the sixth straight month this year. It&#8217;s the appropriately  named Security Update 2007-006.This update is needed for 10.4.9 along with the just released 10.4.10. It&#8217;s also needed for 10.3.9.
Two security vulnerabilities are addressed. One is in Webcore and can allow cross-site scripting attacks.
The second patched vulnerability was [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.theosquest.com/wp-content/uploads/2007/06/osx2007-006.png" title="OSX 2007-006"><img src="http://www.theosquest.com/wp-content/uploads/2007/06/osx2007-006.thumbnail.png" title="OSX 2007-006" alt="OSX 2007-006" align="left" /></a><strong>Apple</strong> has released a security-only update for the sixth straight month this year. It&#8217;s the appropriately  named <a href="http://docs.info.apple.com/article.html?artnum=305759" title="Jump to the Apple support article about the update"><strong>Security Update 2007-006</strong></a>.This update is needed for 10.4.9 along with the <a href="http://www.theosquest.com/2007/06/21/apple-releases-10410-for-os-x/" title="Jump to my posting about 10.4.10">just released 10.4.10</a>. It&#8217;s also needed for 10.3.9.</p>
<p>Two security vulnerabilities are addressed. One is in <strong>Webcore</strong> and can allow <strong>cross-site scripting attacks</strong>.</p>
<p>The second patched vulnerability was in <strong>Webkit</strong> and could allow remote code execution.</p>
<p>I applied the update to an Intel iMac and an Intel Mac Mini without a problem. You can visit my <a href="http://www.theosquest.com/about-2/quest-hardware/" title="Jump to my hardware page">hardware page</a> for the specific hardware patched. The PPC Mac Mini isn&#8217;t hooked up at this time so it hasn&#8217;t been patched yet.</p>
<p class="akst_link"><a href="http://www.theosquest.com/?p=256&amp;akst_action=share-this"  title="Email, post to del.icio.us, etc." id="akst_link_256" class="akst_share_link" rel="noindex nofollow">ShareThis</a>
</p>]]></content:encoded>
			<wfw:commentRss>http://www.theosquest.com/2007/06/23/apple-osx-security-update-2007-006/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Patch Tuesday for June 2007</title>
		<link>http://www.theosquest.com/2007/06/12/patch-tuesday-for-june-2007/</link>
		<comments>http://www.theosquest.com/2007/06/12/patch-tuesday-for-june-2007/#comments</comments>
		<pubDate>Wed, 13 Jun 2007 00:32:22 +0000</pubDate>
		<dc:creator>ray</dc:creator>
		
		<category><![CDATA[Patches]]></category>

		<category><![CDATA[ie]]></category>

		<category><![CDATA[microsoft]]></category>

		<category><![CDATA[vulnerabilities]]></category>

		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.theosquest.com/2007/06/12/patch-tuesday-for-june-2007/</guid>
		<description><![CDATA[Microsoft released six security patches today. Four of them were rated critical, one important and one moderate. There are patches for all supported desktop OS platforms, Internet Explorer, a couple mail apps and for a couple versions of Visio. There aren&#8217;t any Office patches.
The critical desktop patches are:
MS07-031 for Windows XP SP2, Windows XP x64 [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.theosquest.com/wp-content/uploads/2007/06/ms_security_alert.gif" title="MS Security Alert" alt="MS Security Alert" align="left" /><strong>Microsoft</strong> released <a href="http://www.microsoft.com/technet/security/bulletin/ms07-jun.mspx" title="Jump to the Microsoft announcement bulletin for June">six security patches today</a>. Four of them were rated critical, one important and one moderate. There are patches for all supported desktop OS platforms, Internet Explorer, a couple mail apps and for a couple versions of Visio. There aren&#8217;t any Office patches.</p>
<p>The <strong>critical desktop patches</strong> are:</p>
<p><a href="http://www.microsoft.com/technet/security/Bulletin/MS07-031.mspx" title="Jump to the bulletin for MS07-031 at Microsoft">MS07-031</a> for Windows XP SP2, Windows XP x64 and Windows XP x64 SP2. It&#8217;s rated as &#8220;important&#8221; for Windows 2000 SP4. Earlier versions of Windows 2000 and XP may be affected but aren&#8217;t supported by Microsoft. On Windows XP this vulnerability can allow remote code execution. On other OS&#8217;s the vulnerability results in a denial of service attack (such as a system crash). The user must visit a malicious website to be exploited.</p>
<p><a href="http://www.microsoft.com/technet/security/bulletin/ms07-033.mspx" title="Jump to the MS07-033 bulletin at Microsoft">MS07-033</a> is the cumulative patch for all versions of Internet Explorer and is critical on all desktop OS&#8217;s that run it. Since this is a cumulative update it carries forward any baggage of earlier issues (like changes in ActiveX control handling). As usual, the most serious vulnerability impact is remote code execution. Six new vulnerabilities are identified in the bulletin some of which allow remote code execution.</p>
<p><a href="http://www.microsoft.com/technet/security/bulletin/ms07-034.mspx" title="Jump to the MS07-034 bulletin at Microsoft">MS07-034</a> is for Windows Mail on Vista (including Vista x64). It is rated &#8220;important&#8221; for Outlook Express 6 on all versions of Windows XP. There are five different vulnerabilities identified. On XP they may disclose information, on Vista they allow remote code execution.</p>
<p><a href="http://www.microsoft.com/technet/security/Bulletin/ms07-035.mspx" title="Jump to the MS07-035 bulletin at Microsoft">MS07-035</a> is for all desktop OS&#8217;s except Vista. It&#8217;s not needed on Vista. (Obligatory MS dig - proves Vista is &#8220;more secure&#8221;.) This allows remote code execution.</p>
<p>The two other patches are:</p>
<p><a href="http://www.microsoft.com/technet/security/Bulletin/MS07-030.mspx" title="Jump to the MS07-030 bulletin at Microsoft">MS07-030</a> is for Visio 2002 SP2 and Visio 2003 SP2 and is rated as &#8220;important&#8221;. The vulnerability will allow remote code execution although it cannot be exploited automatically. The user must visit a malicious website or open a malicious email attachment.</p>
<p><a href="http://www.microsoft.com/technet/security/bulletin/ms07-032.mspx" title="Jump the the bulletin for MS07-03 at Microsoft">MS07-032</a> is for Windows Vista (including x64) and is rated &#8220;moderate&#8221;. This could result in information disclosure, including some passwords which would allow higher level access. This does require to have valid logon credentials for the PC.</p>
<p>I applied the appropriate patches to Windows XP SP2 without incident. I don&#8217;t use the Mail app of Vista so can&#8217;t say if it affects the app in some way. The bulletins don&#8217;t list any known issues.</p>
<p>The patches are released through Windows Update and are available for individual download.</p>
<p class="akst_link"><a href="http://www.theosquest.com/?p=218&amp;akst_action=share-this"  title="Email, post to del.icio.us, etc." id="akst_link_218" class="akst_share_link" rel="noindex nofollow">ShareThis</a>
</p>]]></content:encoded>
			<wfw:commentRss>http://www.theosquest.com/2007/06/12/patch-tuesday-for-june-2007/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Apple Updates Quicktime Security and iTunes DRM</title>
		<link>http://www.theosquest.com/2007/05/30/apple-updates-quicktime-security-and-itunes-drm/</link>
		<comments>http://www.theosquest.com/2007/05/30/apple-updates-quicktime-security-and-itunes-drm/#comments</comments>
		<pubDate>Wed, 30 May 2007 13:52:26 +0000</pubDate>
		<dc:creator>ray</dc:creator>
		
		<category><![CDATA[Patches]]></category>

		<category><![CDATA[drm]]></category>

		<category><![CDATA[itunes]]></category>

		<category><![CDATA[quicktime]]></category>

		<category><![CDATA[security_update]]></category>

		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.theosquest.com/2007/05/30/apple-updates-quicktime-security-and-itunes-drm/</guid>
		<description><![CDATA[Apple has released updates for both Quicktime and iTunes. The updates are for the software on both Windows and OS X.
The Quicktime patch is a security update that patches two vulnerabilities. The vulnerabilities allow a malicious website to either run code on a computer or get infomation from a computer.
Apple also released an update to [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Apple</strong> has released updates for both <strong>Quicktime</strong> and <strong>iTunes</strong>. The updates are for the software on both <strong>Windows</strong> and <strong>OS X</strong>.</p>
<p>The Quicktime patch is a security update that <a href="http://docs.info.apple.com/article.html?artnum=305531" title="Jump to the Apple bulletin on the security update">patches two vulnerabilities</a>. The vulnerabilities allow a malicious website to either run code on a computer or get infomation from a computer.</p>
<p>Apple also released an <a href="http://www.apple.com/support/downloads/itunes72formac.html" title="Jump to the Apple bulletin for the iTunes download">update to iTunes</a> that adds support for DRM free music. It looks like Apple might just make their promise of DRM-free music available in iTunes by the end of May.</p>
<p>The updates will be pushed through Apple update or can be downloaded directly.</p>
<p class="akst_link"><a href="http://www.theosquest.com/?p=180&amp;akst_action=share-this"  title="Email, post to del.icio.us, etc." id="akst_link_180" class="akst_share_link" rel="noindex nofollow">ShareThis</a>
</p>]]></content:encoded>
			<wfw:commentRss>http://www.theosquest.com/2007/05/30/apple-updates-quicktime-security-and-itunes-drm/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Apple Security Update 2007-05</title>
		<link>http://www.theosquest.com/2007/05/25/apple-security-update-2007-05/</link>
		<comments>http://www.theosquest.com/2007/05/25/apple-security-update-2007-05/#comments</comments>
		<pubDate>Fri, 25 May 2007 15:38:20 +0000</pubDate>
		<dc:creator>ray</dc:creator>
		
		<category><![CDATA[Patches]]></category>

		<category><![CDATA[apple]]></category>

		<category><![CDATA[os_x]]></category>

		<category><![CDATA[security_update]]></category>

		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.theosquest.com/2007/05/25/apple-security-update-2007-05/</guid>
		<description><![CDATA[In keeping with it&#8217;s &#8220;one-a-month&#8221; trend for then year so far, Apple has released Security Update 2007-05.
According to the Apple notification it contains updates to the following components:

bind
CarbonCore
CoreGraphics
crontabs
fetchmail
file
iChat
mDNSResponder
PPP
ruby
screen
texinfo
VPN

I applied the Universal version of the update to my iMac through software update without a problem. The update does require a reboot and on my iMac it [...]]]></description>
			<content:encoded><![CDATA[<p>In keeping with it&#8217;s &#8220;one-a-month&#8221; trend for then year so far, Apple has released <strong>Security Update 2007-05</strong>.</p>
<p>According to the <a href="http://docs.info.apple.com/article.html?artnum=305530" title="Jump to the Apple support article on the update.">Apple notification</a> it contains updates to the following components:</p>
<ul>
<li>bind</li>
<li>CarbonCore</li>
<li>CoreGraphics</li>
<li>crontabs</li>
<li>fetchmail</li>
<li>file</li>
<li>iChat</li>
<li>mDNSResponder</li>
<li>PPP</li>
<li>ruby</li>
<li>screen</li>
<li>texinfo</li>
<li>VPN</li>
</ul>
<p>I applied the Universal version of the update to my iMac through software update without a problem. The update does require a reboot and on my iMac it did a bit of a double reboot. During the first reboot, which took longer than usual, another reboot was done. This occurred before the logon screen appeared. That second reboot took the normal length of time.</p>
<p>My PPC Mac Mini is currently packed away so I haven&#8217;t tried the PPC version of the update and it will be awhile before I do.</p>
<p class="akst_link"><a href="http://www.theosquest.com/?p=175&amp;akst_action=share-this"  title="Email, post to del.icio.us, etc." id="akst_link_175" class="akst_share_link" rel="noindex nofollow">ShareThis</a>
</p>]]></content:encoded>
			<wfw:commentRss>http://www.theosquest.com/2007/05/25/apple-security-update-2007-05/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Apple Patch: Pro Application Support Version 4.0</title>
		<link>http://www.theosquest.com/2007/05/09/apple-patch-pro-application-support-version-40/</link>
		<comments>http://www.theosquest.com/2007/05/09/apple-patch-pro-application-support-version-40/#comments</comments>
		<pubDate>Thu, 10 May 2007 02:02:52 +0000</pubDate>
		<dc:creator>ray</dc:creator>
		
		<category><![CDATA[Patches]]></category>

		<category><![CDATA[apple]]></category>

		<category><![CDATA[software_update]]></category>

		<guid isPermaLink="false">http://www.theosquest.com/2007/05/09/apple-patch-pro-application-support-version-40/</guid>
		<description><![CDATA[Apple released a patch called Pro Application Support 4.0. In typical Apple fashion they don&#8217;t feel the need to get into any detail, here&#8217;s the entire text of their bulletin.
About Pro Application Support 4.0
This update improves general user interface reliability for Apple&#8217;s professional applications and is recommended for all users of Final Cut Studio, Final [...]]]></description>
			<content:encoded><![CDATA[<p>Apple released a patch called Pro Application Support 4.0. In typical Apple fashion they don&#8217;t feel the need to get into any detail, here&#8217;s the entire text of their bulletin.</p>
<blockquote><p><strong>About Pro Application Support 4.0</strong></p>
<p>This update improves general user interface reliability for Apple&#8217;s professional applications and is recommended for all users of Final Cut Studio, Final Cut Pro, Motion, Soundtrack Pro, DVD Studio Pro, Aperture, Final Cut Express HD, Soundtrack, Logic Pro and Logic Express.</p></blockquote>
<p>It&#8217;s a 8.3MB download through Software Update and 7.3MB through the <a href="http://www.apple.com/support/downloads/proapplicationsupport40.html" title="Jump to the Apple bulletin about the patch">Apple website</a>.</p>
<p class="akst_link"><a href="http://www.theosquest.com/?p=154&amp;akst_action=share-this"  title="Email, post to del.icio.us, etc." id="akst_link_154" class="akst_share_link" rel="noindex nofollow">ShareThis</a>
</p>]]></content:encoded>
			<wfw:commentRss>http://www.theosquest.com/2007/05/09/apple-patch-pro-application-support-version-40/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Patch Tuesday for May 2007</title>
		<link>http://www.theosquest.com/2007/05/08/patch-tuesday-for-may-2007/</link>
		<comments>http://www.theosquest.com/2007/05/08/patch-tuesday-for-may-2007/#comments</comments>
		<pubDate>Wed, 09 May 2007 01:13:49 +0000</pubDate>
		<dc:creator>ray</dc:creator>
		
		<category><![CDATA[Patches]]></category>

		<category><![CDATA[ie]]></category>

		<category><![CDATA[ms_office]]></category>

		<category><![CDATA[security_update]]></category>

		<category><![CDATA[vulnerabilities]]></category>

		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.theosquest.com/2007/05/08/patch-tuesday-for-may-2007/</guid>
		<description><![CDATA[Mac users take note - It&#8217;s the second Tuesday of May and that means it&#8217;s patch day for Microsoft. Microsoft released 7 critical update bulletins. Three of them affect Office 2004 for Mac so if you&#8217;re a Office 2004 for Mac user read on along with just about every Windows user.
Two of the seven bulletins [...]]]></description>
			<content:encoded><![CDATA[<p>Mac users take note - It&#8217;s the second Tuesday of May and that means it&#8217;s patch day for Microsoft. Microsoft released 7 critical update bulletins. Three of them affect <strong>Office 2004 for Mac</strong> so if you&#8217;re a Office 2004 for Mac user read on along with just about every Windows user.</p>
<p>Two of the seven bulletins are for servers only. <a href="http://www.microsoft.com/technet/security/bulletin/ms07-026.mspx" title="Jump to the Microsoft bulletin for MS09-026">MS07-026</a> is for Exchange Server, including the latest version. <a href="http://www.microsoft.com/technet/security/bulletin/ms07-029.mspx" title="Jump to the Microsoft bulletin for MS07-029">MS07-029</a> is for the RPC interface to DNS server and affects their server software.</p>
<p>That leaves 5 bulletins for desktops. Three of them are for Office components.</p>
<p><a href="http://www.microsoft.com/technet/security/bulletin/ms07-023.mspx" title="Jump to the Microsoft Bulletin for MS07-023">MS07-023</a> is for Office, specifically Microsoft Excel 2000, 2002 (aka XP), 2003 and the latest version, Excel 2007. Excel 2004 for the Mac is also vulnerable and needs to be patched. The viewer for Excel 2003 and the compatibility pack for Office 2007 is also affected.</p>
<p><a href="http://www.microsoft.com/technet/security/bulletin/ms07-024.mspx" title="Jump to the Microsoft bulletin for MS07-024">MS07-024</a> is also for Office, this time it&#8217;s for Word. The patch is NOT needed for the latest version, Word 2007. But it&#8217;s needed for Word 2000, Word 2002 (aka XP), Word 2003, Word 2004 for the Mac. Word Viewer 2003 also needs to be patched. And the list continues with Microsoft Works Suite 2004, 2005 and 2006. the update file for all three Works version is the same one as for Word 2002.</p>
<p><a href="http://www.microsoft.com/technet/security/bulletin/ms07-025.mspx">MS07-025</a> is another Office patch. Multiple Office components, pretty much every Office user will need the update as it affects Office 2000, Office 2002 (aka XP), Office 2003 and the latest version, Office 2007. Office 2004 for Mac is also affected and needs updating.</p>
<p><a href="http://www.microsoft.com/technet/security/bulletin/ms07-027.mspx" title="Jump to the Microsoft bulletin for MS07-027">MS07-027</a> is the cumulative update for Internet Explorer. All supported versions of Internet Explorer on all supported operating systems are affected and needs to be updated.</p>
<p><a href="http://www.microsoft.com/technet/security/bulletin/ms07-028.mspx" title="Jump to the Microsoft bulletin for MS07-028">MS07-028</a> is a patch for CAPCOM which is the &#8220;Cryptographic API Component Object Model&#8221;. CAPCOM is an Active X control that allows scriptors (VBS, ASP, etc&#8230;) he ability to encrypt data. It&#8217;s part of the Biztalk servers but may be installed by other software. My Windows XP SP2 machine needed the update, other systems may not need it.</p>
<p>This is a pretty depressing set up updates to see Microsoft release. It shoots holes through the statement that Microsoft has improved security and that their latest &#8220;2007&#8243; versions are the most secure ever. While they may be the &#8220;most secure ever&#8221; this set up updates adds ammunition to the argument that they aren&#8217;t much more secure. Four of the five desktops updates are needed across all versions, from oldest to newest. I guess it&#8217;s possible to say that Vista/Office 2007 only needed 4 out of the 5 patches so it was 20% more secure.</p>
<p class="akst_link"><a href="http://www.theosquest.com/?p=150&amp;akst_action=share-this"  title="Email, post to del.icio.us, etc." id="akst_link_150" class="akst_share_link" rel="noindex nofollow">ShareThis</a>
</p>]]></content:encoded>
			<wfw:commentRss>http://www.theosquest.com/2007/05/08/patch-tuesday-for-may-2007/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Apple Patches Quicktime, Airport and More</title>
		<link>http://www.theosquest.com/2007/05/01/apple-patches-quicktime-airport-and-more/</link>
		<comments>http://www.theosquest.com/2007/05/01/apple-patches-quicktime-airport-and-more/#comments</comments>
		<pubDate>Wed, 02 May 2007 04:17:20 +0000</pubDate>
		<dc:creator>ray</dc:creator>
		
		<category><![CDATA[Patches]]></category>

		<category><![CDATA[airport]]></category>

		<category><![CDATA[apple]]></category>

		<category><![CDATA[os_x]]></category>

		<category><![CDATA[quicktime]]></category>

		<category><![CDATA[wpa]]></category>

		<guid isPermaLink="false">http://www.theosquest.com/2007/05/01/apple-patches-quicktime-airport-and-more/</guid>
		<description><![CDATA[I was greeted by this screen on my Intel iMac today.

The Quicktime update patches the &#8220;hack-a-mac&#8221; Quicktime vulnerability that was publicized on April 20th. It doesn&#8217;t really provide any detail but Apple has a support article on the patch.
The Airport Extreme Update 2007-003 description is succinct&#8230;
This update is recommended for all Intel-based Macintosh computers and [...]]]></description>
			<content:encoded><![CDATA[<p>I was greeted by this screen on my Intel iMac today.</p>
<p><img src="http://www.theosquest.com//wp-content/uploads/2007/04/AppleUpdate1.png" alt="Screenshot of the Quicktime and Airport update screen" /></p>
<p>The Quicktime update patches the &#8220;hack-a-mac&#8221; <a href="http://www.spamchronicles.com/commentary/mac-hacked-both-sides-miss-the-point/" title="Jump to my posting on the Hack-A-Mac vulnerability on my Spam Chronicles blog.">Quicktime vulnerability</a> that was publicized on April 20th. It doesn&#8217;t really provide any detail but Apple has a <a href="http://docs.info.apple.com/article.html?artnum=305446" title="Jump to the Apple support article on the Quicktime update">support article</a> on the patch.</p>
<p>The Airport Extreme Update 2007-003 description is succinct&#8230;</p>
<blockquote><p>This update is recommended for all Intel-based Macintosh computers and includes compatibility updates for certain third-party access points configured to use WPA™ or WPA2™ security.</p>
<p>WPA and WPA2 are trademarks of the Wi-Fi Alliance.</p></blockquote>
<p>Both patches require a reboot and applied without a problem on my Intel iMac. The Quicktime 7.1.6 update was also available for my Windows XP PC with iTunes.</p>
<p>Apple also released <a href="http://docs.info.apple.com/article.html?artnum=305445" title="Jump to the Apple support article on security update 2007-003v1.1">security update 2007-004 v1.1</a> which is an update a previously released version. None of my Macs qualify for the &#8220;update to the update&#8221; which includes:</p>
<ul>
<li>A fix for OS X 10.3.9 (not a typo, that&#8217;s 10.3, not .4) with the 2007-004 security update. Seems there was an issue when waking from sleep.</li>
<li>Security update 2007-004 applied an incorrect ftp configuration to OS X Server 10.4.9</li>
</ul>
<p>If you didn&#8217;t already apply 2007-004 v1.0 then you&#8217;ll be getting 2007-004v1.1 in place of it, not two updates.</p>
<p class="akst_link"><a href="http://www.theosquest.com/?p=141&amp;akst_action=share-this"  title="Email, post to del.icio.us, etc." id="akst_link_141" class="akst_share_link" rel="noindex nofollow">ShareThis</a>
</p>]]></content:encoded>
			<wfw:commentRss>http://www.theosquest.com/2007/05/01/apple-patches-quicktime-airport-and-more/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Apple Security Update 2007-004 for OS X</title>
		<link>http://www.theosquest.com/2007/04/19/apple-security-update-2007-004-for-os-x/</link>
		<comments>http://www.theosquest.com/2007/04/19/apple-security-update-2007-004-for-os-x/#comments</comments>
		<pubDate>Fri, 20 Apr 2007 03:23:21 +0000</pubDate>
		<dc:creator>ray</dc:creator>
		
		<category><![CDATA[Patches]]></category>

		<category><![CDATA[os_x]]></category>

		<category><![CDATA[security_update]]></category>

		<guid isPermaLink="false">http://www.theosquest.com/2007/04/19/apple-security-update-2007-004-for-os-x/</guid>
		<description><![CDATA[Apple release a OS X security update today, 2007-004. Apple doesn&#8217;t have a fixed schedule but they&#8217;ve released one security update a month so far this year. The patch contains 25 updates for 19 categories, see the screenshot for the list.
I installed it on my 24&#8243; iMac without incident. The shutdown and reboot took longer [...]]]></description>
			<content:encoded><![CDATA[<p>Apple release a OS X security update today, <a href="http://docs.info.apple.com/article.html?artnum=305391" title="Jump to the Apple document that describes security update 2007-004">2007-004</a>. Apple doesn&#8217;t have a fixed schedule but they&#8217;ve released one security update a month so far this year. The patch contains 25 updates for 19 categories, see the screenshot for the list.</p>
<p>I installed it on my 24&#8243; iMac without incident. The shutdown and reboot took longer than normal, long enough that I was beginning to get worried but it was fine. A second reboot took the usual amount of time.</p>
<p>I ran through my typical quick tests without a problem - start/stop iPhoto, Apple Mail, Thunderbird, iTunes (sync iPod), Chicken of the VNC, Firefox and Safari.</p>
<p><img src="http://www.theosquest.com/wp-content/uploads/2007/04/OSXUpdate1.png" alt="Here's what's in the Intel version of the update." /></p>
<p>The Power PC (PPC) version of the update is 10.0 MB. Other than the download size, the software update information for the PPC version is the same as the Intel version. Installation on my PPC Mac Mini was also without incident.</p>
<p class="akst_link"><a href="http://www.theosquest.com/?p=126&amp;akst_action=share-this"  title="Email, post to del.icio.us, etc." id="akst_link_126" class="akst_share_link" rel="noindex nofollow">ShareThis</a>
</p>]]></content:encoded>
			<wfw:commentRss>http://www.theosquest.com/2007/04/19/apple-security-update-2007-004-for-os-x/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Apple Aperture 1.5.3</title>
		<link>http://www.theosquest.com/2007/04/19/apple-aperture-153/</link>
		<comments>http://www.theosquest.com/2007/04/19/apple-aperture-153/#comments</comments>
		<pubDate>Fri, 20 Apr 2007 03:08:36 +0000</pubDate>
		<dc:creator>ray</dc:creator>
		
		<category><![CDATA[Patches]]></category>

		<category><![CDATA[aperture]]></category>

		<guid isPermaLink="false">http://www.theosquest.com/2007/04/19/apple-aperture-153/</guid>
		<description><![CDATA[Apple released Aperture 1.5.3. It&#8217;s available through Software Update or from the Apple website here. You&#8217;ll need a Apple ID and your Aperture serial number to download from the Aperture site. The Aperture &#8220;update&#8221; download is actually a download of the full program (the same for the push through software update).
The software update screen pretty [...]]]></description>
			<content:encoded><![CDATA[<p>Apple released Aperture 1.5.3. It&#8217;s available through Software Update or from the Apple website <a href="http://www.apple.com/aperture/download/" title="Jump to the Aperture download page on the Apple website">here</a>. You&#8217;ll need a Apple ID and your Aperture serial number to download from the Aperture site. The Aperture &#8220;update&#8221; download is actually a download of the full program (the same for the push through software update).</p>
<p>The software update screen pretty much sums up the information I could find on the specifics of this update.</p>
<p><img src="http://www.theosquest.com/wp-content/uploads/2007/04/ApertureUpdate1.png" alt="Screenshot of the Software Update screen for the Aperture 1.5.3 patch" /></p>
<p class="akst_link"><a href="http://www.theosquest.com/?p=127&amp;akst_action=share-this"  title="Email, post to del.icio.us, etc." id="akst_link_127" class="akst_share_link" rel="noindex nofollow">ShareThis</a>
</p>]]></content:encoded>
			<wfw:commentRss>http://www.theosquest.com/2007/04/19/apple-aperture-153/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Apple Security Update For Airport Extreme</title>
		<link>http://www.theosquest.com/2007/04/10/apple-security-update-for-airport-extreme/</link>
		<comments>http://www.theosquest.com/2007/04/10/apple-security-update-for-airport-extreme/#comments</comments>
		<pubDate>Wed, 11 Apr 2007 01:17:53 +0000</pubDate>
		<dc:creator>ray</dc:creator>
		
		<category><![CDATA[Patches]]></category>

		<category><![CDATA[airport]]></category>

		<category><![CDATA[apple]]></category>

		<category><![CDATA[firmware]]></category>

		<category><![CDATA[security_update]]></category>

		<guid isPermaLink="false">http://www.theosquest.com/2007/04/10/apple-security-update-for-airport-extreme/</guid>
		<description><![CDATA[Apple released a firmware update for their Airport Extreme Base Station with 802.11n. The Apple bulletin recommends that Airport Base Station update 2007-001  as it includes an update to the Airport Utility.
ShareThis
]]></description>
			<content:encoded><![CDATA[<p>Apple released a <a href="http://docs.info.apple.com/article.html?artnum=305366" title="Jump to the bulletin at Apple">firmware update</a> for their Airport Extreme Base Station with 802.11n. The Apple bulletin recommends that <a href="http://www.apple.com/support/downloads/" title="Jump to the downloads page at Apple">Airport Base Station update 2007-001</a>  as it includes an update to the Airport Utility.</p>
<p class="akst_link"><a href="http://www.theosquest.com/?p=116&amp;akst_action=share-this"  title="Email, post to del.icio.us, etc." id="akst_link_116" class="akst_share_link" rel="noindex nofollow">ShareThis</a>
</p>]]></content:encoded>
			<wfw:commentRss>http://www.theosquest.com/2007/04/10/apple-security-update-for-airport-extreme/feed/</wfw:commentRss>
		</item>
		<item>
		<title>It&#8217;s Microsoft Patch Tuesday</title>
		<link>http://www.theosquest.com/2007/04/10/its-microsoft-patch-tuesday/</link>
		<comments>http://www.theosquest.com/2007/04/10/its-microsoft-patch-tuesday/#comments</comments>
		<pubDate>Wed, 11 Apr 2007 01:09:25 +0000</pubDate>
		<dc:creator>ray</dc:creator>
		
		<category><![CDATA[Patches]]></category>

		<category><![CDATA[microsoft]]></category>

		<category><![CDATA[security_update]]></category>

		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.theosquest.com/2007/04/10/its-microsoft-patch-tuesday/</guid>
		<description><![CDATA[Microsoft released four security patches that they rated critical. They are&#8230;
MS07-018 is for Content Management server and doesn&#8217;t affect it&#8217;s desktop OS&#8217;s.
MS07-019 is for a vulnerability in Universal Plug and Play. It only affects Windows XP SP2 and the 64-bit version of Windows XP. Note that MS doesn&#8217;t support WinXP SP1 and the fact that [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft released four security patches that they rated critical. They are&#8230;</p>
<p><a href="http://www.microsoft.com/technet/security/Bulletin/MS07-018.mspx" title="Jump to the MS07-018 bulletin at Microsoft">MS07-018</a> is for Content Management server and doesn&#8217;t affect it&#8217;s desktop OS&#8217;s.</p>
<p><a href="http://www.microsoft.com/technet/security/Bulletin/MS07-019.mspx" title="Jump to the MS07-019 bulletin at Microsoft">MS07-019</a> is for a vulnerability in Universal Plug and Play. It only affects Windows XP SP2 and the 64-bit version of Windows XP. Note that MS doesn&#8217;t support WinXP SP1 and the fact that it&#8217;s not listed doesn&#8217;t mean it isn&#8217;t vulnerable. It just means Microsoft wants you on the latest SP and if you aren&#8217;t they don&#8217;t care. (To be fair, by now you should be on the latest SP) MS doesn&#8217;t list any known issues. Windows 2000 and Vista aren&#8217;t affected.</p>
<p><a href="http://www.microsoft.com/technet/security/Bulletin/MS07-020.mspx" title="Jump to the bulletin at Microsoft">MS07-020</a> is for a vulnerability in Microsoft Agent. It affects all Windows desktop OS&#8217;s except Vista. MS doesn&#8217;t list any known issues.</p>
<p><a href="http://www.microsoft.com/technet/security/Bulletin/MS07-021.mspx" title="Jump to the bulletin at Microsoft">MS07-021</a> is for a vulnerability in CSRSS. It affects all Microsoft desktop OS&#8217;s including Vista. MS doesn&#8217;t list any known issues.</p>
<p>And there was one bulletin rated &#8220;important&#8221;. <a href="http://www.microsoft.com/technet/security/Bulletin/MS07-022.mspx" title="Jump to the bulletin at Microsoft">MS07-022</a> is for a Windows Kernal vulnerability. This will get installed by WIndows Update (by default) as a &#8220;High Priority&#8221; update. This affects Windows 2000 SP4 (earlier SP&#8217;s aren&#8217;t supported and may be vulnerable) and Windows XP SP2 (earlier SP&#8217;s aren&#8217;t supported and may be vulnerable)</p>
<p>So in the final tally, Windows Vista is &#8220;more secure&#8221; than Windows XP as only one patch was for Vista and four (3 critical) were for Windows XP.</p>
<p>When I applied the patches to my Windows XP machines a reboot was required, which is usually the case.</p>
<p class="akst_link"><a href="http://www.theosquest.com/?p=115&amp;akst_action=share-this"  title="Email, post to del.icio.us, etc." id="akst_link_115" class="akst_share_link" rel="noindex nofollow">ShareThis</a>
</p>]]></content:encoded>
			<wfw:commentRss>http://www.theosquest.com/2007/04/10/its-microsoft-patch-tuesday/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
