PDA

ѕросмотр полной версии : February Microsoft Security Updates



Shu_b
09.02.2005, 12:10
February Microsoft Security Updates
Windows, February: MS05-004, MS05-006ЦMS05-015
Office, February: MS05-005, MS05-006

Microsoft Security Bulletin MS05-004
Maximum severity: Important
Update number: 887219
Supported software affected:
Х Microsoft .NET Framework 1.1 (all versions)
Х Microsoft .NET Framework 1.0 Service Pack 3 (SP3) and SP2
Technical bulletin: ASP.NET Path Validation Vulnerability (887219)
http://www.microsoft.com/technet/security/bulletin/MS05-004.mspx
rus: http://www.securitylab.ru/52532.html

Microsoft Security Bulletin MS05-005
Maximum severity: Critical
Update number: 873352
Supported software affected:
Х Office XP SP3 and SP2
Х Microsoft Project 2002
Х Microsoft Visio 2002
Х Microsoft Works Suite 2004
Х Microsoft Works Suite 2003
Х Microsoft Works Suite 2002
Technical bulletin: Vulnerability in Microsoft Office XP Could Lead to Buffer Overrun (873352)
http://www.microsoft.com/technet/security/bulletin/MS05-005.mspx
rus: http://www.securitylab.ru/52529.html

Microsoft Security Bulletin MS05-006
Maximum severity: Moderate
Update number: 887981
Supported software affected:
Х SharePoint Team Services from Microsoft
Technical bulletin: Vulnerability in Windows SharePoint Services and SharePoint Team Services Could Allow Cross-Site Scripting and Spoofing Attacks (887981)
http://www.microsoft.com/technet/security/bulletin/MS05-006.mspx
rus: http://www.securitylab.ru/52513.html

Microsoft Security Bulletin MS05-007
Maximum severity: Important
Update number: 888302
Supported software affected:
Х Windows XP SP2 and SP1
Х Windows XP 64-Bit Edition SP1 (Itanium)
Technical bulletin: Vulnerability in Windows Could Allow Information Disclosure (888302)
http://www.microsoft.com/technet/security/bulletin/MS05-007.mspx
rus: http://www.securitylab.ru/52515.html

Microsoft Security Bulletin MS05-008
Maximum severity: Important
Update number: 890047
Supported software affected:
Х Windows XP SP2 and SP1
Х Windows XP 64-Bit Edition SP1 (Itanium)
Х Windows XP 64-Bit Edition Version 2003 (Itanium)
Х Windows 2000 SP4 and SP3
Х Windows Server 2003
Х Windows Server 2003 for 64-Bit Itanium-based Systems
Technical bulletin: Vulnerability in Windows Shell Could Allow Remote Code Execution (890047)
http://www.microsoft.com/technet/security/bulletin/MS05-008.mspx
rus: http://www.securitylab.ru/52517.html

Microsoft Security Bulletin MS05-009
Maximum severity: Critical
Update number: 890261
Supported software affected:
Х Windows Media Player 9 on Windows XP, Windows 2000, or Windows Server 2003
Х Windows XP 64-Bit Edition SP1 running Windows Messenger
Х Windows XP 64-Bit Edition Version 2003 running Windows Messenger
Х Windows Millennium Edition (Windows Me), Windows 98 Second Edition (SE), and Windows 98
Note Updates for Windows Me, Windows 98 SE, and Windows 98 are being made available under extended support for critical security issues.
Х Windows Messenger 4.7.2009 on Windows XP SP1 and Windows XP
Х Windows Messenger 4.7.3000 on Windows XP SP2
Х Windows Messenger 5.0
Technical bulletin: Vulnerability in PNG Processing Could Lead to Buffer Overrun (890261)
http://www.microsoft.com/technet/security/bulletin/MS05-009.mspx
rus: http://www.securitylab.ru/52519.html

Microsoft Security Bulletin MS05-010
Maximum severity: Critical
Update number: 885834
Supported software affected:
Х Windows NT Server 4.0 SP6a
Х Windows NT Server 4.0, Terminal Server Edition SP6
Х Windows 2000 Server SP4 and SP3
Х Windows Server 2003
Х Windows Server 2003 for 64-Bit Itanium-based Systems
Technical bulletin: Vulnerability in the License Logging Service Could Allow Code Execution (885834)
http://www.microsoft.com/technet/security/bulletin/MS05-010.mspx
rus: http://www.securitylab.ru/52525.html

Microsoft Security Bulletin MS05-011
Maximum severity: Critical
Update number: 885250
Supported software affected:
Х Windows XP SP2 and SP1
Х Windows XP 64-Bit Edition SP1 (Itanium)
Х Windows XP 64-Bit Edition Version 2003 (Itanium)
Х Windows 2000 SP4 and SP3
Х Windows Server 2003
Х Windows Server 2003 for 64-Bit Itanium-based Systems
Technical bulletin: Vulnerability in Server Message Block Could Allow Remote Code Execution (885250)
http://www.microsoft.com/technet/security/bulletin/MS05-011.mspx
rus: http://www.securitylab.ru/52521.html

Microsoft Security Bulletin MS05-012
Maximum severity: Critical
Update number: 873333
Supported software affected:
Х Windows XP SP2 and SP1
Х Windows XP 64-Bit Edition SP1 (Itanium)
Х Windows XP 64-Bit Edition Version 2003 (Itanium)
Х Windows 2000 SP4 and SP3
Х Windows Server 2003
Х Windows Server 2003 for 64-Bit Itanium-based Systems
Х Office XP Service Pack 3 (SP3), Office XP SP2, and Office XP
Note Office XP includes Outlook 2002, Word 2002, Excel 2002, PowerPoint 2002, FrontPage 2002, Publisher 2002, and Access 2002
Х Office 2003 SP1 and Office 2003
Note Office 2003 includes Outlook 2003, Word 2003, Excel 2003, PowerPoint 2003, FrontPage 2003, Publisher 2003, Access 2003, InfoPath 2003, and OneNote 2003
Х Exchange 2000 Server Service Pack 3 (SP3)
Х Exchange Server 2003 and Exchange Server 2003 SP1
Х Exchange Server 5.0 SP2
Х Exchange Server 5.5 SP4
Technical bulletin: Vulnerability in OLE and COM Could Allow Remote Code Execution (873333)
http://www.microsoft.com/technet/security/bulletin/MS05-012.mspx
rus: http://www.securitylab.ru/52523.html

Microsoft Security Bulletin MS05-013
Maximum severity: Critical
Update number: 891781
Supported software affected:
Х Windows XP SP2 and SP1
Х Windows XP 64-Bit Edition SP1 (Itanium)
Х Windows XP 64-Bit Edition Version 2003 (Itanium)
Х Windows 2000 SP4 and SP3
Х Windows Server 2003
Х Windows Server 2003 for 64-Bit Itanium-based Systems
Х Windows Me, Windows 98 SE, and Windows 98
Note Updates for Windows Me, Windows 98 SE, and Windows 98 are being made available under extended support for critical security issues.
Technical bulletin: Vulnerability in the DHTML Editing Component ActiveX Control Could Allow Code Execution
http://www.microsoft.com/technet/security/bulletin/MS05-013.mspx
rus: http://www.securitylab.ru/52534.html

Microsoft Security Bulletin MS05-014
Maximum severity: Critical
Update number: 867282
Supported software affected:
Х Internet Explorer 6 SP1 on Windows XP SP1, on Windows XP, or on Windows 2000 SP4 or SP3
Х Internet Explorer 6 SP1 on Windows Me, on Windows 98 SE, or on Windows 98
Note Updates for Windows Me, Windows 98 SE, and Windows 98 are being made available under extended support for critical security issues.
Х Internet Explorer 6 for Windows XP SP1 (64-Bit Edition)
Х Internet Explorer 6 for Windows Server 2003
Х Internet Explorer 6 for Windows Server 2003 64-Bit Edition and Windows XP 64-Bit Edition Version 2003
Х Internet Explorer 6 for Windows XP SP2
Х Internet Explorer 5.5 SP2 on Windows Me
Note This update is being made available under extended support for critical security issues.
Х Internet Explorer 5.01 SP4 on Windows 2000 SP4
Х Internet Explorer 5.01 SP3 on Windows 2000 SP3
Technical bulletin: Cumulative Security Update for Internet Explorer (867282)
http://www.microsoft.com/technet/security/bulletin/MS05-014.mspx
rus: http://www.securitylab.ru/52531.html

Microsoft Security Bulletin MS05-015
Maximum severity: Critical
Update number: 888113
Supported software affected:
Х Windows XP SP2 and SP1
Х Windows 2000 SP4 and SP3
Х Windows XP 64-Bit Edition SP1 (Itanium)
Х Windows XP 64-Bit Edition Version 2003 (Itanium)
Х Windows Server 2003
Х Windows Server 2003 for 64-Bit Itanium-based Systems
Х Windows Me, Windows 98 SE, and Windows 98
Note Updates for Windows Me, Windows 98 SE, and Windows 98 are being made available under extended support for critical security issues.
Technical bulletin: Vulnerability in Hyperlink Object Library Could Allow Remote Code Execution (888113)
http://www.microsoft.com/technet/security/bulletin/MS05-015.mspx
rus: http://www.securitylab.ru/52527.html

santy
09.02.2005, 14:31
имеет ли значение последовательность выполнени€ указанных обновлений дл€ win2000, например?

pig
09.02.2005, 16:58
я думаю, что в пределах этой пачки - нет.

Minos
10.02.2005, 16:47
имеет ли значение последовательность выполнени€ указанных обновлений дл€ win2000, например?

ќбычно последовательность не имеет значени€. ≈сли вы будите пытатьс€ установить уже установленное обновлени€, установку не начнетс€, а в дистрибутив с обновлением вход€т все необходимые дл€ его правильной установки файлы. ¬ любом случае, если обновление не подходит к ¬ашей операционной системе (например не та верси€), то будет выдано соответствующее предупреждение и установка не начнетс€.

pig
10.02.2005, 18:31
Ћучше всЄ-таки устанавливать заплатки по хронологии выпуска. ћало ли что. ќшибаютс€ все, в том числе и те, кто INF дл€ заплаток пишет.