copyright
|
disclaimer
|
privacy
|
contact
HOME
About
AusCERT
Membership
Contact Us
PKI Services
Training
Publications
Sec. Bulletins
Conferences
News & Media
Services
Web Log
Site Map
Site Help
Member login
Login »
Become a member »
Home
»
Security Bul...
»
By Operating...
»
Windows (all)
» AU-2007.0022 -- AusCERT Update - [Win] - Microsoft S...
AU-2007.0022 -- AusCERT Update - [Win] - Microsoft Security Bulletin MS07-042 Re-Release
Date:
28 September 2007
References
:
AL-2007.0095
AU-2008.0013
Click here for printable version
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 AusCERT Update AU-2007.0022 - [Win] Microsoft Security Bulletin MS07-042 Re-Release 28 September 2007 AusCERT Update Summary ---------------------- Product: Microsoft XML Core Services 3.0, 4.0, 5.0, 6.0 Publisher: Microsoft Operating System: Windows Vista Windows Server 2003 Windows XP Windows 2000 Impact: Execute Arbitrary Code/Commands Access: Remote/Unauthenticated CVE Names: CVE-2007-2223 Ref: AL-2007.0095 Original Bulletin: http://www.microsoft.com/technet/security/bulletin/ms07-042.mspx - -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ******************************************************************** Title: Microsoft Security Bulletin Re-Release Issued: September 27, 2007 ******************************************************************** Summary ======= The following bulletin has undergone a major revision increment. Please see the appropriate bulletin for more details. * MS07-042 - Critical Bulletin Information: ===================== * MS07-042 - Critical - http://www.microsoft.com/technet/security/bulletin/ms07-042.mspx - Reason for Revision: Bulletin Updated: Added Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats and Microsoft Expression Web as affected products. The Bulletin has also been updated to inform customers that a potential reliability issue exists in applications that have installed Microsoft XML Core Services 4.0 on Windows Vista, which can be addressed by applying the download available in Microsoft Knowledge Base Article 941833. - Originally posted: August 14, 2007 - Updated: September 27, 2007 - Bulletin Severity Rating: Critical - Version: 2.0 Other Information ================= Recognize and avoid fraudulent e-mail to Microsoft customers: ============================================================= If you receive an e-mail message that claims to be distributing a Microsoft security update, it is a hoax that may contain malware or pointers to malicious Web sites. Microsoft does not distribute security updates via e-mail. The Microsoft Security Response Center (MSRC) uses PGP to digitally sign all security notifications. However, it is not required to read security notifications, security bulletins, security advisories, or install security updates. You can obtain the MSRC public PGP key at https://www.microsoft.com/technet/security/bulletin/pgp.mspx. To receive automatic notifications whenever Microsoft Security Bulletins and Microsoft Security Advisories are issued or revised, subscribe to Microsoft Technical Security Notifications on http://www.microsoft.com/technet/security/bulletin/notify.mspx. ******************************************************************** THE INFORMATION PROVIDED IN THIS MICROSOFT COMMUNICATION IS PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING LIMITATION MAY NOT APPLY. ******************************************************************** - -----BEGIN PGP SIGNATURE----- Version: PGP 8.1 iQIVAwUBRvwlPIlDklrxMhdPAQKcTg/+LQ2V2lF02wcdzi3mKC/b5zCOfRTsjdvD OBcDcYMitsRSwuRhgYPWzKVVXBn3g4fVCh0lnONGuWBVa+YeEsdm69IbQAS8ECZY iYrkNIRx5zlTsAz+nhB02gcpCgbrbRUs1di9X/XbvG/jBQ7GO6kxDvOZ57KxOwLH lZwr1uGKVRfh+35UFT7tFwQPLPJVmKVOMsAHV3v1ZAjJAWZTh7WL3aOhTk1DKb+o SWn8/BnPrqY4yCM4SA7JA5lXCXWNxlUxpx9JOIU7dHe+2MHy+cVaHnVgskmRglA7 Bgh8+LyBZbncaSuYqpkgi/UvMmWMeU9jKS/JtDL9GKtJ/qUMbuu2AFqmlc58i5Li Jv+PGgiCIwZkieCgAHOEuaHBZ4Bd9UquImPIMYNH075nzsNbEVt6H59Ib7gUyDbV Ct68XiRbmLiM/wAqvSRf+BMy0aJUv7SwVynLZmi+kONKT9/VzVK4FloYOEDtaEIA 4kpgdr/fyZTT6ac6KLnhF0rPcKdQ/ouXIcOfYukYtrBgD2Dek390+LRdXRQ4OiaA RnO8sGqmK4K//Ki0uxYAka4HDwDDZv1PnJdJ6P5gqn9cLEOP4xJhmQ5NoXSgkUs4 NMPwFqrhboB5EePQ0+1ysYAa6arPV7FxPKDSiujOMT/WxOaDc7R47OYiXx7Zc0Eb svjWFoRlzX0= =2aRP - -----END PGP SIGNATURE----- AusCERT has made every effort to ensure that the information contained in this document is accurate. However, the decision to use the information described is the responsibility of each user or organisation. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. If you believe that your computer system has been compromised or attacked in any way, we encourage you to let us know by completing the secure National IT Incident Reporting Form at: http://www.auscert.org.au/render.html?it=3192 =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQCVAwUBRvxjTSh9+71yA2DNAQKIEwQAhffQtwRoErdikFi7mL6u8spUi0c2DKvp 0/PjKt+MEjIoQrS1GE6VxshR6oJkZQvpOkTPKrynkxUW6Jba+VfOSMqgbOOh9D9Y FPWW3SIqNxN5QmyVJiVJR9K/eingBqgNLRksAM9UlWWtKV44LXngPyWPZTegu8HQ bg8SEs4W4EI= =XrsT -----END PGP SIGNATURE-----
Comments? Click here
http://www.auscert.org.au/render.html?cid=21&it=8135