Massassi Forums Logo

This is the static archive of the Massassi Forums. The forums are closed indefinitely. Thanks for all the memories!

You can also download Super Old Archived Message Boards from when Massassi first started.

"View" counts are as of the day the forums were archived, and will no longer increase.

ForumsDiscussion Forum → .WMF Exploit Patched
.WMF Exploit Patched
2006-01-08, 6:09 PM #1
http://arstechnica.com/journals/microsoft.ars/2006/1/7/2394

Grab the patch here

I'm glad to see MS didn't drop the ball with this one.
D E A T H
2006-01-08, 6:19 PM #2
This was released on Thursday >.>
Holy soap opera Batman. - FGR
DARWIN WILL PREVENT THE DOWNFALL OF OUR RACE. - Rob
Free Jin!
2006-01-08, 6:20 PM #3
8 Days IS a long time to code an entire patch that works on every single OS and produces results that don't further open the security hole.[/sarcasm]

Glad to see they hopped on it so quick, actually. SP2 fixed some major holes and that didn't come out for, what, 2 or 3 years?
ᵗʰᵉᵇˢᵍ๒ᵍᵐᵃᶥᶫ∙ᶜᵒᵐ
ᴸᶥᵛᵉ ᴼᵑ ᴬᵈᵃᵐ
2006-01-08, 6:23 PM #4
Indeed.
D E A T H
2006-01-08, 7:16 PM #5
Would it be safe to assume that windows update automatically downloaded and installed this when I ran it yesterday?
2006-01-08, 7:18 PM #6
Originally posted by JediKirby:
SP2 fixed some major holes and that didn't come out for, what, 2 or 3 years?

I'll agree that for a multi-billion dollar software giant, Microsoft is rather slow at patching severe exploits, but to be fair, a lot of updates in SP2 were gradual and had been released previously. Service packs are largely accumulations of patches.
Bassoon, n. A brazen instrument into which a fool blows out his brains.
2006-01-08, 10:42 PM #7
Originally posted by Stormtrooper:
Would it be safe to assume that windows update automatically downloaded and installed this when I ran it yesterday?


For the sake of a fairly small file (I think it was about a meg when I patched Izzy's laptop) I'd go get it.
2006-01-08, 10:55 PM #8
Go to add/remove programs & select show updates.

Look for Windows Security Update KB912919. If you have it, you're all set. If you don't, go get it. :)

This is assuming you're on WinXP..I don't know if it's the same # for 2k.
woot!
2006-01-08, 11:21 PM #9
If an exploit is found, is there any real incentive for Mircosoft to update right away?
SnailIracing:n(500tpostshpereline)pants
-----------------------------@%
2006-01-08, 11:48 PM #10
Dang... I can't get the patch installed! It says I need version one of the servicepack first. I have SP1 though... I wonder if it means SP2. If that is the case, then I have a problem, because I have tried several times, but I simply can't install SP2 on my comp. =\
ORJ / My Level: ORJ Temple Tournament I
2006-01-09, 12:00 AM #11
Wow, uh, that's really bad. You might want to get that working.
2006-01-09, 5:03 AM #12
Originally posted by ORJ_JoS:
Dang... I can't get the patch installed! It says I need version one of the servicepack first. I have SP1 though... I wonder if it means SP2. If that is the case, then I have a problem, because I have tried several times, but I simply can't install SP2 on my comp. =\


oh... yeah, the .wmf issue is sort of the least of your worries if you don't have SP2...
ᵗʰᵉᵇˢᵍ๒ᵍᵐᵃᶥᶫ∙ᶜᵒᵐ
ᴸᶥᵛᵉ ᴼᵑ ᴬᵈᵃᵐ
2006-01-09, 7:00 AM #13
haha, I remember last summer, "oh nos, SP2 will break all your applications, don't get it!"

and now? "you'd better have SP2 or you're in big trouble."

Reality can change. It's just a matter of time. :o
Cordially,
Lord Tiberius Grismath
1473 for '1337' posts.
2006-01-10, 2:56 AM #14
Heh, new vulnerability found in WMF: http://blogs.technet.com/msrc/archive/2006/01/09/417198.aspx

Not as severe as the previous exploit, but usable for a simple DoS.
Sorry for the lousy German
2006-01-10, 8:42 AM #15
Originally posted by Lord_Grismath:
haha, I remember last summer, "oh nos, SP2 will break all your applications, don't get it!"

and now? "you'd better have SP2 or you're in big trouble."

Reality can change. It's just a matter of time. :o

Not so much reality changing as the patching process for SP2 changed. They fixed a lot of the major bugs with it--originally it would stop during installation (voiding your current windows installation, making you reformat and reinstall), install wrong (same thing as before) or have weird settings upon installation and make certain drivers not work.
D E A T H

↑ Up to the top!