<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Spam Chronicles&#187; os-security-patch</title>
	<atom:link href="http://www.spamchronicles.com/tag/os-security-patch/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.spamchronicles.com</link>
	<description>Chronicling My Spam Explorations</description>
	<lastBuildDate>Wed, 12 Sep 2007 02:11:20 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Microsoft Patch Tuesday for August 2007</title>
		<link>http://www.spamchronicles.com/2007/08/14/microsoft-patch-tuesday-for-august-2007/</link>
		<comments>http://www.spamchronicles.com/2007/08/14/microsoft-patch-tuesday-for-august-2007/#comments</comments>
		<pubDate>Tue, 14 Aug 2007 19:26:56 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[os-security-patch]]></category>
		<category><![CDATA[software-security-patch]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/microsoft-patch-tuesday-for-august-2007/</guid>
		<description><![CDATA[Microsoft patch Tuesday for August 2007 brings us 6 critical and 3 important security updates from Microsoft. Microsoft summarizes the patches in their August summary. Every supported desktop version of Windows is affected by one or more patches. Several Microsoft Office versions are also affected along with several versions of Virtual PC and Virtual Server. [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.spamchronicles.com/wp-content/uploads/2008/02/ms_security_alert.gif" alt="MS Security Alert" align="left" /><b>Microsoft patch Tuesday</b> for August 2007 brings us <b>6 critical</b> and <b>3 important</b> security updates from <b>Microsoft</b>. Microsoft <a href="http://www.microsoft.com/technet/security/bulletin/ms07-aug.mspx" title="Jump to the Microsoft article about the security patches">summarizes the patches</a> in their August summary. Every supported desktop version of Windows is affected by one or more patches.  Several Microsoft Office versions are also affected along with several versions of Virtual PC and Virtual Server. Microsoft Office for Mac also needs patching.</p>
<p>Rather than repeating all the patches I&#8217;ll direct you to news.com which has a <a href="http://news.com.com/8301-10784_3-9759611-7.html?tag=nefd.only" title="Jump to the news.com summary of the Microsoft patches">good summary of the patches</a> along with links to the individual bulletins. The patches are available through automatic updates or individual downloads.</p>
<p>Happy patching and good luck.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/07/11/microsoft-patch-tuesday-for-july-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for July 2007</a></li><li><a href="http://www.spamchronicles.com/2007/06/12/microsoft-patch-tuesday-for-june-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for June 2007</a></li><li><a href="http://www.spamchronicles.com/2007/05/08/may-2007-patch-tuesday/" rel="bookmark" class="crp_title">May 2007 Patch Tuesday</a></li><li><a href="http://www.spamchronicles.com/2007/04/03/microsoft-releases-patch-for-animated-cursor-vulnerability/" rel="bookmark" class="crp_title">Microsoft Releases Patch for Animated Cursor Vulnerability</a></li><li><a href="http://www.spamchronicles.com/2007/07/11/apple-adds-to-patch-tuesday/" rel="bookmark" class="crp_title">Apple Adds to Patch Tuesday</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/08/14/microsoft-patch-tuesday-for-august-2007/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OSX Security Update 2007-007</title>
		<link>http://www.spamchronicles.com/2007/07/31/osx-security-update-2007-007/</link>
		<comments>http://www.spamchronicles.com/2007/07/31/osx-security-update-2007-007/#comments</comments>
		<pubDate>Wed, 01 Aug 2007 02:32:39 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[os-security-patch]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/osx-security-update-2007-007/</guid>
		<description><![CDATA[Apple almost made it through the month of July without an operating system security update which would have been a first for the year. But OS X Security Update 2007-007 was released on the last day of the month. Thirteen components are updated. Click the thumbnail to see the component list or visit the Apple [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.spamchronicles.com/wp-content/uploads/2008/02/osxsecurityupdate2007-007.png" title="OS X Security Update 2007-007"><img src="http://www.spamchronicles.com/wp-content/uploads/2008/02/osxsecurityupdate2007-007.thumbnail.png" alt="OS X Security Update 2007-007" align="left" /></a><b>Apple</b> almost made it through the month of July without an operating system security update which would have been a first for the year. But <b>OS X Security Update 2007-007</b> was released on the last day of the month.</p>
<p>Thirteen components are updated. Click the thumbnail to see the component list or visit the <a href="http://docs.info.apple.com/article.html?artnum=306172" title="Jump to the Apple support page for the update">Apple Support Page</a> for the complete details. Of special note is the Samba vulnerability that Apple has finally patched. Samba is an open source windows file sharing application that is bundled with OS X. A critical vulnerability was found in late may and almost immediately patched by the Samba team. Apple has released several security updates since then but none have included the Samba patch, until now. Samba is off by default but is enabled when turning on Windows sharing in System Preference -&gt; Sharing.</p>
<p>The update is for both Intel and PPC based Macs running OS X 10.3.9 or OS X 10.4.10 including the standard OS and the Server OS. It&#8217;s available through Apple&#8217;s built-in software update service or as a standalone download. A computer restart is needed after applying the patch.</p>
<p>Apple also released <a href="http://www.apple.com/support/downloads/airportextremeupdate2007004.html" title="Jump to the Airport Extreme Update support page">Airport Extreme Update 2007-004</a>. Details are lacking and Apple&#8217;s only comment is:</p>
<blockquote><p>This update is recommended for all Intel-based MacBook, MacBook Pro, and Mac mini computers and improves the reliability of AirPort connections.</p></blockquote>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/06/21/apple-releases-10410-for-os-x/" rel="bookmark" class="crp_title">Apple Releases 10.4.10 for OS X</a></li><li><a href="http://www.spamchronicles.com/2007/06/23/security-update-2007-006-for-apple-os-x/" rel="bookmark" class="crp_title">Security Update 2007-006 for Apple OS X</a></li><li><a href="http://www.spamchronicles.com/2007/05/25/security-update-2007-05-for-mac-os-x/" rel="bookmark" class="crp_title">Security Update 2007-05 for Mac OS X</a></li><li><a href="http://www.spamchronicles.com/2007/07/11/apple-adds-to-patch-tuesday/" rel="bookmark" class="crp_title">Apple Adds to Patch Tuesday</a></li><li><a href="http://www.spamchronicles.com/2007/05/30/quicktime-security-update1/" rel="bookmark" class="crp_title">Quicktime Security Update</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/07/31/osx-security-update-2007-007/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Patch Tuesday for July 2007</title>
		<link>http://www.spamchronicles.com/2007/07/11/microsoft-patch-tuesday-for-july-2007/</link>
		<comments>http://www.spamchronicles.com/2007/07/11/microsoft-patch-tuesday-for-july-2007/#comments</comments>
		<pubDate>Wed, 11 Jul 2007 12:55:43 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[ie-security-patch]]></category>
		<category><![CDATA[os-security-patch]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/microsoft-patch-tuesday-for-july-2007/</guid>
		<description><![CDATA[It&#8217;s the second Tuesday of July and that means patches from Microsoft. This month brings six patches, three rated critical, two important, and one moderate. Only five of the patches (and only two of the critical patches) are for desktops. The sixth patch only affects server operating systems. Windows Vista also gets its own unique [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.spamchronicles.com/wp-content/uploads/2008/02/ms_security_alert.gif" alt="MS Security Alert" align="left" />It&#8217;s the second Tuesday of July and that means patches from <b>Microsoft</b>. This month brings <b>six patches</b>, three rated critical, two important, and one moderate. Only five of the patches (and only two of the critical patches) are for desktops. The sixth patch only affects server operating systems. Windows Vista also gets its own unique patch although it&#8217;s the one rated moderate.</p>
<p>Two of the patches affect <b>Microsoft Office</b> software:</p>
<p><a href="http://www.microsoft.com/technet/security/Bulletin/MS07-036.mspx" title="Jump to the MS07-036 bulletin at Microsoft">MS07-036</a> is rated <b>critical</b> and affects all versions of <b>Microsoft Excel </b>from Excel 2000 on up. It also applies to the Office 2007 compatibility pack. It&#8217;s only rated critical for Excel 2000. Microsoft rates the other versions as &#8220;important&#8221;. The bulletin does not list any known issues.</p>
<p><a href="http://www.microsoft.com/technet/security/Bulletin/MS07-037.mspx" title="Jump to the MS07-037 bulletin">MS07-037</a> is rated <b>important</b> and affects <b>Microsoft Office Publisher 2007</b> only. The bulletin does not list any known issues.</p>
<p>One patch affects Vista only:</p>
<p><a href="http://www.microsoft.com/technet/security/Bulletin/MS07-038.mspx" title="Jump to the MS07-038 bulletin">MS07-038</a> is rated <b>moderate</b> and affects <b>Windows Vista</b>, both 32-bit and 64-bit versions. This patches a vulnerability in the Windows Vista firewall that could allow an attacker to gather information about a host. There are no known issues listed in the bulletin.</p>
<p>One patch affects <b>.NET</b>:</p>
<p><a href="http://www.microsoft.com/technet/security/Bulletin/MS07-040.mspx" title="Jump to the MS07-040 bulletin">MS07-040</a> is rated critical and affects .NET versions 1.x and 2.x, version 3.x is not affected. All operating systems are affected if they have a vulnerable version of .NET installed. There are no known issues listed in the bulletin.</p>
<p>The final desktop patch, <a href="http://www.microsoft.com/technet/security/Bulletin/MS07-041.mspx" title="Jump to the MS07-041 bulletin">MS-07-041</a>, is rated important and affects Microsoft Internet Information Server (IIS) when running on Windows XP SP2. Earlier versions of Windows XP may be affected but Microsoft only supports service pack 2. IIS is not installed by default on Windows XP.</p>
<p>The server patch is is <a href="http://www.microsoft.com/technet/security/Bulletin/MS07-039.mspx" title="Jump to the MS07-039 bulletin">MS07-039</a> and is a vulnerability in Active Directory that&#8217;s rated critical.</p>
<p>The patches are available through automatic update or can be downloaded individually from Microsoft.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/06/12/microsoft-patch-tuesday-for-june-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for June 2007</a></li><li><a href="http://www.spamchronicles.com/2007/05/08/may-2007-patch-tuesday/" rel="bookmark" class="crp_title">May 2007 Patch Tuesday</a></li><li><a href="http://www.spamchronicles.com/2007/04/03/microsoft-releases-patch-for-animated-cursor-vulnerability/" rel="bookmark" class="crp_title">Microsoft Releases Patch for Animated Cursor Vulnerability</a></li><li><a href="http://www.spamchronicles.com/2007/08/14/microsoft-patch-tuesday-for-august-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for August 2007</a></li><li><a href="http://www.spamchronicles.com/2007/07/18/firefox-2005-released/" rel="bookmark" class="crp_title">Firefox 2.0.0.5 Released</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/07/11/microsoft-patch-tuesday-for-july-2007/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Update 2007-006 for Apple OS X</title>
		<link>http://www.spamchronicles.com/2007/06/23/security-update-2007-006-for-apple-os-x/</link>
		<comments>http://www.spamchronicles.com/2007/06/23/security-update-2007-006-for-apple-os-x/#comments</comments>
		<pubDate>Sat, 23 Jun 2007 23:55:56 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[os-security-patch]]></category>
		<category><![CDATA[osx]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/security-update-2007-006-for-apple-os-x/</guid>
		<description><![CDATA[Apple has released a security-only update for OS X. It&#8217;s the appropriately named Security Update 2007-006 as Apple has released one security update a month so far this year. This update is needed for 10.4.9 along with the just released 10.4.10. It&#8217;s also needed for 10.3.9. The security update addresses two vulnerabilities. One is in [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.spamchronicles.com/wp-content/uploads/2008/02/osx2007-006.png" title="OS X Security Update 2007-006"><img src="http://www.spamchronicles.com/wp-content/uploads/2008/02/osx2007-006.thumbnail.png" alt="OS X Security Update 2007-006" align="left" /></a><b>Apple</b><b> </b>has released a security-only update for OS X. It&#8217;s the appropriately  named <a href="http://docs.info.apple.com/article.html?artnum=305759" title="Jump to the Apple support article about the update"><b>Security Update 2007-006</b></a> as Apple has released one security update a month so far this year. This update is needed for 10.4.9 along with the just released 10.4.10. It&#8217;s also needed for 10.3.9. The security update addresses two vulnerabilities.</p>
<p>One is in <b>Webcore</b> and can allow <b>cross-site scripting attacks</b>.</p>
<p>The second patched vulnerability was in <b>Webkit</b> and could allow remote code execution.</p>
<p>The update is available through Software Update or as a <a href="http://www.apple.com/support/downloads/" title="Jump to the Apple download page">standalone download</a> and requires a reboot.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/06/21/apple-releases-10410-for-os-x/" rel="bookmark" class="crp_title">Apple Releases 10.4.10 for OS X</a></li><li><a href="http://www.spamchronicles.com/2007/07/31/osx-security-update-2007-007/" rel="bookmark" class="crp_title">OSX Security Update 2007-007</a></li><li><a href="http://www.spamchronicles.com/2007/07/11/apple-adds-to-patch-tuesday/" rel="bookmark" class="crp_title">Apple Adds to Patch Tuesday</a></li><li><a href="http://www.spamchronicles.com/2007/05/30/quicktime-security-update1/" rel="bookmark" class="crp_title">Quicktime Security Update</a></li><li><a href="http://www.spamchronicles.com/2007/05/25/security-update-2007-05-for-mac-os-x/" rel="bookmark" class="crp_title">Security Update 2007-05 for Mac OS X</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/06/23/security-update-2007-006-for-apple-os-x/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Apple Releases 10.4.10 for OS X</title>
		<link>http://www.spamchronicles.com/2007/06/21/apple-releases-10410-for-os-x/</link>
		<comments>http://www.spamchronicles.com/2007/06/21/apple-releases-10410-for-os-x/#comments</comments>
		<pubDate>Thu, 21 Jun 2007 13:48:24 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[os-security-patch]]></category>
		<category><![CDATA[osx]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/apple-releases-10410-for-os-x/</guid>
		<description><![CDATA[Apple has released OS X version 10.4.10. While it contains several enhancements and fixes for the operating system it also includes one security related update. This security update keeps Apple in the one-a-month category for security updates to OS X. This security vulnerability is described by Apple as: &#8230;the reception of specially crafted IPv6 packets [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.spamchronicles.com/wp-content/uploads/2008/02/applebluelogo.thumbnail.jpg" alt="Apple Logo (Blue)" align="left" /><b>Apple</b> has released <b>OS X version 10.4.10</b>. While it contains several enhancements and fixes for the operating system it also includes <a href="http://docs.info.apple.com/article.html?artnum=305712" title="Jump to the Apple support article about the security update">one security related update</a>. This <b>security update</b> keeps Apple in the one-a-month category for security updates to OS X.</p>
<p>This security vulnerability is described by Apple as:</p>
<blockquote><p>&#8230;the reception of specially crafted IPv6 packets may lead to a reduction in network bandwidth.</p></blockquote>
<p>This is a relatively low risk vulnerability as it doesn&#8217;t include a potential loss of data and doesn&#8217;t allow the installation of malicious software. The update also includes security patches released since 10.4.9.</p>
<p><a href="http://www.spamchronicles.com/wp-content/uploads/2007/06/osx10410.png" title="Software Update 10.4.10"><img src="http://www.spamchronicles.com/wp-content/uploads/2007/06/osx10410.thumbnail.png" alt="Software Update 10.4.10" align="left" /></a>The update is available through the Software Update feature of OS X or as a standalone download. The Intel version of the update is a 49MB download when done through Software Update (click the thumbnail to see notification full size). The update is also available as a <a href="http://www.apple.com/support/downloads/" title="Jump to the update download page at Apple">standalone installer in four forms</a>. There are downloads for the Power PC (PPC) and Intel CPUs. Then each CPU has a &#8220;delta&#8221; update which requires that 10.4.9 already be applied and a much larger &#8220;combo&#8221; update which includes all previous updates to OS X 10.4.</p>
<p>I applied the update to two Intel Macs without incident. Like previous updates the first reboot after the patch is significantly longer than usual.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/07/11/apple-adds-to-patch-tuesday/" rel="bookmark" class="crp_title">Apple Adds to Patch Tuesday</a></li><li><a href="http://www.spamchronicles.com/2007/07/31/osx-security-update-2007-007/" rel="bookmark" class="crp_title">OSX Security Update 2007-007</a></li><li><a href="http://www.spamchronicles.com/2007/06/23/security-update-2007-006-for-apple-os-x/" rel="bookmark" class="crp_title">Security Update 2007-006 for Apple OS X</a></li><li><a href="http://www.spamchronicles.com/2007/05/25/security-update-2007-05-for-mac-os-x/" rel="bookmark" class="crp_title">Security Update 2007-05 for Mac OS X</a></li><li><a href="http://www.spamchronicles.com/2007/05/30/quicktime-security-update1/" rel="bookmark" class="crp_title">Quicktime Security Update</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/06/21/apple-releases-10410-for-os-x/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Patch Tuesday for June 2007</title>
		<link>http://www.spamchronicles.com/2007/06/12/microsoft-patch-tuesday-for-june-2007/</link>
		<comments>http://www.spamchronicles.com/2007/06/12/microsoft-patch-tuesday-for-june-2007/#comments</comments>
		<pubDate>Wed, 13 Jun 2007 02:26:02 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[ie-security-patch]]></category>
		<category><![CDATA[os-security-patch]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/microsoft-patch-tuesday-for-june-2007/</guid>
		<description><![CDATA[Microsoft released six security patches today. Four of them were rated critical, one important and one moderate. There are patches for all supported desktop OS platforms, Internet Explorer, a couple mail apps and for a couple versions of Visio. There aren&#8217;t any Office patches. The four critical desktop patches are: MS07-031 for Windows XP SP2, [...]]]></description>
			<content:encoded><![CDATA[<p><img src='http://www.spamchronicles.com/wp-content/uploads/2007/06/ms_security_alert.gif' alt='Microsoft Security Alert'><strong>Microsoft</strong> released <a href="http://www.microsoft.com/technet/security/bulletin/ms07-jun.mspx" title="Jump to the Microsoft announcement bulletin for June">six security patches today</a>. Four of them were rated critical, one important and one moderate. There are patches for all supported desktop OS platforms, Internet Explorer, a couple mail apps and for a couple versions of Visio. There aren&#8217;t any Office patches.</p>
<p>The four <strong>critical desktop patches</strong> are:</p>
<p><a href="http://www.microsoft.com/technet/security/Bulletin/MS07-031.mspx" title="Jump to the bulletin for MS07-031 at Microsoft">MS07-031</a> for Windows XP SP2, Windows XP x64 and Windows XP x64 SP2. It&#8217;s rated as &#8220;important&#8221; for Windows 2000 SP4. Earlier versions of Windows 2000 and XP may be affected but aren&#8217;t supported by Microsoft. On Windows XP this vulnerability can allow remote code execution. On other OS&#8217;s the vulnerability results in a denial of service attack (such as a system crash). The user must visit a malicious website to be exploited.</p>
<p><a href="http://www.microsoft.com/technet/security/bulletin/ms07-033.mspx" title="Jump to the MS07-033 bulletin at Microsoft">MS07-033</a> is the cumulative patch for all versions of Internet Explorer and is critical on all desktop OS&#8217;s that run it. Since this is a cumulative update it carries forward any baggage of earlier issues (like changes in ActiveX control handling). As usual, the most serious vulnerability impact is remote code execution. Six new vulnerabilities are identified in the bulletin some of which allow remote code execution.</p>
<p><a href="http://www.microsoft.com/technet/security/bulletin/ms07-034.mspx" title="Jump to the MS07-034 bulletin at Microsoft">MS07-034</a> is for Windows Mail on Vista (including Vista x64). It is rated &#8220;important&#8221; for Outlook Express 6 on all versions of Windows XP. There are five different vulnerabilities identified. On XP they may disclose information, on Vista they allow remote code execution.</p>
<p><a href="http://www.microsoft.com/technet/security/Bulletin/ms07-035.mspx" title="Jump to the MS07-035 bulletin at Microsoft">MS07-035</a> is for all desktop OS&#8217;s except Vista. It&#8217;s not needed on Vista. This allows remote code execution.</p>
<p>The patches are released through Windows Update and are available for individual download.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/07/11/microsoft-patch-tuesday-for-july-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for July 2007</a></li><li><a href="http://www.spamchronicles.com/2007/05/08/may-2007-patch-tuesday/" rel="bookmark" class="crp_title">May 2007 Patch Tuesday</a></li><li><a href="http://www.spamchronicles.com/2007/04/03/microsoft-releases-patch-for-animated-cursor-vulnerability/" rel="bookmark" class="crp_title">Microsoft Releases Patch for Animated Cursor Vulnerability</a></li><li><a href="http://www.spamchronicles.com/2007/08/14/microsoft-patch-tuesday-for-august-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for August 2007</a></li><li><a href="http://www.spamchronicles.com/2007/06/10/yahoo-messenger-critical-security-update/" rel="bookmark" class="crp_title">Yahoo Messenger Critical Security Update</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/06/12/microsoft-patch-tuesday-for-june-2007/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Update 2007-05 for Mac OS X</title>
		<link>http://www.spamchronicles.com/2007/05/25/security-update-2007-05-for-mac-os-x/</link>
		<comments>http://www.spamchronicles.com/2007/05/25/security-update-2007-05-for-mac-os-x/#comments</comments>
		<pubDate>Sat, 26 May 2007 00:45:11 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[os-security-patch]]></category>
		<category><![CDATA[osx]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/security-update-2007-05-for-mac-os-x/</guid>
		<description><![CDATA[Apple has released Security Update 2007-05 which keeps it in the one-a-month category for the year. According to the Apple notification it contains updates to the following components: bind CarbonCore CoreGraphics crontabs fetchmail file iChat mDNSResponder PPP ruby screen texinfo VPN The update is for both Intel and PPC macs. Related Posts:Quicktime Security UpdateOSX Security [...]]]></description>
			<content:encoded><![CDATA[<p>Apple has released <strong>Security Update 2007-05</strong> which keeps it in the one-a-month category for the year.</p>
<p>According to the <a title="Jump to the Apple support article on the update." href="http://docs.info.apple.com/article.html?artnum=305530">Apple notification</a> it contains updates to the following components:</p>
<ul>
<li>bind</li>
<li>CarbonCore</li>
<li>CoreGraphics</li>
<li>crontabs</li>
<li>fetchmail</li>
<li>file</li>
<li>iChat</li>
<li>mDNSResponder</li>
<li>PPP</li>
<li>ruby</li>
<li>screen</li>
<li>texinfo</li>
<li>VPN</li>
</ul>
<p>The update is for both Intel and PPC macs.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/05/30/quicktime-security-update1/" rel="bookmark" class="crp_title">Quicktime Security Update</a></li><li><a href="http://www.spamchronicles.com/2007/07/31/osx-security-update-2007-007/" rel="bookmark" class="crp_title">OSX Security Update 2007-007</a></li><li><a href="http://www.spamchronicles.com/2007/06/21/apple-releases-10410-for-os-x/" rel="bookmark" class="crp_title">Apple Releases 10.4.10 for OS X</a></li><li><a href="http://www.spamchronicles.com/2007/06/23/security-update-2007-006-for-apple-os-x/" rel="bookmark" class="crp_title">Security Update 2007-006 for Apple OS X</a></li><li><a href="http://www.spamchronicles.com/2007/07/11/apple-adds-to-patch-tuesday/" rel="bookmark" class="crp_title">Apple Adds to Patch Tuesday</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/05/25/security-update-2007-05-for-mac-os-x/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>May 2007 Patch Tuesday</title>
		<link>http://www.spamchronicles.com/2007/05/08/may-2007-patch-tuesday/</link>
		<comments>http://www.spamchronicles.com/2007/05/08/may-2007-patch-tuesday/#comments</comments>
		<pubDate>Wed, 09 May 2007 01:34:18 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[ie-security-patch]]></category>
		<category><![CDATA[ms-office-security-patch]]></category>
		<category><![CDATA[os-security-patch]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/may-2007-patch-tuesday/</guid>
		<description><![CDATA[Microsoft released five critical security bulletins for desktop software today. In line with a growing trend, 3 of the 5 were for application software and not operating systems. Most of the vulnerabilities were also intended to be exploited through a website. Mac users also take notice since Office 2004 for the Mac is also vulnerable [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft released five critical security bulletins for desktop software today. In line with a growing trend, 3 of the 5 were for application software and not operating systems. Most of the vulnerabilities were also intended to be exploited through a website. <strong>Mac</strong> users also take notice since <strong>Office 2004 for the Mac </strong>is also vulnerable and needs patching.</p>
<p><a title="Jump to the Microsoft Bulletin for MS07-023" href="http://www.microsoft.com/technet/security/bulletin/ms07-023.mspx">MS07-023</a> is for Office, specifically Microsoft Excel. All versions from 2000-2007 are affected as-is the Excel viewers and compatibility packs. Office 2004 for Mac is also vulnerable and needs updating.</p>
<p><a title="Jump to the Microsoft bulletin for MS07-024" href="http://www.microsoft.com/technet/security/bulletin/ms07-024.mspx">MS07-024</a> is also for Office, this time it&#8217;s for Word. The patch is NOT needed for the latest version, Word 2007. But it&#8217;s needed for all versions from 2000-2003 and Office 2004 for Mac. The Word viewer also needs updating, Microsoft Works 2004, 2005 and 2006 are also vulnerable and needs updating.</p>
<p><a href="http://www.microsoft.com/technet/security/bulletin/ms07-025.mspx">MS07-025</a> is another Office patch. and affects every version from 2000-2007 along with all the viewers and compatibility packs. Office 2004 for Mac is also affected and needs updating.</p>
<p><a title="Jump to the Microsoft bulletin for MS07-027" href="http://www.microsoft.com/technet/security/bulletin/ms07-027.mspx">MS07-027</a> is the cumulative update for Internet Explorer. All supported versions of Internet Explorer on all supported operating systems are affected and needs to be updated.</p>
<p><a title="Jump to the Microsoft bulletin for MS07-028" href="http://www.microsoft.com/technet/security/bulletin/ms07-028.mspx">MS07-028</a> is a patch for CAPCOM which is the &#8220;Cryptographic API Component Object Model&#8221;. CAPCOM is an Active X control that allows scriptors (VBS, ASP, etc&#8230;) he ability to encrypt data. It&#8217;s part of the Biztalk servers but may be installed by other software. My Windows XP SP2 machine needed the update, other systems may not need it.</p>
<p>You can get the updates through Windows Update. The links above will also bring you to the bulletins at the Microsoft site. I applied the updates to Windows XP SP2 and Vista without a problem. I don&#8217;t run any versions of Office at home so I can&#8217;t try those updates. There aren&#8217;t any compatibility warnings in the bulletins. </p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/07/11/microsoft-patch-tuesday-for-july-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for July 2007</a></li><li><a href="http://www.spamchronicles.com/2007/06/12/microsoft-patch-tuesday-for-june-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for June 2007</a></li><li><a href="http://www.spamchronicles.com/2007/04/03/microsoft-releases-patch-for-animated-cursor-vulnerability/" rel="bookmark" class="crp_title">Microsoft Releases Patch for Animated Cursor Vulnerability</a></li><li><a href="http://www.spamchronicles.com/2007/08/14/microsoft-patch-tuesday-for-august-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for August 2007</a></li><li><a href="http://www.spamchronicles.com/2007/03/31/windows-pc-have-cursor-hole/" rel="bookmark" class="crp_title">Windows PC Have Cursor Hole</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/05/08/may-2007-patch-tuesday/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Releases Patch for Animated Cursor Vulnerability</title>
		<link>http://www.spamchronicles.com/2007/04/03/microsoft-releases-patch-for-animated-cursor-vulnerability/</link>
		<comments>http://www.spamchronicles.com/2007/04/03/microsoft-releases-patch-for-animated-cursor-vulnerability/#comments</comments>
		<pubDate>Tue, 03 Apr 2007 20:00:04 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[os-security-patch]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/microsoft-releases-patch-for-animated-cursor-vulnerability/</guid>
		<description><![CDATA[Microsoft has released a patch for the animated cursor vulnerability. The bulletin is MS07-017. They also address six other vulnerabilities in the Graphics Rendering Engine (GDI), although none are rated critical. They make a note of an known issue with the Realtek HD Audio Control Panel (Rthdcpl.exe) on Windows XP SP2 which is documented here. [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft has released a patch for the <a href="http://www.spamchronicles.com/windows/windows-pc-have-cursor-hole/" title="Jump to my original posting on the vulnerability">animated cursor vulnerability</a>. The bulletin is <a href="http://www.microsoft.com/technet/security/Bulletin/MS07-017.mspx" title="Jump to the bulletin on the Microsoft website">MS07-017</a>.</p>
<p>They also address six other vulnerabilities in the Graphics Rendering Engine (GDI), although none are rated critical.</p>
<p>They make a note of an known issue with the <strong>Realtek HD Audio Control Panel</strong> (Rthdcpl.exe) on Windows XP SP2 which is documented <a href="http://support.microsoft.com/kb/935448/" title="Jump to the Microsoft document on this issue.">here</a>.</p>
<p>The Microsoft bulletin for &#8220;home users&#8221; is <a href="http://www.microsoft.com/athome/security/update/bulletins/200704oob.mspx" title="Jump to the Microsoft bulletin for home users">here</a>.</p>
<p>The Microsoft bulletin fot &#8220;technical users&#8221; is <a href="http://www.microsoft.com/technet/security/bulletin/ms07-017.mspx" title="Jump to the Microsoft bulltin for technical users.">here</a>.</p>
<p>As usual, the patch will be in Windows update.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/06/12/microsoft-patch-tuesday-for-june-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for June 2007</a></li><li><a href="http://www.spamchronicles.com/2007/05/08/may-2007-patch-tuesday/" rel="bookmark" class="crp_title">May 2007 Patch Tuesday</a></li><li><a href="http://www.spamchronicles.com/2007/07/11/microsoft-patch-tuesday-for-july-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for July 2007</a></li><li><a href="http://www.spamchronicles.com/2007/08/14/microsoft-patch-tuesday-for-august-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for August 2007</a></li><li><a href="http://www.spamchronicles.com/2007/03/31/windows-pc-have-cursor-hole/" rel="bookmark" class="crp_title">Windows PC Have Cursor Hole</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/04/03/microsoft-releases-patch-for-animated-cursor-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
