Robert's Blog

Gelezen op een nieuwssite: "Condoms Good For Business Rise"!

Hoe bedoelt u "double entendre"?

Een nieuwe generatie Linux adepten komt eraan, wordt dat HET probleem voor Microsoft in de toekomst?

Over Services gesproken. Als ik Dell moet vergelijken met bij voorbeeld HP, dan zitten daar minimaal 3 klassen verschil tussen. Ook bij Dell worden wel eens foutjes gemaakt, het blijft immers mensenwerk, maar ze doen heel veel om fouten te corrigeren, ze zijn coulant, en ze denken ZELF na, het grootste winstpunt. Een voorbeeld voor vele andere bedrijven.

Dell plant boom voor iedere klant, die carbon neutraal wil werken.

Home arrow Nieuws Blog arrow Microsoft's ANI patch levert problemen op met REALTEK

Editorial

Nu er een golf nieuwe software over de mensheid uit gestort gaat worden, niet alleen door Microsoft, maar ook door de Open Source Software groep, Mozilla en anderen, zullen wij extra aandacht besteden aan deze nieuwe producten. Wij zullen met name focussen op ernstige gebreken en nieuwe -het leven aanzienlijk veraangenamende- features en navenante voordelen, alwaar wij onze bezoekers regelmatig kond van zullen doen.

N.B.: Wij vragen onze bezoekers zich te registreren via het login menu in de rechterkolom.

Een groeiend aantal artikelen zullen wij alleen specifiek ter beschikking stellen aan klanten van theHelpdesk.nl en aan onze geregistreerde bezoekers binnen de Registered User Section en het afgeschermde gedeelte van HackersWorld (full disclosure exploits). (te bereiken na registratie en/of login)

Microsoft's ANI patch levert problemen op met REALTEK PDF Print E-mail
Written by Administrator   
Thursday, 05 April 2007
Microsoft's ANI patch levert problemen op met REALTEK. 2 artikelen

Windows cursor patch creates difficulties

 

Joris Evers CNET News.com

Published: 05 Apr 2007 09:45 BST

Installing Microsoft's Tuesday patch for a "critical" Windows vulnerability is causing trouble for some users.

Microsoft broke with its monthly patch cycle on Tuesday to repair a bug in the way Windows handles animated cursors. Cybercrooks had been using the hole since last week to attack Windows PCs. But the fix is not compatible with software that runs audio and networking components from Realtek Semiconductor, some Windows users have found.

"Apparently the update is not compatible with Realtek," reader Dave House wrote in an email to ZDNet UK's sister site, CNET News.com. "We lost all Ethernet and audio functions. Removing the update and doing system restores brought the systems back."

Microsoft is aware of problems with Realtek's audio software. In fact, it knew about them before releasing the fix and published a support article with the security bulletin. An additional update is available from Microsoft to remedy the problem, according to the company's website. Microsoft is not aware of networking issues, a representative said.

The audio problem occurs on Windows XP PCs that have the Realtek HD Audio Control Panel installed, Microsoft said. The application may not start after the patch is applied and Windows may display an error message, the company said.

Microsoft consciously released the cursor flaw patch despite the compatibility problem, Mike Reavey, a Microsoft Security Response Center staffer, wrote on a corporate blog. The company tested the fix throughout February and March and eliminated many problems, he wrote.

"At one point our testing had uncovered over 80 potential issues with the update that were investigated and resolved... at the time of release, only one minor quality issue was known," Reavey wrote.

The cursor vulnerability is one of seven flaws addressed by Microsoft's Tuesday patch - three of them also affect Vista. Cybercrooks moved quickly to exploit the cursor hole. Security firm Websense has spotted hundreds of websites that try to use the bug to compromise PCs, as well as an email spam campaign with links to the malicious sites.

Microsoft plans to issue additional fixes next week on its regular monthly patch day, the company said.

 

AANVULLING:

 

Just one day after releasing an emergency patch for a vulnerability in its operating system, Microsoft has documented one problem with it and is asking users to report any other issues they might encounter.

 

Microsoft late Tuesday issued a Knowledge Base (KB) article and a hotfix addressing a problem that may cause the Realtek HD Audio Control Panel not to start after installing the MS07-017 patch, released Tuesday to fix a bug in the way Windows processes .ani Animated Cursor files.

The control panel, developed by Realtek Semiconductor, is used to configure the onboard Realtek HD sound on the system’s motherboard.

Users are rushing to install the MS07-017 patch based on known exploits already occurring and the fact it could allow an attacker to take complete control of a system remotely. The patch’s severity rating was critical.

The Realtek issue affects users who have installed the patch on Windows XP Service Pack 2 – Professional, Home, Tablet and Media Center Editions.

In addition to the Realtek issue, the Internet Storm Center at the SANS Institute also is reporting that “other possible issues have been reported and are being investigated.”

Microsoft did not confirm the existence of “other possible issues,” but a spokesman said, “I can tell you that Microsoft encourages customers who believe they are affected can contact Product Support Services.” There is no charge for contacting Product Support Services in North America at 1866-PCSAFETY or here for international customers.

The spokesman added, “The company was aware of the Realtek HD Audio Control Panel issue during testing of MS07-017,” and recommended that users affected by the problem download the hotfix,

“Currently, the impact of this known issue appears limited in terms of the number of customers impacted,” the spokesman said in an e-mail. Microsoft is continuing to monitor the situation.

The Realtek problem also involves security update MS07-008, which was released in February to address a vulnerability in the Windows HTML Help ActiveX control that could allow remote code execution.

 

Microsoft said in the KB article that the Realtek problem occurs after installing the two updates. A user with the Realtek HD Audio Control Panel installed would see an alert telling them of an “illegal system DLL relocation.”

The KB article says “the Hhctrl.ocx file that is included in security update 928843 [MS07-008] and the User32.dll file that is included in security update 925902 [MS07-017] have conflicting base addresses. This problem occurs if the program loads the Hhctrl.ocx file before it loads the User32.dll file.”

Microsoft was forced to release the MS07-017 patch a week ahead of its monthly “second Tuesday” patch schedule, because exploits of the vulnerability had become too widespread. Microsoft said it was only the third such early release of a patch since January 2006. Microsoft was first notified of the animated-cursor files flaw in December 2006 by security vendor Determina.

 

Bron o.a.: NetworkWorld 

 

 

 

 

 

 

 

 

Last Updated ( Thursday, 05 April 2007 )
 
< Prev   Next >

Over deze Website

Zowel deze NIEUWS site als het bijbehorende eZine zullen voor een groot deel, qua inhoud, bestuurd kunnen worden door onze klanten en de bezoekers van onze website(-s).

Wij nodigen U dan ook uit, op dit moment nog via e-mail, This e-mail address is being protected from spam bots, you need JavaScript enabled to view it , om de voor U interessante onderwerpen aan te melden. U kunt hierbij denken aan de vaste rubrieken op beveiligingsgebied, onderzoek en technologie (zowel fundamenteel als toegepast onderzoek), waarschuwingen uit de praktijk. Daarnaast kan men denken aan, bij voorbeeld, uitleg van bepaalde zaken, zoals protocollen, technieken, methodieken, maar ook commentaren op ontwikkelingen e.d.

Als onze klanten en bezoekers zelf ook een bijdrage willen en kunnen leveren, worden zij hiertoe hartelijk uitgenodigd. Het delen van kennis, zowel vanuit een professioneel-, als een gebruikersperspectief, is de missie van deze nieuwsvoorziening.

 

Het e-Zine zal maandelijks worden toegezonden aan de klanten van theHelpdesk.nl en aan geregistreerde bezoekers van deze website. Daarnaast kunnen zij Alerts en Waarschuwingen verwachten, buiten de reguliere verzending van het e-Zine om, indien het nieuws dit nodig mocht maken.

 

News Feeds / Syndication / links.

Wij hebben als extra service aan onze bezoekers besloten de syndication e/o news feeds aanzienlijk uit te breiden. 

Ook het aantal overige news feeds en links zal in de nabije toekomst aanzienlijk worden uitgebreid. Voorts verwachten wij op grond van de binnengekomen e-mails binnenkort een aantal rubrieken toe te kunnen voegen. 

  wcg3


Login Form






Lost Password?
No account yet? Register

Related Items

 
Alien Ant Farm songs Amigos downloadable music Amr Diab mp3s Anais Mitchell mp3 music Derniere Volonte best mp3 DJ Reeplee Feat. Jessica Braun mp3 music Ghosts Of Verona mp3s Icehouse mp3 online Junior Mance song downloads Katrina Carlson mp3 downloads Klangwelt albums Marcel song downloads Max Coveri mp3 search Mia review Natasha Atlas and David Arnold dowland NON album Notis new mp3 Only Ones music download Richard Anthony new mp3 Rolf Harris best mp3 Salvador Candel mp3 Scar Symmetry music search 3 de Copas mp3 downloads Abdullah Ibrahim and Ekaya new mp3 Albert Griffiths and The Gladiators mp3 downloads Alexi Delano and Jesper Dahlback mp3s Angelo Debarre Et Ludovic Beier albums Barricada top mp3 Betelgeuse albums Donna Summer downloadable music Emily Loizeau mp3 online First And Andre dowland Gentleman And The Far East Band download mp3 Jad Fair and Daniel Johnston mp3 John Hammond new mp3 Juan Manuel music downloading Krzysztof Penderecki downloads Logic System download mp3 Marc Ford And The Neptune Blues Club mp3s Maxeen mp3 songs Mental top mp3 Mike Koglin Vs Energy Dai download mp3 Modena City Ramblers music download Musafir music downloading P.M. Dawn review Pallas downloads Pauline Oliveros get mp3 Pedrito Altamiranda mp3 Peter Punk english mp3 Quarteto Em Cy and Tamba Trio new mp3 Real Life downloads Stormwarrior download Swag downloadable music T Bone Burnett mp3 online Toumani Diabate and Roswell Rudd music Arsenik mp3 search Cesti instrumental David Benoit And Russ Freeman songs Dead Man in Reno download mp3 Defiance download songs Depth Affect top mp3 DJ List and Damodar english mp3 Garwall song downloads Gundog get mp3 Hector Romero mp3 search Hillsong United mp3 downloads Ian Boddy and Andy Pickford download Ian Lurgee music downloading Jack Kerouac review Jan Garbarek and Miroslav Vitous english mp3 Lacksley Castell mp3 online Marcos Vidal mp3 Nordreich get mp3 Puzzle music search Riblja Corba downloadable music Riley Lee and Gabriel Lee downloads Sagittarius mp3 music Seventh One dowland Shop Boyz review Steve Coleman and the Five Elements mp3 music Alvin Lucier all mp3 Blackfusion mp3 music Chiaki Ishikawa mp3 downloads Devin downloadable music Dies Ater music download Dj Scream And Dj Smallz albums Gontyna Kry best mp3 Guts Pie Earshot mp3 songs Hittman song downloads Kevin Kern mp3 songs Kim Lukas music downloading Kristina Bach mp3s Lavrenchukki downloads Martin Roth music to download Nino Buonocore new mp3 Philippa Gregory new mp3 Richard Souther download songs Robert Leiner mp3 search Venu Gopal Goswami review Yotopia pop