Forum Moderators: phranque

Message Too Old, No Replies

M$ Security Alert

A SERIOUS threat to ALL Windoze versions!

         

DaveAtIFG

4:22 pm on Dec 14, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



M$ announces
Flaw in Microsoft VM Could Enable System Compromise
Who should read this bulletin: Customers using Microsoft® Windows®.

From the End User Bulletin [microsoft.com]:

Why We Are Issuing This Update

A set of security issues has been identified in the Microsoft® Virtual Machine (Microsoft VM), which enables Java programs to run on Microsoft Windows®. The most serious of these issues could enable a Web site to compromise your system and take actions such as changing data, loading and running programs, and reformatting the hard disk. You can help protect your computer by installing this update.

Additional, but less dramatic security flaws were also announced, more info is here [extremetech.com].
It states in part:

Some of these flaws have been known, at least to some extent, to hackers for several months.

msr986

7:13 pm on Dec 14, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Thanks for the heads up!

The patch for this security hole is already two days old, in the land of MS, that makes this OLD news ;)

Macguru

7:20 pm on Dec 14, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Just installed it.

I just installed another one for IE 5.5 along with the VW thing. M$ recommended me to install both IE 5.5 and IE 6 service packs at the same time. It keeps bugging me every day for critcal updates for IE 6 wich I dont have installed. Can anyone tell me how to kill IE 6 service pack notifications?

DaveAtIFG

7:26 pm on Dec 14, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Under W2K, an "Automatic Updates" icon was added to the Control Panel with SP3 so users can manage if and when update notices are presented.

Macguru

7:30 pm on Dec 14, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Thanks!

But I am on win 98 (french). I see nothing in the control panels. Whathever I set the "Planned tasks" (hope this makes sense) to monthly checks it reverts to daily checks.

DaveAtIFG

8:14 pm on Dec 14, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



The Opera browser is incompatible with the M$ VM and installs the Sun Microsystems VM during Opera installation. This avoids the M$ security vulnerability and the Sun version is compatible with all browsers. It has no known security problems.

I use Opera (and the Sun VM) daily. But I still felt it was prudent to update the M$ VM. IF my system somehow reverts to the M$ VM, perhaps by removing Opera or an M$ update, I don't want this "security hole" opened. It's a bad one!

If you want to switch to the Sun VM, it can be downloaded at [java.sun.com...]

martinibuster

11:18 pm on Dec 14, 2002 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



Ugg!

I'm afraid of updates. I updated one of my computers last year and was horrified when Windows could no longer load up because it couldn't find the hard drive. That "update" crippled my machine.

Ever since then I've been leery of Windows updates.

MarkHutch

1:31 am on Dec 15, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



After updating my Windows machine at home with the latest MS security patch, I noticed that the Java on one of our sites quit working all together. Just wanted to let everyone know that they should run this security update via "Windows Update" to see if Java is still working on your website.

P.S. I know a bunch of folks here don't use IE, but many of your customers do and if they can't see your Java, they are not going to blame MS.

martinibuster

3:02 am on Dec 15, 2002 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



Java or JavaScript?

Which version of Windows did you update?

keyplyr

9:43 am on Dec 15, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month




Can anyone tell me how to kill IE 6 service pack notifications? - Macguru

Don't know on a MAC, but in Windows go to: Start > Settings > Control Panel > Automatic Updates and check "Turn off automatic Updating."

Macguru

10:21 am on Dec 15, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Can you scroll up to message 5 keyplyr? ;) Thanks anyways.

keyplyr

7:58 pm on Dec 15, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Macguru - the suggestion WAS for Windows 98. I wouldn't know why a french version would be any different.

john316

8:14 pm on Dec 15, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I wonder if the Sun version has the same security issue? Maybe the upgrade should be to real java.

MarkHutch

5:40 am on Dec 16, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



**Update**

I finally got Java working again on my Windows 98 se computer at home. I had mentioned earlier that all Java had stopped working after I installed the Windows VM update. I installed that same update on a laptop computer with the same operating system and the Java on that computer didn't stop working. Who knows why. What I did on the computer where all Java stopped is to download the Windows VM Java package from the folks at Sun and installed it into my computer. Java is working again. I just hope that it is secure.