Unsolved

This post is more than 5 years old

1 Rookie

 • 

17 Posts

4268

March 20th, 2015 03:00

Timeline of ETA 199379: Isilon OneFS: Microsoft security update MS15-027 may cause...

Hi

The ETA 199379 was a big hit for some of our customers. So I took the time for investigating this ETA.

What I found was:

MS-KB:

https://support.microsoft.com/de-de/kb/3002657

---xxx---

Products that are affected

All supported versions of EMC Isilon OneFS. These include the following:

  • EMC Isilon OneFS 7.2.0.x
  • EMC Isilon OneFS 7.1.1.x
  • EMC Isilon OneFS 7.1.0.x
  • EMC Isilon OneFS 7.0.2.x
  • EMC Isilon OneFS 7.0.1.x
  • EMC Isilon OneFS 6.5.5.x
  • EMC Isilon OneFS 6.5.4.x
  • EMC Isilon OneFS 6.5.3.x
  • EMC Isilon OneFS 6.5.2.x
  • EMC Isilon OneFS 6.5.1.x
  • EMC Isilon OneFS 6.5.0.x

---xxx---

http://packetstormsecurity.com/files/130773/Windows-Pass-Through-Authentication-Methods-Improper-Validation.html

In the timeline

----xxx-----

2015-01-02:

        Microsoft informs that they are not going to meet the

        expectations for a fix in January because they require to fix

        the NETLOGON API, and during its application compatibility

        testing they identified a major service provider that is

        affected by their fix.

---xxx---

This looks like EMC was informed about this problem very early end send out the ETA far too late.

Maybe EMC could tell something about the timeline and theirs policy to inform customers.

1 Rookie

 • 

17 Posts

March 20th, 2015 14:00

Hi Mike

It was more like a question.

I posted my two sources. Packetstorm postet about the delay of the fix because microsoft identified a big vendor wich fails with that fix.

And the Microsoft release notes of that patch where only emc isilon is affected.

So EMC could be that big vendor... I think

Correct me, if I'm on the wrong lane

Christian

--

Auf einem Mobildevice erstellt

11 Legend

 • 

20.4K Posts

 • 

87.4K Points

March 20th, 2015 20:00

are you going to release a  patch for 7.1.0.x family ?

2 Intern

 • 

300 Posts

March 24th, 2015 05:00

Furthermore they have not refreshed the ETA

https://emc--c.na5.visual.force.com/apex/KB_ETA?id=kA3700000000260

1 Message

March 24th, 2015 05:00

Hello Mike,

Is this fix available now? you mentioned in your post that something might be out by the 20th of March, today is the 24th.

We are on Vs 7.1.0.1

6 Operator

 • 

1.2K Posts

March 24th, 2015 05:00

I have received the following updates notification today via e-mail

and  the linked patches address the Microsoft  issue  in question.

Ironically, the linked Current Patches document, while also

updated yesterday, does NOT list those patches....   

-- Peter

EMC

Your EMC Product Updates

Updates are now available for the following product(s):

Notification Frequency: DAILY

Product(s)Content TypeDateTitle
Isilon OneFS, IsilonDownloads2015-03-23

Isilon OneFS Patch-145046

Isilon OneFS, IsilonDownloads2015-03-23

Isilon OneFS Patch-139809

Isilon OneFS, IsilonDownloads2015-03-23

Isilon OneFS Patch-145051

Isilon OneFS, IsilonProduct Documentation2015-03-23

Current Isilon OneFS Patches

Isilon OneFS, IsilonProduct Documentation2015-03-23

Managing SMB Shares Using Isilon OneFS

Isilon OneFS, IsilonProduct Documentation2015-03-23

Business Data Lake Protection 1.0 Integration Guide

Isilon OneFS, IsilonDownloads2015-03-23

Isilon OneFS Patch-145047

Isilon OneFS, IsilonDownloads2015-03-23

Isilon OneFS Patch-145050

Isilon OneFS, IsilonDownloads2015-03-23

Isilon OneFS Patch-145049


Service Life


You are receiving this notification because you have subscribed to product updates through the EMC Support website.

Sincerely,
EMC Customer Service

6 Operator

 • 

1.2K Posts

March 24th, 2015 06:00

Hold on a second --- at least the ETA's publication date has been updated to Mar 23.

So it's consistent with the Current Patches doc now.

scnr

-- Peter

11 Legend

 • 

20.4K Posts

 • 

87.4K Points

March 24th, 2015 07:00

sorry Scott, i posted in the wrong thread. I just updated this discussion Re: ESA-2015-015 Question

60 Posts

March 24th, 2015 07:00

Dynamox,

Patch 145049 is for OneFS 7.1.0.6 (the listing on the site references 7.0.1.6, but we are working to have the information corrected to reflect that it is for OneFS 7.1.0.6

https://download.emc.com/downloads/DL58529_Isilon_OneFS_Patch-145049.tgz


1 Rookie

 • 

17 Posts

March 24th, 2015 13:00

Hi

my question (to EMC) is still not answered.

Is my interpretation of the timeline right or wrong?

Was EMC informed in Feb. about this problem or not?

I interpret the packetstorn notice from 2015-01-02 in a way that EMC was informed early.

The second thing which points in this direction is the very early warning published by Microsoft.

Chris

179 Posts

March 24th, 2015 13:00

Hi Christian,

Are you looking for an answer from EMC  as a whole or Isilon specifically? mikewong  has answered on Isilon's behalf above with a date. If you are looking for an overall EMC statement, I would have to find the right person for that. Can you please confirm?

Thank you

Niki

1 Rookie

 • 

17 Posts

March 24th, 2015 13:00

Hi

Mike Wong didn't answer anything.

ISILON is a part of EMC, so for me it's not a difference if the one who answers has EMC or ISILON Division in his title.

I exspect a answer.

For now I value mikes answer as "yes we know early but we don't tell"

Chris

4 Apprentice

 • 

638 Posts

 • 

3 Points

March 24th, 2015 14:00

4 Apprentice

 • 

638 Posts

 • 

3 Points

March 25th, 2015 10:00

per Mike Wong reply above:

I'm not sure where you received your information about EMC receiving information about this patch early, but from my information we were made aware of the issue on 3/12/15, two days after the patch was released from Microsoft.

2 Intern

 • 

300 Posts

April 16th, 2015 04:00


I'm missing a Patch for this issue for release  7.1.1.3... It's not fixed and it's no patch available... (just saying, SR is already open...)

That's also a point you could work on: don't release a release which has such a massive technical / security hole and no patch - especially when you do not fix the issue for all codes and force your customers to schedule updates to newer code.

Just my 2 Cents

--sluetze

12 Posts

April 16th, 2015 05:00

There is a patch for 7.1.1.3, on demand from the support team.

If you can wait another week. It's my understanding we will be releasing a new set of patches ( target code only) which will have a better mechanism to handle the ms15-027 issue.

The same approach will be built in :

- 7.2.0.2 ( may 6 ETA)

- 7.1.1.5 ( late June ETA )

- 7.1.1.4 ( late April )

Luc Simard - 415-793-0989

Senior Technical Account Manager.

Isilon Systems - Simple is Smart™

Messages may contain confidential information.

Sent from my iPhone

0 events found

No Events found!

Top