UNSOLVED

joangolfing

updated

20 years ago

J

joangolfing

137 Posts

0

20458

October 8th, 2006 18:00

Vulnerability MS06-055

I posted a message a few days ago about a Vulnerability issue and today had another alert from Panda Titanium
AntiVirus about Vulnerability MS06-055 directing me to the Microsoft Update center.
I ran that and nothing showed up as needing updating.

Is this related to the Skype issues?
  • ky331

    5 Journeyman

    •

    15627 Posts

    •

    45058 Points

    700

    0

    Posted October 8th, 2006 18:00

    Microsoft Security Bulletin MS06-055
    .
    Vulnerability in Vector Markup Language Could Allow Remote Code Execution (925486)

    http://www.microsoft.com/technet/security/bulletin/ms06-055.mspx

  • Bugbatter

    4 Apprentice

    •

    20487 Posts

    700

    0

    Posted October 8th, 2006 19:00

    No fix for this (Skype) yet:

    "Oxygen3 24h-365d, by Panda Software (http://www.pandasoftware.com)

    Madrid, October 4, 2006 - A vulnerability has been reported in Skype,
    the popular software for making voice calls via the Internet, that
    could
    allow a remote user to run arbitrary code on the affected system.

    The problem lies in handling of data received by the program, so that
    if
    a remote user sends specially-crafted data, they could trigger a format
    string error to run arbitrary code on the system.

    Panda Software advices caution when using Skype, as, even though the
    problem has been reported, no fix has yet been provided by the Skype
    vendor."

    The original advisory is available at:
    /www.securitytracker.com/alerts/2006/Jan/1015447.html>
  • joangolfing

    137 Posts

    700

    0

    Posted October 8th, 2006 21:00

    I went to the site mentioned and downloaded KB925486x86-ENU.exe
    It wasn't able to install on my system. Not compatible with my version.

    The site wasn't very clear about what to do.
    Is it a problem I can ignore or do I need to fix it.
  • ky331

    5 Journeyman

    •

    15627 Posts

    •

    45058 Points

    700

    0

    Posted October 8th, 2006 21:00

    joangolfing
     
    I gave you the site for "Vulnerability MS06-055", so that you (and anyone else reading this thread) could see precisely just what this technical numbering was referring to. 
     
    In turn, that site offered several links for different versions of the Windows operating system... for example, there was a link for win xp sp1, and a separate link for win xp sp2.   If you downloaded from an inappropriate link, then yes, it would not be compatible with your version.
     
    The best way to test to see if you are impacted by this vulnerability... and to fix it if you are... is simply to run Windows Updates.   If the Update Center says you didn't need any updates, then you should be okay.    [You might also want to check your update HISTORY there, to see if this particular update has already been applied to your system.]

     
     
  • ky331

    5 Journeyman

    •

    15627 Posts

    •

    45058 Points

    701

    0

    Posted October 8th, 2006 22:00

    when you checked for  KB925486 in your control panel, add/remove programs, did you place a CHECK MARK in the box on top that says show updates ?
     
    that should reveal a whole section of Windows XP - Software Updates, one of which may be Security Update for Windows XP  (KB925486)

    Message Edited by ky331 on 10-08-2006 07:22 PM

  • joangolfing

    137 Posts

    700

    0

    Posted October 8th, 2006 22:00

    Thanks for the info.
    I checked my updates in Control Panel/AddRemove Prog. and couldn't find KB925486 installed on my Dell Dimension 4300.
    I did download the correct version of KB925486 XP SP2 but it didn't install--incompatible
    I had no high priority updates needed when I checked the site you included.
    I sent an email to Panda Titanium AntiVirus tech support to find out more.
    I'll keep working on the issue.
  • joangolfing

    137 Posts

    701

    0

    Posted October 8th, 2006 23:00

    I checked my updates again and didn't find KB925486.I downloaded the exe file again and got the same
    incompatibility issue.

    Then I checked my Internet Explorer and found I had updated it to Version 7--7.0.5346.5 Beta 2.
    That is probably the issue now.

    Should I revert back to an earlier IE verion?
    And if so, how should I go about it. Delete the current version and get another version--where to find it?
  • ky331

    5 Journeyman

    •

    15627 Posts

    •

    45058 Points

    701

    0

    Posted October 8th, 2006 23:00

    there are several points for consideration here:
     
     
    1)  I am still using IE 6... therefore I am not familiar with the workings of IE 7 --- which, as you've noticed, is a BETA (testing) product.   As such, I am not in a position to advise you about it... perhaps someone else can.    My suggestion is that, unless you know for sure that your problem is related to the IE 7, it's probably best not to try tinkering with it, or reverting back to the older version.
     
    2)  You're also asking about SKYPE... and I have no idea whether or not your SKYPE issues are related to IE 7 beta... and/or if they are related to the MS06-055 issue.   I have to reiterate that my point in replying to your thread was just to bring to light what the "cryptic" message "MS06-055" was referring to.
     
    Having taken this about as far as I can, I would hope you'd wait to see if anyone else is in a position to offer you any more help.
     
     
  • joangolfing

    137 Posts

    701

    0

    Posted October 9th, 2006 21:00

    I thought about having the Beta version of IE and decided to try installing the very next version--Internet Explorer 7 Release Candidate I for WinXP SP2--I think this will solve my problem. It seems very nice and comes with lots of extra protections and spyware safeguards. It automatically went out and got an update (KB918439). So now I just have to watch my Panda Titanium Antivirus messages and see if that vulnerability shows up.

    I think I have found the solution. Thanks for listening to my computer problem.
  • ky331

    5 Journeyman

    •

    15627 Posts

    •

    45058 Points

    522

    0

    Posted October 9th, 2006 22:00

    Listening was easy enough.   I don't know that I offered any particularly useful advice here... the link I gave was indeed rather formal.
     
    But as long as you're satisfied...