You are here: silicon.com > Software > Security Strategy

Security Strategy

Microsoft: Another patch comes unstuck

Get your hotfix here...

Tags: patch, microsoft

By Dawn Kawamoto

Published: 21 August 2006 08:30 BST

Microsoft on Thursday issued a "hotfix" for a fault in a security patch designed to correct a flaw already being targeted by worms.

The company is making the hotfix, or repair code targeted to a specific issue, available upon request, according to a posting on its website. The fix addresses the problem of programs failing if they request one gigabyte or more of information on a patched system.

Computers running x64-based versions of Microsoft Windows Server 2003, along with Service Pack 1 and Windows XP Professional x64 Edition, are affected, if the MS06-040 update has been installed. Only 32-bit programs can encounter problems, Microsoft said.

The software behemoth said Microsoft Business Solutions Navision 3.7, for example, may fail under such conditions.

MS06-040 was part of a dozen security patches Microsoft released earlier this month as part of its monthly patch cycle. The patch, which Microsoft had rated "critical", was designed to prevent attackers from exploiting a vulnerability that could allow a remote code execution.

Users were urged to install MS06-040 as soon as possible, given that worms were already trying to take advantage of the vulnerability, according to a posting on the Sans Internet Storm Center.

MS06-040 was not the only problematic patch in the August update. MS06-042 also created problems for users who installed the critical patch. In that case, Microsoft's Internet Explorer browser could crash when various websites were viewed. The company has said it plans to rerelease the MS06-042 bulletin and patch on 22 August.

Dawn Kawamoto writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
Accenture Siebel Consultants-00037335

Loyalty, Business Intelligence and Analytics, Customer Data Integration, Self Service, Sales and Call Centre Functional analysis & design experience ...

Junior .NET Developer / QA - London - .NET / QA - Junior .NET Developer

Questionmark internal style guides - Ensures that all coding meet Questionmark internal quality and coding guidelines - Assists others in team within ...

After Point Of Sales (APOS) Specialist

Knowledge & Skills - Fluent French - Viewed as a trusted expert to the customer and uses knowledge of Dells services to recommend appropriate APOS ...

CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.





Quick Sitemap Links: