Warning: mysql_result(): supplied argument is not a valid MySQL result resource in /var/www/hosts/cases/inc/refcount_alerts.php on line 23
Windows 98 & Me OpSys - Problems with Patch -- Confirmed
Just the facts
     
Title   Windows 98 & Me OpSys - Problems with Patch -- Confirmed
Description   Could allow remote code execution
CyTRAP Labs ID   CT110007
Original release date   2005-03-29
Systems affected  
Version number   1.0
ISSN   1603-9858
Verify threat   http://casescontact.org/alerts/110007
Risk assessment   Moderate
Impact/Severity   Medium
 

Why not get new tips and alerts by e-mail directly to your in-box? It's much more convenient:

Your email: or press here.

 

What is the problem?
     
Admin   Problem for users of OSes Windows 98,Windows 98 SE, and Windows Me who installed a January 2005 patch from Microsoft.
     
How does it affect me?  

  • A) Threat Vulnerability in cursor and icon format handling -- Microsoft reported not being aware of customers having been exploited by way of the vulnerability fixed in MS05-002 on Windows 98, Windows 98 SE and Windows ME.

  • B) Vulnerability in cursor and icon format handling that could allow remote code execution - affects Internet Explorer

  • C) Impact could allow remote code execution -- HOWEVER, applying the patch can result in the machine to hang or dramatically slow down therafter.

  •      
    Systems affected  
  • Windows 98
  • Windows 98 SE, and
  • Windows Me
  •      
    Not affected systems   Windows XP
     

    Minimize your exposure to this threat - follow the steps outlined below
         
    Much Gain - Little Pain - Do this  

    Roll back the patch

    Use another Web browser for now to mimize vulnerability after rolling back the patch to assure smooth operating of your system running in Windows 98.

     
         
    How do I fix it   Wait for an unpdate from Microsoft and follow the above suggestions  
         
    Other Actions   REMEMBER - 98 OSes are no longer supported by Microsoft, except for serious security patches that Microsoft still provides for free.
         
    Additional risk minimization   Use another Web browser until Microsoft releases new update that fixes the problem for these OSes.   
     

    If you need more information, please read on. Otherwise follow the steps outlined above.
         
    Source   dBforums-MS05-002 on 9x and ME
    Source URL   http://www.dbforums.com/t1142599.html
    Source date   2005-03-26
    Other source URL   http://www.microsoft.com/technet/security/bulletin/ms05-002.mspx
    Other source date   2005-03-08
    Microsoft   MS05-002 - KB891711
     

    CYTRAP resources - check it out - because it will help you better protect yourself
         

    Administrative
         
    Author   Urs E. Gattiker - CyTRAP Labs
         
    Revisions  
  • 1.0 - 2005-3-30 - First Version
  • Contact details   Web: http://CASEScontact.org
    E-mail: support01 at CASEScontact.org

    Tel: +41(0)76-200-7778 or + 44(0)70-9237-6036
    Fax: +44(0)70-9237-6036, dial 3 send fax
     

    --END of ADVISORY - Important Info Below--
     
    We recommend that you VERIFY ALL ADVISORIES you receive IMMEDIATELY, by clicking on the link provided at the top of this alert.

    NO WARRANTY
    Any material furnished by CASEScontact.org is furnished on an 'as is' basis. CASEScontact.org, writers & sponsors make no warranties of any kind, either expressed or implied as to any matter including, but not limited to, warranty of fitness for a particular purpose or merchantability, exclusivity or results obtained from use of the material.

    Ride the rollercoaster successfully by subscribing to our alerts, tips, tools and skills training receiving them either via:

    1) e-mail
    2) RSS feeds, or else, just get a
    3) free skills tune-up


    NO WARRANTY
    Any material furnished by CASEScontact.org is furnished on an 'as is' basis. CASEScontact.org, writers & sponsors make no warranties of any kind, either expressed or implied as to any matter including, but not limited to, warranty of fitness for a particular purpose or merchantability, exclusivity or results obtained from use of the material.

    CASES writers & sponsors do not make any warranty of any kind with respect to freedom from patent, trademark, or copyright infringement.
    Full DISCLAIMER notice at: http://www.casescontact.org/terms.php

    UNSUBSCRIBE
    If you no longer wish to receive this THREAT ALERT, please Unsubscribe at:
    http://www.casescontact.org/unsubscribe.php

    QUESTIONS, comments, ideas? Cheer us up at:Alerts-Comments at CASEScontact.org

    CASEScontact.org -- Threat Alerts and Security Notices --clear and precise, no compromise -
    --currently hosted by Flashcable

    -- END of THREAT ALERT --
    Copyright (c) 2007 by CyTRAP labs - Urs E. Gattiker. All rights reserved.