View Single Post
  #6 (permalink)  
Old 2006-04-18
runcmd runcmd is offline
Member
 
Join Date: 2006-02-21
Location: 127.0.0.1
Posts: 56
Rep Power: 3
runcmd has an average reputation (10+)
Default Re: SmartDefense Update CPAI-2006-033 / CVE-2006-1359

Although I have not yet received an update on my CheckPoint case, Microsoft has issued KB912812 to address the "Internet Explorer createTextRange () Vulnerability". The bad news: Microsoft released this as a cumulative security update, which includes the changes made by KB912945. This is the patch that adversely affects ActiveX. The quasi-good news is: Microsoft has granted a temporary "reprieve" on these ActiveX changes with the release of KB917425, which reverses the change made by KB912945--but only until sometime in June.


Summary:
KB912945 - ActiveX Changes
KB912812 - Addresses "Internet Explorer createTextRange () Vulnerability", as well as others. Also includes the ActiveX changes of KB912945.
KB917425 - Temporarily reverses ActiveX changes of KB912945/KB912812


Reference:
Microsoft Security Bulletin MS06-013
http://www.microsoft.com/technet/sec.../MS06-013.mspx

MS06-013: Cumulative security update for Internet Explorer
http://support.microsoft.com/?kbid=912812

Internet Explorer ActiveX update
http://support.microsoft.com/kb/912945

Internet Explorer ActiveX compatibility patch for Mshtml.dll
http://support.microsoft.com/kb/917425/
Reply With Quote