the_guy:
QUOTE
Is there a way to delete the original runservices entry for the official 918547 and also the unofficial 891711 update? That way there is only 1 entry for each service. Maybe have a delreg for the official entry?
Good point.
I have just added a new [QX] section [which is run by DelReg=QX] to U891711.INF + U918547.INF to delete MS official RunServices entries upon installation.
Please download updated executables:
- U891711.EXE:
http://www.mdgx.com/files/U891711.EXE- U918547.EXE:
http://www.mdgx.com/files/U918547.EXE____________________________________
all:
To my knowledge, the WMF bug fixed by both Q918547 + U918547 is *not* the same with the MetaFile bug discussed at GRC.com:
http://www.grc.com/wmf/wmf.htmand detected by MouseTrap:
http://www.grc.com/files/MouseTrap.exeThis bug is present only in NTx [NT4/2000/XP/2003] OSes, and is described in MS06-001:
http://www.microsoft.com/technet/security/...n/ms06-001.mspxbecause if one runs MouseTrap on 9x OSes, they are found to be bug-free.
The WMF MetaFile bug fixed by both 918547 fixes in 98/98 SE/ME OSes and described in MS06-026:
http://www.microsoft.com/technet/security/...n/ms06-026.mspxis different, and so far, MS has not [*yet*] released any source code, full disclosure, proof-of-concept nor demo test for it.
Please read "AUTHOR's NOTES" in U918547.TXT for complete details:
http://www.mdgx.com/files/U918547.TXTComments from the U891711 + U918547 author:
QUOTE
On June 27 2006
eidenk wrote:
QUOTE
I thought there was finally no WMF vulnerability on 9x OSes.
http://www.grc.com/wmf/wmf.htmThere is no need to patch it if it's not vulnerable.
Windows 9x is vulnerable in many respects. Please see Peter Ferrie's article
on WMF vulnerabilities [Symantec web site]:
http://securityresponse.symantec.com/avcen...tent/18322.htmlMore info [Adobe Acrobat PDF, 113 KB, right-click to save!]:
http://pferrie.tripod.com/vb/wmf.pdfPeter Ferrie's home page:
http://pferrie.tripod.com/For example, it is a very, very quick thing to verify that a WMF with a
zero-pointer or backward-pointer record (*no* protection from Q918745 nor
U918745!) trashes, for example, Windows 98 SE.
____________________________________
PROBLEMCHYLD:
Unofficial 908519FX fix does only 1 thing, and requires MS official Q908519 fix already installed
[please read documentation before posting] = found here:
http://www.mdgx.com/web.htm#9SUQuoted from above:
* Microsoft Windows 98/98 SE Embedded Web Fonts T2EMBED.DLL 5.00.2195.7073
Security Vulnerability Fix:
http://www.microsoft.com/technet/security/...n/ms06-002.mspxDirect download [211 KB, English]:
http://download.windowsupdate.com/msdownlo...b8bd1b389f9.EXERequires MS IE 5.5 SP2 or newer already installed:
http://www.mdgx.com/toy.htm#IEXBUG: T2EMBED.DLL Fix above installs BUGgy INF file!
FIX: MUST Install this INF Fix [63 KB]:
http://www.mdgx.com/files/908519FX.EXEAFTER installing T2EMBED.DLL Fix above!
About U891711:
Please read here:
http://www.mdgx.com/web.htm#9SUand U891711.TXT for complete details:
http://www.mdgx.com/files/U891711.TXTAbout U918547:
Please read here:
http://www.mdgx.com/web.htm#9SUand U918547.TXT for complete details:
http://www.mdgx.com/files/U918547.TXT____________________________________
erpdude8:
MS official Q918547.EXE contains Q918547.DLL + KB918547.EXE with date stamp
4-26-2006.
Unofficial U918547.EXE contains Q918547.DLL + KB918547.EXE with date stamp
6-20-2006.
HTH