Tech Support > Computers & Technology > Virus & Worms > New updates for Win-98 (was: Critical Updates for Microsoft Windows)
New updates for Win-98 (was: Critical Updates for Microsoft Windows)
Posted by 98 Guy on June 14th, 2006


PCR wrote:

It was previously generally assumed that Win-98 was not affected by
the Windows Metafile vulnerability. Test files that were generated to
cause certain actions have never worked (to my knowledge) on Win-98
systems. So what's the story here?

http://secunia.com/advisories/20631/
http://www.microsoft.com/technet/sec.../MS06-026.mspx

Microsoft Security Bulletin MS06-026
Vulnerability in Graphics Rendering Engine Could Allow Remote Code
Execution (918547)
Published: June 13, 2006

-----------------

Microsoft Security Bulletin MS06-023
Vulnerability in Microsoft JScript Could Allow Remote Code Execution
(917344)

Secunia is not listing that item as affecting Windows 98.

But microsoft seems insistent that 98 is affected. Presumably, this
pertains only to the original or legacy version of Java that shipped
with 98, and that if that version is not installed (or has since been
replaced with any newer version of Java runtime) then this item is not
relavent.

But is this update compatible with any Win-98 system which has the
latest Sun Java runtime (JRE) installed?

Posted by Noel Paton on June 15th, 2006



"98 Guy" <98@Guy.com> wrote in message news:44909975.594E2767@Guy.com...
JAvascript and Java are two totally different things with no relation to
each other whatever. All versions of IE (above about v3, IIRC) have Jsript
capability, whether or not Java is installed, or whether the Java is the Sun
VM, or the MS VM.

--
Noel Paton (MS-MVP 2002-2006, Windows)

Nil Carborundum Illegitemi
http://www.crashfixpc.com/millsrpch.htm

http://tinyurl.com/6oztj

Please read http://dts-l.org/goodpost.htm on how to post messages to NG's


Posted by Ant on June 15th, 2006


"98 Guy" wrote:

Not quite. This is what the Microsoft Security Response Center Blog
<http://blogs.technet.com/msrc/archive/2006/01/13/417431.aspx>
had to say about the original problem announced in MS06-001:

<quote>
With WMF we want to be very clear: the Windows 9x platform is not
vulnerable to any "Critical" attack vector. The reason Windows 9x is
not vulnerable to a "Critical" attack vector is because an additional
step exists in the Win9x platform: When not printing to a printer,
applications will simply never process the SetAbortProc record.
Although the vulnerable code does exist in the Win9x platform, all
"Critical" attack vectors are blocked by this additional step. The
remaining attack vectors that we have identified require extensive
user interaction and are not rated "Critical". Again the "Critical"
rating refers to code execution attacks that could result in automated
attacks requiring little or no user interaction.
</quote>

So, the vulnerable code exists in 9x but is apparently difficult to
exploit.

From the MS06-026 link:

<quote>
How does this vulnerability relate to the vulnerabilities that were
corrected by MS06-001?

Both vulnerabilities were in the Graphics Rendering Engine. However,
this update addresses a new vulnerability that was not addressed as
part of MS06-001. MS06-001 does not help protect against the
vulnerability that is discussed in this bulletin, and does not
address this new vulnerability.
</quote>

This is something different and, according to MS, only affects Win98
and ME. They also say they have not had any reports about the exploit
being used.



Posted by PCR on June 15th, 2006


I had a mishap taking them at the Auto-Windows Update-- a CRASH during the install stage! As Candlin said, all five are offered at...

http://v4.windowsupdate.microsoft.co...en/default.asp
...., which also can be got by...
(1) "START button, Windows Update".
(2) Under "Other Options" in the left pane,
click "Personalize Windows Update".
(3) Check "Display the link to the Windows Update Catalog...",
& click Save Settings
(4) Click "Windows Update Catalog" in left pane, which is now under
"See Also". (Perhaps you need to leave & re-enter the site to see
it-- the whole site.)
(5) Click "Find Updates..." in right pane.
(6) Select OS in window & click "Search".
(7) Select "Critical Updates...", & be patient for them to show up in
the bottom window.

You must decide which apply to your computer, when you take them that
way. Probably, I need to install two of them from there, myself, now. Three were offered again subsequently at Windows Update & now show "Successful" at the installation history page-- where there is a "Failed" showing for all five after the first attempt! Sheesh!

| It was previously generally assumed that Win-98 was not affected by
| the Windows Metafile vulnerability.

I think Ant answered that well elsewhere in this thread. It wasn't considered "Critical", because it's "attack vector" required input from the user. HOWEVER, I think that required input might have been JUST to click an URL! Therefore, I'm glad it's fixed, if I did or can get it!

| Presumably, this
| pertains only to the original or legacy version of Java that shipped
| with 98

I'll go with Glee's response about Java & Script. I trust him implicitly in those matters! Also, there was I recall at least one critical update to MS's Java at Windows Update, though not in this round. And you can upgrade your Script separately, which I finally did do a while ago...
.......Quote..............
....snip...
Windows Script 5.6 for Windows 98, Windows Millennium Edition, and Windows NT 4.0:
http://www.microsoft.com/downloads/d...displaylang=en

Hmm... I do see...
c:\windows\SYSTEM\jscript.dll=c:\windows\SYSTEM\js cript.001
....in Wininit.bak, &...
jscript.dll Updated 5.6.0.8825 8/9/04 5.6.0.8831 5/17/06
....in my SFCLog.txt, after my 2nd try at Windows Update this round! It wasn't there after the crash of try one.


--
Glen Ventura, MS MVP Shell/User, A+
http://dts-l.org/goodpost.htm
........EOQ.............


--
Thanks or Good Luck,
There may be humor in this post, and,
Naturally, you will not sue,
should things get worse after this,
PCR
pcrrcp@netzero.net
"98 Guy" <98@Guy.com> wrote in message news:44909975.594E2767@Guy.com...
| PCR wrote:
|
| > Security Update for Windows 98 (KB918547)
|
| It was previously generally assumed that Win-98 was not affected by
| the Windows Metafile vulnerability. Test files that were generated to
| cause certain actions have never worked (to my knowledge) on Win-98
| systems. So what's the story here?
|
| http://secunia.com/advisories/20631/
| http://www.microsoft.com/technet/sec.../MS06-026.mspx
|
| Microsoft Security Bulletin MS06-026
| Vulnerability in Graphics Rendering Engine Could Allow Remote Code
| Execution (918547)
| Published: June 13, 2006
|
| -----------------
|
| > Security Update for Windows 98 (KB917344)
|
| Microsoft Security Bulletin MS06-023
| Vulnerability in Microsoft JScript Could Allow Remote Code Execution
| (917344)
|
| Secunia is not listing that item as affecting Windows 98.
|
| But microsoft seems insistent that 98 is affected. Presumably, this
| pertains only to the original or legacy version of Java that shipped
| with 98, and that if that version is not installed (or has since been
| replaced with any newer version of Java runtime) then this item is not
| relavent.
|
| But is this update compatible with any Win-98 system which has the
| latest Sun Java runtime (JRE) installed?


Similar Posts