![]() |
| |||||||
Dec 12 SECURITY UPDATE to version 11.3.1 to patch vulnerabilities |
| | Thread Tools | Search this Thread | Display Modes |
|
#1
| |||
| |||
| I saw the the update posted on versiontracker.com at: http://www.versiontracker.com/dyn/moreinfo/macosx/14980 Rather than download at that site, I updated by going under Entourage's Help pulldown menu to "Check for Updates." As I noted in my comments on the versiontracker.com site: 11.3.0 installed without incident after I had quit out of all Office programs. Version numbers: Entourage updated from 11.2.5 to 11.3.1 but both Word and Excel remained at 11.3.0. No issues whatsoever in putting Entourage, Excel and Word through their paces. It would be nice if there never were any security vulnerabilities to patch but I do appreciate the frequent and quick efforts of Microsoft and of Apple to respond to discovery of holes. Respectfully, Norm |
|
#2
| |||
| |||
| Norman R. Nager, Ph.D. wrote: > I saw the the update posted on versiontracker.com at: > > http://www.versiontracker.com/dyn/moreinfo/macosx/14980 > Hmmm, prompted by this post I went to <http://www.microsoft.com/mac/downloads.aspx?pid=download&location=/mac/download/Office2004/Office2004_11.3.1.xml&secid=4&ssid=32&flgnosysreq=True> to download the update. Clicking any of the languages gives "page not found". Ho hum, maybe I'll go via versiontracker.com PhilD -- <>< |
|
#3
| |||
| |||
| On 13/12/06 08:27, in article 1165998436.426003.31630@f1g2000cwa.googlegroups.co m, "PhilD" <phildeaves@yahoo.co.uk> wrote: > > Norman R. Nager, Ph.D. wrote: >> I saw the the update posted on versiontracker.com at: >> >> http://www.versiontracker.com/dyn/moreinfo/macosx/14980 >> > > > Hmmm, prompted by this post I went to > <http://www.microsoft.com/mac/downlo...ion=/mac/downlo > ad/Office2004/Office2004_11.3.1.xml&secid=4&ssid=32&flgnosysreq=True> > to download the update. Clicking any of the languages gives "page not > found". > > Ho hum, maybe I'll go via versiontracker.com > > PhilD > > -- > <>< > I get the same 'page not found' message when I try the link. If I try and get the update via Entourage, using 'Check for Updates', it reckons that there are no updates available. I've tried going via the versiontracker route too, and it's still unavailable. I presume the update has been pulled by Microsoft, and will remain unavailable until there's a fix for the fix?! -- Paul Stockford |
|
#4
| |||
| |||
| ------------------------------ Title: Microsoft Office 2004 11.3.1: Plugs security holes [UPDATE: Download no longer available] Date: Tuesday, December 12 2006 @ 03:15 PM PST Read the full article at http://www.macfixit.com/article.php...061212152421334 ------------------------------ Anyone know what's going on???? In article <C1A475A4.1A8C5%nnager@vnoxsxpxaxmv.fullerton.edu>, "Norman R. Nager, Ph.D." <nnager@vnoxsxpxaxmv.fullerton.edu> wrote: > I saw the the update posted on versiontracker.com at: > > http://www.versiontracker.com/dyn/moreinfo/macosx/14980 > > Rather than download at that site, I updated by going under Entourage's Help > pulldown menu to "Check for Updates." > > As I noted in my comments on the versiontracker.com site: > > 11.3.0 installed without incident after I had quit out of all Office > programs. > > Version numbers: Entourage updated from 11.2.5 to 11.3.1 but both Word and > Excel remained at 11.3.0. > > No issues whatsoever in putting Entourage, Excel and Word through their > paces. > > It would be nice if there never were any security vulnerabilities to patch > but I do appreciate the frequent and quick efforts of Microsoft and of Apple > to respond to discovery of holes. > > Respectfully, Norm |
|
#5
| |||
| |||
| See the discussion thread on "Why was 11.3.1 Pulled?" in the Entourage Newsgroup. Respectfully, Norm On 12/13/06 9:27 AM, in article REMOVEarkay-BE8AE2.11270313122006@n...ews.prodigy.com, "aRKay" <REMOVEarkay@qsl.net> wrote: > ------------------------------ > > Title: Microsoft Office 2004 11.3.1: Plugs security holes [UPDATE: > Download no longer available] > Date: Tuesday, December 12 2006 @ 03:15 PM PST > > Read the full article at > http://www.macfixit.com/article.php...061212152421334 > > ------------------------------ > > Anyone know what's going on???? > > > > In article <C1A475A4.1A8C5%nnager@vnoxsxpxaxmv.fullerton.edu>, > "Norman R. Nager, Ph.D." <nnager@vnoxsxpxaxmv.fullerton.edu> wrote: > >> I saw the the update posted on versiontracker.com at: >> >> http://www.versiontracker.com/dyn/moreinfo/macosx/14980 >> >> Rather than download at that site, I updated by going under Entourage's Help >> pulldown menu to "Check for Updates." >> >> As I noted in my comments on the versiontracker.com site: >> >> 11.3.0 installed without incident after I had quit out of all Office >> programs. >> >> Version numbers: Entourage updated from 11.2.5 to 11.3.1 but both Word and >> Excel remained at 11.3.0. >> >> No issues whatsoever in putting Entourage, Excel and Word through their >> paces. >> >> It would be nice if there never were any security vulnerabilities to patch >> but I do appreciate the frequent and quick efforts of Microsoft and of Apple >> to respond to discovery of holes. >> >> Respectfully, Norm |
|
#6
| |||
| |||
| Yep. Wait a few days... The patch was released early in error, and cancelled when they discovered that some of the bits it included had not been fully tested. If you have already loaded it, leave it there, it is unlikely to do any harm. The official release will straighten it out. Cheers On 14/12/06 4:27 AM, in article REMOVEarkay-BE8AE2.11270313122006@n...ews.prodigy.com, "aRKay" <REMOVEarkay@qsl.net> wrote: > ------------------------------ > > Title: Microsoft Office 2004 11.3.1: Plugs security holes [UPDATE: > Download no longer available] > Date: Tuesday, December 12 2006 @ 03:15 PM PST > > Read the full article at > http://www.macfixit.com/article.php...061212152421334 > > ------------------------------ > > Anyone know what's going on???? > > > > In article <C1A475A4.1A8C5%nnager@vnoxsxpxaxmv.fullerton.edu>, > "Norman R. Nager, Ph.D." <nnager@vnoxsxpxaxmv.fullerton.edu> wrote: > >> I saw the the update posted on versiontracker.com at: >> >> http://www.versiontracker.com/dyn/moreinfo/macosx/14980 >> >> Rather than download at that site, I updated by going under Entourage's Help >> pulldown menu to "Check for Updates." >> >> As I noted in my comments on the versiontracker.com site: >> >> 11.3.0 installed without incident after I had quit out of all Office >> programs. >> >> Version numbers: Entourage updated from 11.2.5 to 11.3.1 but both Word and >> Excel remained at 11.3.0. >> >> No issues whatsoever in putting Entourage, Excel and Word through their >> paces. >> >> It would be nice if there never were any security vulnerabilities to patch >> but I do appreciate the frequent and quick efforts of Microsoft and of Apple >> to respond to discovery of holes. >> >> Respectfully, Norm -- Please reply to the newsgroup to maintain the thread. Please do not email me unless I ask you to. John McGhie <john@mcghie.name> Microsoft MVP, Word and Word for Macintosh. Business Analyst, Consultant Technical Writer. Sydney, Australia +61 (0) 4 1209 1410 |
|
#7
| |||
| |||
| This morning, I ran AutoUpdate (Help pulldown menu/"Check for Updates") and happily discovered that 11.3.2 was available. I used AutoUpdate without incident. It advanced Entourage from 11.2.5 to 11.3.2. The version numbers of Excel and Word remained at 11.3. I've spent a few hours putting all three Office 2004 applications through their paces. Everything's working perfectly on my Dual G5 2.0., running with OS 10.4.8. Respectfully, Norm On 12/16/06 11:21 PM, in article C1AB3B39.534D8%john@mcghie.name, "John McGhie [MVP - Word and Word Macintosh]" <john@mcghie.name> wrote: > Yep. > > Wait a few days... The patch was released early in error, and cancelled > when they discovered that some of the bits it included had not been fully > tested. > > If you have already loaded it, leave it there, it is unlikely to do any > harm. The official release will straighten it out. > > Cheers > > > On 14/12/06 4:27 AM, in article > REMOVEarkay-BE8AE2.11270313122006@n...ews.prodigy.com, "aRKay" > <REMOVEarkay@qsl.net> wrote: > >> ------------------------------ >> >> Title: Microsoft Office 2004 11.3.1: Plugs security holes [UPDATE: >> Download no longer available] >> Date: Tuesday, December 12 2006 @ 03:15 PM PST >> >> Read the full article at >> http://www.macfixit.com/article.php...061212152421334 >> >> ------------------------------ >> >> Anyone know what's going on???? >> >> >> >> In article <C1A475A4.1A8C5%nnager@vnoxsxpxaxmv.fullerton.edu>, >> "Norman R. Nager, Ph.D." <nnager@vnoxsxpxaxmv.fullerton.edu> wrote: >> >>> I saw the the update posted on versiontracker.com at: >>> >>> http://www.versiontracker.com/dyn/moreinfo/macosx/14980 >>> >>> Rather than download at that site, I updated by going under Entourage's Help >>> pulldown menu to "Check for Updates." >>> >>> As I noted in my comments on the versiontracker.com site: >>> >>> 11.3.0 installed without incident after I had quit out of all Office >>> programs. >>> >>> Version numbers: Entourage updated from 11.2.5 to 11.3.1 but both Word and >>> Excel remained at 11.3.0. >>> >>> No issues whatsoever in putting Entourage, Excel and Word through their >>> paces. >>> >>> It would be nice if there never were any security vulnerabilities to patch >>> but I do appreciate the frequent and quick efforts of Microsoft and of Apple >>> to respond to discovery of holes. >>> >>> Respectfully, Norm |
|
#8
| |||
| |||
| MacFixIt has since reported the availability of an 11.3.2 download, as well as the AutoUpdate. The MacFixIt article tells what changes 11.3.2 makes--and doesn't make. Apparently, the Word vulnerabilities that were supposed to have been patched by by the pulled 11.3.1 update still remain: <http://www.macfixit.com/index.shtml> Here's the Microsoft webpage to which the MacFixIt article links: <http://www.microsoft.com/mac/downlo...ation=/mac/down load/Office2004/Office2004_1132.xml> One piece of important info on pre-reqs before installation of the download: Make sure that you've already run the 11.3.0 updater. It's unclear to me whether/how this applies to running of AutoUpdate. Perhaps, someone can answer that? Respectfully, Norm On 12/19/06 12:58 PM, in article C1AD927C.1AB3A%nnager@vnoxsxpxaxmv.fullerton.edu, "Norman R. Nager, Ph.D." <nnager@vnoxsxpxaxmv.fullerton.edu> wrote: > This morning, I ran AutoUpdate (Help pulldown menu/"Check for Updates") and > happily discovered that 11.3.2 was available. > > I used AutoUpdate without incident. It advanced Entourage from 11.2.5 to > 11.3.2. The version numbers of Excel and Word remained at 11.3. > > I've spent a few hours putting all three Office 2004 applications through > their paces. Everything's working perfectly on my Dual G5 2.0., running > with OS 10.4.8. > > Respectfully, Norm > > > On 12/16/06 11:21 PM, in article C1AB3B39.534D8%john@mcghie.name, "John > McGhie [MVP - Word and Word Macintosh]" <john@mcghie.name> wrote: > >> Yep. >> >> Wait a few days... The patch was released early in error, and cancelled >> when they discovered that some of the bits it included had not been fully >> tested. >> >> If you have already loaded it, leave it there, it is unlikely to do any >> harm. The official release will straighten it out. >> >> Cheers >> >> >> On 14/12/06 4:27 AM, in article >> REMOVEarkay-BE8AE2.11270313122006@n...ews.prodigy.com, "aRKay" >> <REMOVEarkay@qsl.net> wrote: >> >>> ------------------------------ >>> >>> Title: Microsoft Office 2004 11.3.1: Plugs security holes [UPDATE: >>> Download no longer available] >>> Date: Tuesday, December 12 2006 @ 03:15 PM PST >>> >>> Read the full article at >>> http://www.macfixit.com/article.php...061212152421334 >>> >>> ------------------------------ >>> >>> Anyone know what's going on???? >>> >>> >>> >>> In article <C1A475A4.1A8C5%nnager@vnoxsxpxaxmv.fullerton.edu>, >>> "Norman R. Nager, Ph.D." <nnager@vnoxsxpxaxmv.fullerton.edu> wrote: >>> >>>> I saw the the update posted on versiontracker.com at: >>>> >>>> http://www.versiontracker.com/dyn/moreinfo/macosx/14980 >>>> >>>> Rather than download at that site, I updated by going under Entourage's >>>> Help >>>> pulldown menu to "Check for Updates." >>>> >>>> As I noted in my comments on the versiontracker.com site: >>>> >>>> 11.3.0 installed without incident after I had quit out of all Office >>>> programs. >>>> >>>> Version numbers: Entourage updated from 11.2.5 to 11.3.1 but both Word and >>>> Excel remained at 11.3.0. >>>> >>>> No issues whatsoever in putting Entourage, Excel and Word through their >>>> paces. >>>> >>>> It would be nice if there never were any security vulnerabilities to patch >>>> but I do appreciate the frequent and quick efforts of Microsoft and of >>>> Apple >>>> to respond to discovery of holes. >>>> >>>> Respectfully, Norm > |
|
#9
| |||
| |||
| Thank you, Norm. I always appreciate the fact that there are young whippersnappers on this NG, such as your good self, who are not as risk-averse as I am! ;-) Cheers, Clive Huggan ============ On 20/12/06 8:16 AM, in article C1AD96B1.1AB3D%nnager@vnoxsxpxaxmv.fullerton.edu, "Norman R. Nager, Ph.D." <nnager@vnoxsxpxaxmv.fullerton.edu> wrote: > MacFixIt has since reported the availability of an 11.3.2 download, as well > as the AutoUpdate. The MacFixIt article tells what changes 11.3.2 makes--and > doesn't make. Apparently, the Word vulnerabilities that were supposed to > have been patched by by the pulled 11.3.1 update still remain: > <http://www.macfixit.com/index.shtml> > > Here's the Microsoft webpage to which the MacFixIt article links: > <http://www.microsoft.com/mac/downlo...ation=/mac/down > load/Office2004/Office2004_1132.xml> > > One piece of important info on pre-reqs before installation of the download: > Make sure that you've already run the 11.3.0 updater. It's unclear to me > whether/how this applies to running of AutoUpdate. Perhaps, someone can > answer that? > > Respectfully, Norm > > > On 12/19/06 12:58 PM, in article > C1AD927C.1AB3A%nnager@vnoxsxpxaxmv.fullerton.edu, "Norman R. Nager, Ph.D." > <nnager@vnoxsxpxaxmv.fullerton.edu> wrote: > >> This morning, I ran AutoUpdate (Help pulldown menu/"Check for Updates") and >> happily discovered that 11.3.2 was available. >> >> I used AutoUpdate without incident. It advanced Entourage from 11.2.5 to >> 11.3.2. The version numbers of Excel and Word remained at 11.3. >> >> I've spent a few hours putting all three Office 2004 applications through >> their paces. Everything's working perfectly on my Dual G5 2.0., running >> with OS 10.4.8. >> >> Respectfully, Norm >> >> >> On 12/16/06 11:21 PM, in article C1AB3B39.534D8%john@mcghie.name, "John >> McGhie [MVP - Word and Word Macintosh]" <john@mcghie.name> wrote: >> >>> Yep. >>> >>> Wait a few days... The patch was released early in error, and cancelled >>> when they discovered that some of the bits it included had not been fully >>> tested. >>> >>> If you have already loaded it, leave it there, it is unlikely to do any >>> harm. The official release will straighten it out. >>> >>> Cheers >>> >>> >>> On 14/12/06 4:27 AM, in article >>> REMOVEarkay-BE8AE2.11270313122006@n...ews.prodigy.com, "aRKay" >>> <REMOVEarkay@qsl.net> wrote: >>> >>>> ------------------------------ >>>> >>>> Title: Microsoft Office 2004 11.3.1: Plugs security holes [UPDATE: >>>> Download no longer available] >>>> Date: Tuesday, December 12 2006 @ 03:15 PM PST >>>> >>>> Read the full article at >>>> http://www.macfixit.com/article.php...061212152421334 >>>> >>>> ------------------------------ >>>> >>>> Anyone know what's going on???? >>>> >>>> >>>> >>>> In article <C1A475A4.1A8C5%nnager@vnoxsxpxaxmv.fullerton.edu>, >>>> "Norman R. Nager, Ph.D." <nnager@vnoxsxpxaxmv.fullerton.edu> wrote: >>>> >>>>> I saw the the update posted on versiontracker.com at: >>>>> >>>>> http://www.versiontracker.com/dyn/moreinfo/macosx/14980 >>>>> >>>>> Rather than download at that site, I updated by going under Entourage's >>>>> Help >>>>> pulldown menu to "Check for Updates." >>>>> >>>>> As I noted in my comments on the versiontracker.com site: >>>>> >>>>> 11.3.0 installed without incident after I had quit out of all Office >>>>> programs. >>>>> >>>>> Version numbers: Entourage updated from 11.2.5 to 11.3.1 but both Word and >>>>> Excel remained at 11.3.0. >>>>> >>>>> No issues whatsoever in putting Entourage, Excel and Word through their >>>>> paces. >>>>> >>>>> It would be nice if there never were any security vulnerabilities to patch >>>>> but I do appreciate the frequent and quick efforts of Microsoft and of >>>>> Apple >>>>> to respond to discovery of holes. >>>>> >>>>> Respectfully, Norm >> > |
|
#10
| |||
| |||
| Hi Norman: It's probably safest to rely on the Microsoft website for information about Microsoft patches :-) The Word vulnerability they are talking about is vanishingly unlikely to matter on the Mac. Basically, what they are saying is that if you create a specially-crafted Word document, you can jam so many digital bits into a specific buffer in Word that the buffer will overflow. When that happens, Word will crash. If you are very clever, you can use this to leave executable code behind in the computer's memory and use that to elevate your permissions to that of the Administrator and thus potentially do bad things. On Windows! On Mac OS, the underlying Unix operating system is less likely to allow you to get away with such nonsense. It's theoretically possible. But the attacker can only actually get a few bytes of code into the machine. In that space, he has to first figure out whether he's on a Mac or a PC, and then which version of operating system he's dealing with. If he can't, he may crash the system, but he won't be able to do bad things. The attack requires that an external program can run code that was written into the memory by a process that no longer exists and used to be Microsoft Word. Unix is far, far less likely to allow any external program to get a look into the memory owned by a different program, much less allow code from a crashed program to continue to execute. I am sure it's "theoretically" possible to do this. It's also theoretically possible that I will win the lottery. I think I have a several hundred times greater chance of winning the lottery than getting hit by this one. So Microsoft has probably decided that they don't have to hurry to fix the Mac version of this one. They'll fix it eventually: but while there is Windows code out there trying to exploit this hole, there's nothing appeared for the Mac yet. Given that malware these days is produced by large commercial businesses (think: Mafia...) looking to make a profit, it's unlikely they will invest in using this one to crack Macs any time soon. We do need to remember that most of these "Security Alerts" are originated by anti-virus companies trying to improve their falling sales :-) It could happen. I could win the lottery... Yes, you must have the 11.3 Service Pack applied before the 11.3.2 Update. The updater should check for this and prompt you if you haven't. The Microsoft Mac website is a bit sloppy about distinguishing between Service Packs and Updaters. A service Pack contains all the fixes released up to its published date, it will update the software all the way up from 11.0 (the un-updated Office CD) to 11.3. An Updater applies only specific fixes. It can update only from the level of the most recent Service Pack. Hope this helps On 20/12/06 8:16 AM, in article C1AD96B1.1AB3D%nnager@vnoxsxpxaxmv.fullerton.edu, "Norman R. Nager, Ph.D." <nnager@vnoxsxpxaxmv.fullerton.edu> wrote: > MacFixIt has since reported the availability of an 11.3.2 download, as well > as the AutoUpdate. The MacFixIt article tells what changes 11.3.2 makes--and > doesn't make. Apparently, the Word vulnerabilities that were supposed to > have been patched by by the pulled 11.3.1 update still remain: > <http://www.macfixit.com/index.shtml> > > Here's the Microsoft webpage to which the MacFixIt article links: > <http://www.microsoft.com/mac/downlo...ation=/mac/down > load/Office2004/Office2004_1132.xml> > > One piece of important info on pre-reqs before installation of the download: > Make sure that you've already run the 11.3.0 updater. It's unclear to me > whether/how this applies to running of AutoUpdate. Perhaps, someone can > answer that? > > Respectfully, Norm > > > On 12/19/06 12:58 PM, in article > C1AD927C.1AB3A%nnager@vnoxsxpxaxmv.fullerton.edu, "Norman R. Nager, Ph.D." > <nnager@vnoxsxpxaxmv.fullerton.edu> wrote: > >> This morning, I ran AutoUpdate (Help pulldown menu/"Check for Updates") and >> happily discovered that 11.3.2 was available. >> >> I used AutoUpdate without incident. It advanced Entourage from 11.2.5 to >> 11.3.2. The version numbers of Excel and Word remained at 11.3. >> >> I've spent a few hours putting all three Office 2004 applications through >> their paces. Everything's working perfectly on my Dual G5 2.0., running >> with OS 10.4.8. >> >> Respectfully, Norm >> >> >> On 12/16/06 11:21 PM, in article C1AB3B39.534D8%john@mcghie.name, "John >> McGhie [MVP - Word and Word Macintosh]" <john@mcghie.name> wrote: >> >>> Yep. >>> >>> Wait a few days... The patch was released early in error, and cancelled >>> when they discovered that some of the bits it included had not been fully >>> tested. >>> >>> If you have already loaded it, leave it there, it is unlikely to do any >>> harm. The official release will straighten it out. >>> >>> Cheers >>> >>> >>> On 14/12/06 4:27 AM, in article >>> REMOVEarkay-BE8AE2.11270313122006@n...ews.prodigy.com, "aRKay" >>> <REMOVEarkay@qsl.net> wrote: >>> >>>> ------------------------------ >>>> >>>> Title: Microsoft Office 2004 11.3.1: Plugs security holes [UPDATE: >>>> Download no longer available] >>>> Date: Tuesday, December 12 2006 @ 03:15 PM PST >>>> >>>> Read the full article at >>>> http://www.macfixit.com/article.php...061212152421334 >>>> >>>> ------------------------------ >>>> >>>> Anyone know what's going on???? >>>> >>>> >>>> >>>> In article <C1A475A4.1A8C5%nnager@vnoxsxpxaxmv.fullerton.edu>, >>>> "Norman R. Nager, Ph.D." <nnager@vnoxsxpxaxmv.fullerton.edu> wrote: >>>> >>>>> I saw the the update posted on versiontracker.com at: >>>>> >>>>> http://www.versiontracker.com/dyn/moreinfo/macosx/14980 >>>>> >>>>> Rather than download at that site, I updated by going under Entourage's >>>>> Help >>>>> pulldown menu to "Check for Updates." >>>>> >>>>> As I noted in my comments on the versiontracker.com site: >>>>> >>>>> 11.3.0 installed without incident after I had quit out of all Office >>>>> programs. >>>>> >>>>> Version numbers: Entourage updated from 11.2.5 to 11.3.1 but both Word and >>>>> Excel remained at 11.3.0. >>>>> >>>>> No issues whatsoever in putting Entourage, Excel and Word through their >>>>> paces. >>>>> >>>>> It would be nice if there never were any security vulnerabilities to patch >>>>> but I do appreciate the frequent and quick efforts of Microsoft and of >>>>> Apple >>>>> to respond to discovery of holes. >>>>> >>>>> Respectfully, Norm >> > -- Please reply to the newsgroup to maintain the thread. Please do not email me unless I ask you to. John McGhie <john@mcghie.name> Microsoft MVP, Word and Word for Macintosh. Business Analyst, Consultant Technical Writer. Sydney, Australia +61 (0) 4 1209 1410 |
| Thread Tools | Search this Thread |
| Display Modes | |
|
|