Fixlet Site - EnterpriseSecurity Current Version: 1052 Published: Thu, 11 Sep 2008 00:00:45 GMT New Fixlets: ============ *************************************************************** Title: MS08-052: Vulnerabilities in GDI+ Could Allow Remote Code Execution - .NET Framework 2.0 SP1 - Windows 2000 SP4 Severity: None Fixlet ID: 805225 Fixlet Link: http://www.microsoft.com/technet/security/Bulletin/MS08-052.mspx Fixlet Description: Microsoft has released a security update that resolves several privately reported vulnerabilities in Microsoft Windows GDI+. These vulnerabilities could allow remote code execution if a user viewed a specially crafted image file using affected software or browsed a Web site that contains specially crafted content. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. After downloading and installing this update, affected computers will no longer be susceptible to these vulnerabilities. Important Note: There are known issues associated with the installation of this update. See the Known Issues section of the security bulletin for more information. Important Note: BigFix has received reports of various issues associated with the deployment of this patch. Please take extra caution to qualify this update in a test environment prior to use in a production environment. *************************************************************** Title: MS08-052: Vulnerabilities in GDI+ Could Allow Remote Code Execution - SQL Server 2005 SP2 - QFE Branch Severity: Critical Fixlet ID: 805229 Fixlet Link: http://www.microsoft.com/technet/security/Bulletin/MS08-052.mspx Fixlet Description: Microsoft has released a security update that resolves several privately reported vulnerabilities in Microsoft Windows GDI+. These vulnerabilities could allow remote code execution if a user viewed a specially crafted image file using affected software or browsed a Web site that contains specially crafted content. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. After downloading and installing this update, affected computers will no longer be susceptible to these vulnerabilities. Important Note: There are known issues associated with the installation of this update. See the Known Issues section of the security bulletin for more information. *************************************************************** Title: MS08-052: Vulnerabilities in GDI+ Could Allow Remote Code Execution - SQL Server 2005 SP2 - QFE Branch (x64) Severity: Critical Fixlet ID: 805230 Fixlet Link: http://www.microsoft.com/technet/security/Bulletin/MS08-052.mspx Fixlet Description: Microsoft has released a security update that resolves several privately reported vulnerabilities in Microsoft Windows GDI+. These vulnerabilities could allow remote code execution if a user viewed a specially crafted image file using affected software or browsed a Web site that contains specially crafted content. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. After downloading and installing this update, affected computers will no longer be susceptible to these vulnerabilities. Important Note: There are known issues associated with the installation of this update. See the Known Issues section of the security bulletin for more information. *************************************************************** Title: MS08-052: Vulnerabilities in GDI+ Could Allow Remote Code Execution - Visual Studio .NET 2002 SP1 Severity: None Fixlet ID: 805233 Fixlet Link: http://www.microsoft.com/technet/security/Bulletin/MS08-052.mspx Fixlet Description: Microsoft has released a security update that resolves several privately reported vulnerabilities in Microsoft Windows GDI+. These vulnerabilities could allow remote code execution if a user viewed a specially crafted image file using affected software or browsed a Web site that contains specially crafted content. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. After downloading and installing this update, affected computers will no longer be susceptible to these vulnerabilities. Important Note: There are known issues associated with the installation of this update. See the Known Issues section of the security bulletin for more information. *************************************************************** Title: MS08-052: Vulnerabilities in GDI+ Could Allow Remote Code Execution - Visual Studio .NET 2003 SP1 Severity: None Fixlet ID: 805235 Fixlet Link: http://www.microsoft.com/technet/security/Bulletin/MS08-052.mspx Fixlet Description: Microsoft has released a security update that resolves several privately reported vulnerabilities in Microsoft Windows GDI+. These vulnerabilities could allow remote code execution if a user viewed a specially crafted image file using affected software or browsed a Web site that contains specially crafted content. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. After downloading and installing this update, affected computers will no longer be susceptible to these vulnerabilities. Important Note: There are known issues associated with the installation of this update. See the Known Issues section of the security bulletin for more information. *************************************************************** Title: MS08-052: CORRUPT PATCH - Visual Studio .NET 2003 SP1 Severity: None Fixlet ID: 805242 Fixlet Link: http://www.microsoft.com/technet/security/Bulletin/MS08-052.mspx *************************************************************** Title: MS08-052: CORRUPT PATCH - Visual Studio .NET 2002 SP1 Severity: None Fixlet ID: 805244 Fixlet Link: http://www.microsoft.com/technet/security/Bulletin/MS08-052.mspx *************************************************************** Title: MS08-052: Vulnerabilities in GDI+ Could Allow Remote Code Execution - Visual FoxPro 9.0 SP1 - Windows 2000 SP4 Severity: None Fixlet ID: 805247 Fixlet Link: http://www.microsoft.com/technet/security/Bulletin/MS08-052.mspx Fixlet Description: Microsoft has released a security update that resolves several privately reported vulnerabilities in Microsoft Windows GDI+. These vulnerabilities could allow remote code execution if a user viewed a specially crafted image file using affected software or browsed a Web site that contains specially crafted content. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. After downloading and installing this update, affected computers will no longer be susceptible to these vulnerabilities. Important Note: There are known issues associated with the installation of this update. See the Known Issues section of the security bulletin for more information. *************************************************************** Title: MS08-052: Vulnerabilities in GDI+ Could Allow Remote Code Execution - Visual FoxPro 9.0 SP2 - Windows 2000 SP4 Severity: None Fixlet ID: 805249 Fixlet Link: http://www.microsoft.com/technet/security/Bulletin/MS08-052.mspx Fixlet Description: Microsoft has released a security update that resolves several privately reported vulnerabilities in Microsoft Windows GDI+. These vulnerabilities could allow remote code execution if a user viewed a specially crafted image file using affected software or browsed a Web site that contains specially crafted content. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. After downloading and installing this update, affected computers will no longer be susceptible to these vulnerabilities. Important Note: There are known issues associated with the installation of this update. See the Known Issues section of the security bulletin for more information.