Microsoft Patch Release Stats - September 2006

(imported topic written by tim_tsai)

Microsoft released new Security Bulletins MS06-052~MS06-054 and re-released MS06-040 and MS06-042 earlier today at 10:40 am. Out of the new and re-released bulletins, three were rated “Critical”.

BigFix released content for all new security bulletins by 5 pm, with the exception of the Network Install (9x/ME) and Administrative Install content for MS06-054. By 8 pm, full content coverage was published, including all re-released updates.

In total, 36 new Fixlet messages were published which covered 13 new Microsoft security patches.

(imported comment written by ktang91)

when will the Fixlets about them be published after the Simplified Chinese patches are released by MS?

(imported comment written by tim_tsai)

The Simplified Chinese content has been published.

(imported comment written by Harald.Zarakowitis)

I cannot see the rereleased MS06-040. Has it a different name to the original fixlet?

Edit:

Also I believe that Microsoft doesn´t change the the version of netapi32.dll with the release so the relevance rule won´t detect it.

Has someone experienced this too?

(imported comment written by tim_tsai)

Hi Harald,

The Fixlet title for re-released and original versions of Microsoft security patches are actually the same. When a revised update is released, we generally supersede the original one (Add a FALSE to the relevance), and create a new set of Fixlet messages for the revised update. Read the Fixlet description carefully to figure out what version of the update is being deployed.

For MS06-040, only the updates for Windows Server 2003 and Windows XP/2003 x64 were re-released.

Original, superseded Fixlet IDs:

Windows Server 2003: 604003, 604004

Windows XP/2003 x64: 604007, 604008, 604009

Re-released Fixlet IDs:

Windows Server 2003: 604011

Windows XP/2003 x64: 604013, 604014, 604015

(imported comment written by Harald.Zarakowitis)

Hi Tim,

first of all: Thanks for the answer. But another question occurs to me. I compared both relevance statements of the MS06-040 for W2k3 and the re-released patch. The are exactly the same. So how does BigFix decides if a computer needs the re-released patch. At the moment the re-released MS06-040 is not relevant for any computer, but we are pretty sure that it is needed because we didn´t installed it yet.

So again: Both fixlets check for the netapi32.dll. I guess if you have installed the original patch BigFix won´t know that the re-released patch is relevant.

Do I miss something here?

Best regards,

Harald

(imported comment written by jessewk)

Harald,

That’s correct. Microsoft only recommends installing the re-release if you have not patched yet, or are experiencing problems with the first patch. Therefore, if you have applied the original patch, the re-release will not be relevant.

If you do have a system where you want to apply the new patch over the old patch, you can use the Patch Rollback Wizard to remove the old version and then install the new version with the Fixlet.

-Jesse