<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>DP's Security Bits</title><link>http://msmvps.com/blogs/donpatterson/default.aspx</link><description>Don Patterson (aka DP)</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Facebook beats the 'spam king'</title><link>http://msmvps.com/blogs/donpatterson/archive/2009/11/18/facebook-beats-the-spam-king.aspx</link><pubDate>Wed, 18 Nov 2009 16:50:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1740509</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1740509</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2009/11/18/facebook-beats-the-spam-king.aspx#comments</comments><description>&lt;p&gt;&lt;b&gt;Facebook was awarded $711m in a judgement on Thursday against self-described &amp;#39;spam king&amp;#39; Sanford Wallace.&lt;/b&gt;
&lt;/p&gt;
&lt;p&gt;
Judge Jeremy Fogel of the US District Court of the Northern District of
California granted Facebook&amp;#39;s application for a default judgement
against Wallace for violating the Can-Spam Act, which bans &amp;quot;false and
misleading&amp;quot; marketing emails. Fogel also found that Wallace &amp;quot;wilfully
violated&amp;quot; a temporary restraining order and preliminary injunction
issued in the case and referred the matter to the US Attorney&amp;#39;s Office
for prosecution of criminal contempt.
&lt;/p&gt;
&lt;p&gt;&amp;quot;The record demonstrates that Wallace wilfully violated the
statutes in question with blatant disregard for the rights of Facebook
and the thousands of Facebook users whose accounts were compromised by
his conduct,&amp;quot; Fogel wrote in his judgement order, which also
permanently prohibits Wallace from accessing the Facebook website or
creating a Facebook account, among other restrictions.
&lt;/p&gt;
&lt;p&gt;
For more, read &amp;quot;&lt;a href="http://news.cnet.com/8301-1023_3-10387021-93.html"&gt;Facebook awarded $711 million in spam lawsuit&lt;/a&gt; on CNET News.

			&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1740509" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/News/default.aspx">News</category></item><item><title>Microsoft Security Advisory Notification - November 13, 2009</title><link>http://msmvps.com/blogs/donpatterson/archive/2009/11/14/microsoft-security-advisory-notification-november-13-2009.aspx</link><pubDate>Sat, 14 Nov 2009 09:16:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1739684</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1739684</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2009/11/14/microsoft-security-advisory-notification-november-13-2009.aspx#comments</comments><description>&lt;p&gt;Issued: November 13, 2009&lt;br /&gt;&lt;br /&gt;&lt;span style="text-decoration:underline;"&gt;&lt;b&gt;Security Advisories Updated or Released Today&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt; * &lt;b&gt;Microsoft Security Advisory (977544)&lt;/b&gt;&lt;br /&gt;  - Title: Vulnerabilities in SMB Could Allow Denial of Service&lt;br /&gt;  - &lt;a class="moz-txt-link-freetext" href="http://www.microsoft.com/technet/security/advisory/977544.mspx"&gt;http://www.microsoft.com/technet/security/advisory/977544.mspx&lt;/a&gt;&lt;br /&gt;  - Revision Note: V1.0 (November 13, 2009): Advisory published.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1739684" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/Advisories+_2F00_+Bulletins/default.aspx">Advisories / Bulletins</category></item><item><title>Apple Releases Safari 4.0.4</title><link>http://msmvps.com/blogs/donpatterson/archive/2009/11/13/apple-releases-safari-4-0-4.aspx</link><pubDate>Fri, 13 Nov 2009 10:05:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1739473</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1739473</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2009/11/13/apple-releases-safari-4-0-4.aspx#comments</comments><description>&lt;p&gt;&lt;span style="font-family:Arial,Geneva,Helvetica;"&gt; Apple has released Safari
4.0.4 to address multiple vulnerabilities in a number of components.
Exploitation of these vulnerabilities may allow an attacker to execute
arbitrary code, cause a denial-of-service condition, conduct cross-site
request forgery, or obtain sensitive information. These vulnerabilities
affect Safari running on both the Mac OS X and Windows platforms.&lt;br /&gt;&lt;br /&gt;US-CERT encourages users and administrators to review Apple article &lt;a href="http://support.apple.com/kb/HT3949" target="_self"&gt;HT3949&lt;/a&gt; and upgrade to Safari 4.0.4 to help mitigate the risks.

  &lt;/span&gt;&lt;/p&gt;

&lt;p&gt;
&lt;span style="font-family:Arial,Geneva,Helvetica;"&gt;&lt;a href="http://www.us-cert.gov/current/index.html#apple_releases_safari_4_03"&gt;http://www.us-cert.gov/current/index.html#apple_releases_safari_4_03&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1739473" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/News/default.aspx">News</category></item><item><title>Microsoft Security Bulletin Minor Revisions - November 12, 2009</title><link>http://msmvps.com/blogs/donpatterson/archive/2009/11/13/microsoft-security-bulletin-minor-revisions-november-12-2009.aspx</link><pubDate>Fri, 13 Nov 2009 09:58:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1739470</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1739470</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2009/11/13/microsoft-security-bulletin-minor-revisions-november-12-2009.aspx#comments</comments><description>&lt;p&gt;Issued: November 12, 2009&lt;br /&gt;&lt;br /&gt;&lt;span style="text-decoration:underline;"&gt;&lt;b&gt;Summary&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The following bulletins have undergone a minor revision increment. &lt;br /&gt;Please see the appropriate bulletin for more details.&lt;br /&gt;&lt;br /&gt;  * MS09-065 - Critical&lt;br /&gt;&lt;br /&gt;&lt;span style="text-decoration:underline;"&gt;&lt;b&gt;Bulletin Information:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;* &lt;b&gt;MS09-065 - Critical&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;  - &lt;a class="moz-txt-link-freetext" href="http://www.microsoft.com/technet/security/bulletin/ms09-065.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/ms09-065.mspx&lt;/a&gt;&lt;br /&gt;  - Reason for Revision: V1.1 (November 12, 2009): Added a link to&lt;br /&gt;    Microsoft Knowledge Base Article 969947 under Known Issues in&lt;br /&gt;    the Executive Summary.  &lt;br /&gt;  - Originally posted: November 10, 2009&lt;br /&gt;  - Updated: November 12, 2009&lt;br /&gt;  - Bulletin Severity Rating: Critical&lt;br /&gt;  - Version: 1.1&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1739470" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/Advisories+_2F00_+Bulletins/default.aspx">Advisories / Bulletins</category></item><item><title>Apple Releases Mac OS X v10.6.2 and Security Update 2009-006</title><link>http://msmvps.com/blogs/donpatterson/archive/2009/11/11/apple-releases-mac-os-x-v10-6-2-and-security-update-2009-006.aspx</link><pubDate>Wed, 11 Nov 2009 13:08:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1738989</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1738989</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2009/11/11/apple-releases-mac-os-x-v10-6-2-and-security-update-2009-006.aspx#comments</comments><description>&lt;p&gt;&lt;span style="font-family:Arial,Geneva,Helvetica;"&gt;Apple has released Mac OS X
v10.6.2 and Security Update 2009-006 to address multiple
vulnerabilities in a number of applications. These vulnerabilities may
allow an attacker to execute arbitrary code, cause a denial-of-service
condition, conduct a man-in-the-middle attack, operate with escalated
privileges, or obtain sensitive information.&lt;br /&gt;&lt;br /&gt;US-CERT encourages users and administrators to review Apple article &lt;a href="http://support.apple.com/kb/HT3937" target="_self"&gt;HT3937&lt;/a&gt; and apply any necessary updates to help mitigate the risks.


  &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family:Arial,Geneva,Helvetica;"&gt;&lt;a href="http://www.us-cert.gov/current/index.html#apple_releases_mac_os_x2"&gt;http://www.us-cert.gov/current/index.html#apple_releases_mac_os_x2&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1738989" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/Advisories+_2F00_+Bulletins/default.aspx">Advisories / Bulletins</category></item><item><title>Microsoft Security Bulletin Major Revisions - November 10, 2009</title><link>http://msmvps.com/blogs/donpatterson/archive/2009/11/10/microsoft-security-bulletin-major-revisions-november-10-2009.aspx</link><pubDate>Tue, 10 Nov 2009 22:44:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1738875</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1738875</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2009/11/10/microsoft-security-bulletin-major-revisions-november-10-2009.aspx#comments</comments><description>&lt;p&gt;Issued: November 10, 2009&lt;br /&gt;&lt;br /&gt;&lt;span style="text-decoration:underline;"&gt;&lt;b&gt;Summary&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The following bulletins have undergone a major revision increment. &lt;br /&gt;Please see the appropriate bulletin for more details.&lt;br /&gt;&lt;br /&gt;  * MS09-051 - Critical&lt;br /&gt;  * MS09-045 - Critical&lt;br /&gt;&lt;br /&gt;&lt;span style="text-decoration:underline;"&gt;&lt;b&gt;Bulletin Information:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;* &lt;b&gt;MS09-051 - Critical&lt;/b&gt;&lt;br /&gt;&lt;br /&gt; - &lt;a class="moz-txt-link-freetext" href="http://www.microsoft.com/technet/security/bulletin/ms09-051.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/ms09-051.mspx&lt;/a&gt;&lt;br /&gt; - Reason for Revision: V2.0 (November 10, 2009): Bulletin revised&lt;br /&gt;    to communicate the rerelease of the update for Audio&lt;br /&gt;    Compression Manager on Microsoft Windows 2000 Service Pack 4&lt;br /&gt;    to fix a detection issue. This is a detection change only;&lt;br /&gt;    there were no changes to the binaries. Customers who have&lt;br /&gt;    successfully updated their systems do not need to reinstall&lt;br /&gt;    this update. Also corrected the registry key verification for&lt;br /&gt;    DirectShow WMA Voice Codec on Windows Server 2003.  &lt;br /&gt; - Originally posted: October 13, 2009&lt;br /&gt; - Updated: November 10, 2009&lt;br /&gt; - Bulletin Severity Rating: Critical&lt;br /&gt; - Version: 2.0&lt;br /&gt;    &lt;br /&gt;* &lt;b&gt;MS09-045 - Critical&lt;/b&gt;&lt;br /&gt;&lt;br /&gt; - &lt;a class="moz-txt-link-freetext" href="http://www.microsoft.com/technet/security/bulletin/ms09-045.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/ms09-045.mspx&lt;/a&gt;&lt;br /&gt; - Reason for Revision: V2.0 (November 10, 2009): Added JScript 5.7&lt;br /&gt;    on Microsoft Windows 2000 Service Pack 4 (KB975542) to the&lt;br /&gt;    Affected Software table and the Security Update Deployment section.  &lt;br /&gt; - Originally posted: September 8, 2009&lt;br /&gt; - Updated: November 10, 2009&lt;br /&gt; - Bulletin Severity Rating: Critical&lt;br /&gt; - Version: 2.0&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1738875" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/Advisories+_2F00_+Bulletins/default.aspx">Advisories / Bulletins</category></item><item><title>TechNet Webcast: Information About Microsoft November Security Bulletins</title><link>http://msmvps.com/blogs/donpatterson/archive/2009/11/10/technet-webcast-information-about-microsoft-november-security-bulletins.aspx</link><pubDate>Tue, 10 Nov 2009 18:04:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1738837</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1738837</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2009/11/10/technet-webcast-information-about-microsoft-november-security-bulletins.aspx#comments</comments><description>&lt;table border="0" cellpadding="0" cellspacing="0" width="90%"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td class="EventInfo" style="width:18%;" valign="top"&gt;&lt;span id="eventInfo_lblEvntLangDisplay"&gt;&lt;b&gt;Language(s):&lt;/b&gt;&lt;/span&gt;
        &lt;/td&gt;
&lt;td class="EventInfo"&gt;
            &lt;span id="eventInfo_lblLanguage"&gt;English.&lt;/span&gt;
        &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class="EventInfo" valign="top"&gt;
            &lt;span id="eventInfo_lblFeaturedProductsTitle"&gt;&lt;b&gt;Product(s):&lt;/b&gt;&lt;/span&gt;
        &lt;/td&gt;
&lt;td class="EventInfo"&gt;
            &lt;span id="eventInfo_lblFeaturedProducts"&gt; Security.&lt;/span&gt;
        &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class="EventInfo" valign="top"&gt;
            &lt;span id="eventInfo_lblTargetAudiencesTitle"&gt;&lt;b&gt;Audience(s): &lt;/b&gt;&lt;/span&gt;
        &lt;/td&gt;
&lt;td class="EventInfo"&gt;
            &lt;span id="eventInfo_lblTargetAudiences"&gt; IT Generalist.&lt;/span&gt;
        &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class="EventInfo" valign="top"&gt;
            
        &lt;/td&gt;
&lt;td class="EventInfo"&gt;
            
        &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class="EventInfo" valign="top"&gt;
            
        &lt;/td&gt;
&lt;td class="EventInfo"&gt;
            
        &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class="EventInfo" valign="top"&gt;
            &lt;span id="eventInfo_lblEventDurationTitle"&gt;&lt;b&gt;Duration:&lt;/b&gt;&lt;/span&gt;
        &lt;/td&gt;
&lt;td class="EventInfo"&gt;
            &lt;span id="eventInfo_lblEventDuration"&gt;90 Minutes&lt;/span&gt;
        &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class="EventInfo" valign="top"&gt;
            &lt;span id="eventInfo_lblStartDate"&gt;
            &lt;b&gt;Start Date:&lt;/b&gt;
            &lt;/span&gt;
        &lt;/td&gt;
&lt;td class="EventInfo"&gt;
&lt;div id="eventInfo_StartDatePanel"&gt;
	
                &lt;span id="eventInfo_lblStDate"&gt;Wednesday, November 11, 2009 11:00 AM Pacific Time (US &amp;amp; Canada)&lt;/span&gt;
            
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan="2"&gt;
            &amp;nbsp;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class="EventInfo" colspan="2"&gt;
            
        &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan="2" class="eventInfo"&gt;
            &lt;br /&gt;
            &lt;b&gt;&lt;span id="eventInfo_lblEventDescHeading"&gt;Event Overview&lt;/span&gt;&lt;/b&gt;
        &lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan="2"&gt;
&lt;div class="eventdetails"&gt;
&lt;p&gt;&lt;span id="eventInfo_lblEventDescription"&gt;
&lt;p&gt;&lt;span style="font-family:verdana;"&gt;On
November 11, 2009, Microsoft releases its monthly security bulletins.
Join us for a brief overview of the technical details of the November
security bulletins. We intend to address your concerns in this webcast,
therefore, most of the webcast is devoted to attendees asking questions
about the bulletins and getting answers from Microsoft security experts.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family:verdana;"&gt;&lt;b&gt;Presenters:&lt;/b&gt;
Jerry Bryant, Senior Security Program Manager Lead, Microsoft
Corporation and Adrian Stone, Senior Security Program Manager Lead,
Microsoft Corporation&lt;/span&gt;&lt;/p&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;a href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032407490&amp;amp;EventCategory=4&amp;amp;culture=en-US&amp;amp;CountryCode=US"&gt;Register Online&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1738837" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/News/default.aspx">News</category></item><item><title>Microsoft Security Bulletin(s) for November 2009</title><link>http://msmvps.com/blogs/donpatterson/archive/2009/11/10/microsoft-security-bulletin-s-for-november-2009.aspx</link><pubDate>Tue, 10 Nov 2009 17:56:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1738835</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1738835</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2009/11/10/microsoft-security-bulletin-s-for-november-2009.aspx#comments</comments><description>&lt;p&gt;&lt;b&gt;Note:&lt;/b&gt; There may be latency issues due to replication, if the page does not display keep refreshing&lt;br /&gt;&lt;br /&gt;Today Microsoft released the following Security Bulletin(s).&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Note: &lt;/b&gt;&amp;raquo;&lt;a href="http://www.microsoft.com/technet/security"&gt;www.microsoft.com/technet/security&lt;/a&gt; and &amp;raquo;&lt;a href="http://www.microsoft.com/security"&gt;www.microsoft.com/security&lt;/a&gt; are authoritative in all matters concerning Microsoft Security Bulletins! ANY e-mail, web board or newsgroup posting (including this one) should be verified by visiting these sites for official information. Microsoft never sends security or other updates as attachments. These updates must be downloaded from the microsoft.com download center or Windows Update. See the individual bulletins for details.&lt;br /&gt;&lt;br /&gt;Because some malicious messages attempt to masquerade as official Microsoft security notices, it is recommended that you physically type the URLs into your web browser and not click on the hyperlinks provided.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Bulletin Summary:&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&amp;raquo;&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-nov.mspx"&gt;www.microsoft.com/technet/securi&amp;middot;&amp;middot;&amp;middot;nov.mspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Critical (3)&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Microsoft Security Bulletin MS09-063 &lt;/b&gt;&lt;br /&gt;Vulnerability in Web Services on Devices API Could Allow Remote Code Execution (973565)&lt;br /&gt;&amp;raquo;&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-063.mspx"&gt;www.microsoft.com/technet/securi&amp;middot;&amp;middot;&amp;middot;063.mspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Microsoft Security Bulletin MS09-064 &lt;/b&gt;&lt;br /&gt;Vulnerability in License Logging Server Could Allow Remote Code Execution (974783)&lt;br /&gt;&amp;raquo;&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-064.mspx"&gt;www.microsoft.com/technet/securi&amp;middot;&amp;middot;&amp;middot;064.mspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Microsoft Security Bulletin MS09-065 &lt;/b&gt;&lt;br /&gt;Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (969947)&lt;br /&gt;&amp;raquo;&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-065.mspx"&gt;www.microsoft.com/technet/securi&amp;middot;&amp;middot;&amp;middot;065.mspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Important (3)&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Microsoft Security Bulletin MS09-066 &lt;/b&gt;&lt;br /&gt;Vulnerability in Active Directory Could Allow Denial of Service (973309)&lt;br /&gt;&amp;raquo;&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-066.mspx"&gt;www.microsoft.com/technet/securi&amp;middot;&amp;middot;&amp;middot;066.mspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Microsoft Security Bulletin MS09-067 &lt;/b&gt;&lt;br /&gt;Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (972652)&lt;br /&gt;&amp;raquo;&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-067.mspx"&gt;www.microsoft.com/technet/securi&amp;middot;&amp;middot;&amp;middot;067.mspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Microsoft Security Bulletin MS09-068 &lt;/b&gt;&lt;br /&gt;Vulnerability in Microsoft Office Word Could Allow Remote Code Execution (976307)&lt;br /&gt;&amp;raquo;&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-068.mspx"&gt;www.microsoft.com/technet/securi&amp;middot;&amp;middot;&amp;middot;068.mspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Please note that Microsoft may release bulletins out side of this schedule if we determine the need to do so.&lt;br /&gt;&lt;br /&gt;If you have any questions regarding the patch or its implementation after reading the above listed bulletin you should contact Product Support Services in the United States at 1-866-PCSafety 1-866-727-2338. International customers should contact their local subsidiary.&lt;br /&gt;&lt;br /&gt;As always, download the updates only from the vendors website - visit &lt;a href="http://www.windowsupdate.com/"&gt;Windows Update&lt;/a&gt; and &lt;a href="http://office.microsoft.com/OfficeUpdate/"&gt;Office Update&lt;/a&gt; or &lt;a href="http://update.microsoft.com/microsoftupdate"&gt;Microsoft Update&lt;/a&gt; websites. You may also get the updates thru &lt;a href="http://www.microsoft.com/athome/security/update/bulletins/automaticupdates.mspx"&gt;Automatic Updates&lt;/a&gt; functionality in Windows system.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Security Tool&lt;/b&gt;&lt;br /&gt;Find out if you are missing important Microsoft product updates by using &lt;a href="http://www.microsoft.com/technet/security/tools/mbsahome.mspx"&gt;MBSA&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1738835" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/Advisories+_2F00_+Bulletins/default.aspx">Advisories / Bulletins</category></item><item><title>Mozilla Firefox 3.5.5 Released</title><link>http://msmvps.com/blogs/donpatterson/archive/2009/11/06/mozilla-firefox-3-5-5-released.aspx</link><pubDate>Fri, 06 Nov 2009 10:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1737974</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1737974</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2009/11/06/mozilla-firefox-3-5-5-released.aspx#comments</comments><description>&lt;p&gt;&lt;em&gt;v.3.5.5, released November 5th, 2009&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://bugzilla.mozilla.org/buglist.cgi?quicksearch=ALL%20status1.9.1%3A.5-fixed"&gt;Fixes in this version&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1737974" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/News/default.aspx">News</category></item><item><title>Microsoft Security Bulletin Advance Notification for Nov. 2009</title><link>http://msmvps.com/blogs/donpatterson/archive/2009/11/05/microsoft-security-bulletin-advance-notification-for-nov-2009.aspx</link><pubDate>Thu, 05 Nov 2009 18:27:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1737850</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1737850</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2009/11/05/microsoft-security-bulletin-advance-notification-for-nov-2009.aspx#comments</comments><description>&lt;p&gt;Microsoft Security Bulletin Advance Notification issued: &lt;b&gt;November 5, 2009&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;Microsoft Security Bulletins to be issued: &lt;b&gt;November 10, 2009&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;This is an advance notification of security bulletins that Microsoft is intending to release on November 10, 2009&lt;br /&gt;&lt;br /&gt;3 rated Critical and 3 rated Important.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-nov.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/ms09-nov.mspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/donpatterson/8345.image.jpg"&gt;&lt;img src="http://msmvps.com/resized-image.ashx/__size/550x0/__key/CommunityServer.Blogs.Components.WeblogFiles/donpatterson/8345.image.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1737850" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/Advisories+_2F00_+Bulletins/default.aspx">Advisories / Bulletins</category></item><item><title>Microsoft Security Bulletin Minor Revisions - November 4, 2009</title><link>http://msmvps.com/blogs/donpatterson/archive/2009/11/05/microsoft-security-bulletin-minor-revisions-november-4-2009.aspx</link><pubDate>Thu, 05 Nov 2009 09:05:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1737757</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1737757</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2009/11/05/microsoft-security-bulletin-minor-revisions-november-4-2009.aspx#comments</comments><description>&lt;p&gt;Issued: November 4, 2009&lt;br /&gt;&lt;br /&gt;&lt;span style="text-decoration:underline;"&gt;&lt;b&gt;Summary&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The following bulletins have undergone a minor revision increment. &lt;br /&gt;Please see the appropriate bulletin for more details.&lt;br /&gt;&lt;br /&gt;  * MS09-062 - Critical&lt;br /&gt;  * MS09-061 - Critical&lt;br /&gt;  * MS09-060 - Critical&lt;br /&gt;  * MS09-055 - Critical&lt;br /&gt;  * MS09-044 - Critical&lt;br /&gt;&lt;br /&gt;&lt;span style="text-decoration:underline;"&gt;&lt;b&gt;Bulletin Information:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;* &lt;b&gt;MS09-062 - Critical&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;  - &lt;a class="moz-txt-link-freetext" href="http://www.microsoft.com/technet/security/bulletin/ms09-062.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/ms09-062.mspx&lt;/a&gt;&lt;br /&gt;  - Reason for Revision: V2.1 (November 4, 2009): Removed erroneous&lt;br /&gt;    references to Microsoft Office Visio Viewer 2007 as affected&lt;br /&gt;    software; corrected the setup switches for Microsoft .NET&lt;br /&gt;    Framework 1.1 and Microsoft .NET Framework 2.0; clarified the&lt;br /&gt;    entry, &amp;quot;If I have an installation of SQL Server, how am I&lt;br /&gt;    affected?&amp;quot; in the FAQ section; and corrected the removal&lt;br /&gt;    information for Microsoft Windows 2000.  &lt;br /&gt;  - Originally posted: October 13, 2009&lt;br /&gt;  - Updated: November 4, 2009&lt;br /&gt;  - Bulletin Severity Rating: Critical&lt;br /&gt;  - Version: 2.1&lt;br /&gt;    &lt;br /&gt;*&lt;b&gt; MS09-061 - Critical&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;  - &lt;a class="moz-txt-link-freetext" href="http://www.microsoft.com/technet/security/bulletin/ms09-061.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/ms09-061.mspx&lt;/a&gt;&lt;br /&gt;  - Reason for Revision: V1.2 (November 4, 2009): Added an entry to&lt;br /&gt;    the Frequently Asked Questions (FAQ) Related to This Security&lt;br /&gt;    Update section to explain this revision. Customers who have&lt;br /&gt;    successfully installed this update do not need to reinstall.  &lt;br /&gt;  - Originally posted: October 13, 2009&lt;br /&gt;  - Updated: November 4, 2009&lt;br /&gt;  - Bulletin Severity Rating: Critical&lt;br /&gt;  - Version: 1.2&lt;br /&gt;    &lt;br /&gt;* &lt;b&gt;MS09-060 - Critical&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;  - &lt;a class="moz-txt-link-freetext" href="http://www.microsoft.com/technet/security/bulletin/ms09-060.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/ms09-060.mspx&lt;/a&gt;&lt;br /&gt;  - Reason for Revision: V1.2 (November 4, 2009): Removed erroneous&lt;br /&gt;    references to Microsoft Office Visio Viewer 2007 as affected software. &lt;br /&gt;  - Originally posted: October 13, 2009&lt;br /&gt;  - Updated: November 4, 2009&lt;br /&gt;  - Bulletin Severity Rating: Critical&lt;br /&gt;  - Version: 1.2&lt;br /&gt;    &lt;br /&gt;* &lt;b&gt;MS09-055 - Critical&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;  - &lt;a class="moz-txt-link-freetext" href="http://www.microsoft.com/technet/security/bulletin/ms09-055.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/ms09-055.mspx&lt;/a&gt;&lt;br /&gt;  - Reason for Revision: V1.2 (November 4, 2009): Added three entries&lt;br /&gt;    in Frequently Asked Questions (FAQ) Related to This Security&lt;br /&gt;    Update to explain user options for Visio Viewer 2007 and&lt;br /&gt;    MS09-060. Also corrected the dll name for Visio Viewer in the&lt;br /&gt;    FAQ for CVE-2009-2493.  &lt;br /&gt;  - Originally posted: October 13, 2009&lt;br /&gt;  - Updated: November 4, 2009&lt;br /&gt;  - Bulletin Severity Rating: Critical&lt;br /&gt;  - Version: 1.2&lt;br /&gt;    &lt;br /&gt;* &lt;b&gt;MS09-044 - Critical&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;  - &lt;a class="moz-txt-link-freetext" href="http://www.microsoft.com/technet/security/bulletin/ms09-044.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/ms09-044.mspx&lt;/a&gt;&lt;br /&gt;  - Reason for Revision: V2.1 (November 4, 2009): Added a new known&lt;br /&gt;    issues entry to the Frequently Asked Questions (FAQ) Related&lt;br /&gt;    to This Security Update section.  &lt;br /&gt;  - Originally posted: August 11, 2009&lt;br /&gt;  - Updated: November 4, 2009&lt;br /&gt;  - Bulletin Severity Rating: Critical&lt;br /&gt;  - Version: 2.1&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1737757" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/Advisories+_2F00_+Bulletins/default.aspx">Advisories / Bulletins</category></item><item><title>Sun Releases JRE Update v1.6.0_17 - November 3, 2009</title><link>http://msmvps.com/blogs/donpatterson/archive/2009/11/03/sun-releases-jre-update-v1-6-0-17-november-3-2009.aspx</link><pubDate>Tue, 03 Nov 2009 22:55:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1737445</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1737445</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2009/11/03/sun-releases-jre-update-v1-6-0-17-november-3-2009.aspx#comments</comments><description>&lt;p&gt;Available at: &amp;raquo;&lt;a href="http://java.sun.com/javase/downloads/index.jsp"&gt;java.sun.com/javase/downloads/index.jsp&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Release notes: &amp;raquo;&lt;a href="http://java.sun.com/javase/6/webnotes/ReleaseNotes.html"&gt;java.sun.com/javase/6/webnotes/R&amp;middot;&amp;middot;&amp;middot;tes.html&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1737445" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/News/default.aspx">News</category></item><item><title>Microsoft Security Bulletin Major Revisions - November 2, 2009</title><link>http://msmvps.com/blogs/donpatterson/archive/2009/11/03/microsoft-security-bulletin-major-revisions-november-2-2009.aspx</link><pubDate>Tue, 03 Nov 2009 22:50:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1737442</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1737442</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2009/11/03/microsoft-security-bulletin-major-revisions-november-2-2009.aspx#comments</comments><description>&lt;p&gt;Issued: November 2, 2009&lt;br /&gt;&lt;br /&gt;&lt;span style="text-decoration:underline;"&gt;&lt;b&gt;Summary&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The following bulletins have undergone a major revision increment. &lt;br /&gt;Please see the appropriate bulletin for more details.&lt;br /&gt;&lt;br /&gt;  * MS09-054 - Critical&lt;br /&gt;&lt;br /&gt;&lt;span style="text-decoration:underline;"&gt;&lt;b&gt;Bulletin Information:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;* &lt;b&gt;MS09-054 - Critical&lt;/b&gt;&lt;br /&gt;&lt;br /&gt; - &lt;a class="moz-txt-link-freetext" href="http://www.microsoft.com/technet/security/bulletin/ms09-054.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/ms09-054.mspx&lt;/a&gt;&lt;br /&gt; - Reason for Revision: V2.0 (November 2, 2009): Revised to announce&lt;br /&gt;    the availability of a hotfix to address application&lt;br /&gt;    compatibility issues. Customers who have already applied this&lt;br /&gt;    update may install the hotfix from Microsoft Knowledge Base&lt;br /&gt;    Article 976749. Also corrected the log file names, spuninst&lt;br /&gt;    folder names, and registry key values for Microsoft Windows 2000.  &lt;br /&gt; - Originally posted: October 13, 2009&lt;br /&gt; - Updated: November 2, 2009&lt;br /&gt; - Bulletin Severity Rating: Critical&lt;br /&gt; - Version: 2.0&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1737442" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/Advisories+_2F00_+Bulletins/default.aspx">Advisories / Bulletins</category></item><item><title>Microsoft Security Intelligence Report (SIR)</title><link>http://msmvps.com/blogs/donpatterson/archive/2009/11/02/microsoft-security-intelligence-report-sir.aspx</link><pubDate>Mon, 02 Nov 2009 19:06:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1737132</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1737132</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2009/11/02/microsoft-security-intelligence-report-sir.aspx#comments</comments><description>&lt;p&gt;The Microsoft Security Intelligence Report (SIR) provides an in-depth
perspective on the changing threat landscape including software
vulnerability disclosures and exploits, malicious software (malware),
and potentially unwanted software. Using data derived from hundreds of
millions of Windows computers, and some of the busiest online services
on the Internet, this report also provides a detailed analysis of the
threat landscape and the changing face of threats and countermeasures
and includes updated data on privacy and breach notifications. &lt;b&gt;The seventh volume of the report is now available:&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.microsoft.com/security/portal/Threat/SIR.aspx"&gt;http://www.microsoft.com/security/portal/Threat/SIR.aspx&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1737132" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/News/default.aspx">News</category></item><item><title>Advance notification of Security Updates for Java SE </title><link>http://msmvps.com/blogs/donpatterson/archive/2009/10/31/advance-notification-of-security-updates-for-java-se.aspx</link><pubDate>Sat, 31 Oct 2009 14:27:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1736583</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1736583</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2009/10/31/advance-notification-of-security-updates-for-java-se.aspx#comments</comments><description>&lt;p&gt;On &lt;b&gt;November 3, 2009&lt;/b&gt;, Sun will release the following security updates:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;JDK and JRE 6 Update 17&lt;/li&gt;
&lt;li&gt;JDK and JRE 5.0 Update 22&lt;/li&gt;
&lt;li&gt;SDK and JRE 1.4.2_24&lt;/li&gt;
&lt;li&gt;SDK and JRE 1.3.1_27&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;a href="http://blogs.sun.com/security/entry/advance_notification_of_security_updates6"&gt;http://blogs.sun.com/security/entry/advance_notification_of_security_updates6&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1736583" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/Advisories+_2F00_+Bulletins/default.aspx">Advisories / Bulletins</category></item><item><title>Microsoft Security Bulletin Minor Revisions - October 29, 2009</title><link>http://msmvps.com/blogs/donpatterson/archive/2009/10/30/microsoft-security-bulletin-minor-revisions-october-29-2009.aspx</link><pubDate>Fri, 30 Oct 2009 08:17:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1736288</guid><dc:creator>Don</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1736288</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2009/10/30/microsoft-security-bulletin-minor-revisions-october-29-2009.aspx#comments</comments><description>&lt;p&gt;Issued: October 29, 2009&lt;br /&gt;&lt;br /&gt;&lt;span style="text-decoration:underline;"&gt;&lt;b&gt;Summary&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The following bulletins have undergone a minor revision increment. &lt;br /&gt;Please see the appropriate bulletin for more details.&lt;br /&gt;&lt;br /&gt;  * MS09-052 - Critical&lt;br /&gt;&lt;br /&gt;&lt;span style="text-decoration:underline;"&gt;&lt;b&gt;Bulletin Information:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;* &lt;b&gt;MS09-052 - Critical&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;  - &lt;a class="moz-txt-link-freetext" href="http://www.microsoft.com/technet/security/bulletin/ms09-052.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/ms09-052.mspx&lt;/a&gt;&lt;br /&gt;  - Reason for Revision: V1.1 (October 29, 2009): Removed a&lt;br /&gt;    workaround. Also added an entry in the section, Frequently&lt;br /&gt;    Asked Questions (FAQ) Related to This Security Update, to&lt;br /&gt;    clarify why some customers without Windows Media Player 6.4&lt;br /&gt;    on their systems may be offered this update.  &lt;br /&gt;  - Originally posted: October 13, 2009&lt;br /&gt;  - Updated: October 29, 2009&lt;br /&gt;  - Bulletin Severity Rating: Critical&lt;br /&gt;  - Version: 1.1&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1736288" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/Advisories+_2F00_+Bulletins/default.aspx">Advisories / Bulletins</category></item><item><title>Microsoft Security Bulletin Major Revisions - October 28, 2009</title><link>http://msmvps.com/blogs/donpatterson/archive/2009/10/28/microsoft-security-bulletin-major-revisions-october-28-2009.aspx</link><pubDate>Wed, 28 Oct 2009 22:03:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1735953</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1735953</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2009/10/28/microsoft-security-bulletin-major-revisions-october-28-2009.aspx#comments</comments><description>&lt;p&gt;Issued: October 28, 2009&lt;br /&gt;&lt;br /&gt;&lt;span style="text-decoration:underline;"&gt;&lt;b&gt;Summary&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The following bulletins have undergone a major revision increment. &lt;br /&gt;Please see the appropriate bulletin for more details.&lt;br /&gt;&lt;br /&gt;  * MS09-062 - Critical&lt;br /&gt;&lt;br /&gt;&lt;span style="text-decoration:underline;"&gt;&lt;b&gt;Bulletin Information:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;* &lt;b&gt;MS09-062 - Critical&lt;/b&gt;&lt;br /&gt;&lt;br /&gt; - &lt;a class="moz-txt-link-freetext" href="http://www.microsoft.com/technet/security/bulletin/ms09-062.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/ms09-062.mspx&lt;/a&gt;&lt;br /&gt; - Reason for Revision: V2.0 (October 28, 2009): Added Microsoft&lt;br /&gt;    Office Visio Viewer 2007, Microsoft Office Visio Viewer 2007&lt;br /&gt;    Service Pack 1, and Microsoft Office Visio Viewer 2007&lt;br /&gt;    Service Pack 2 as affected software, and added SQL Server&lt;br /&gt;    2008 and SQL Server 2008 Service Pack 1 to the Non-Affected&lt;br /&gt;    Software table. Also added notes to the Affected Software&lt;br /&gt;    table for SQL Server 2005 customers with a Reporting Services&lt;br /&gt;    SharePoint dependency; corrected the MBSA detection entries&lt;br /&gt;    for Microsoft Report Viewer; and corrected the log file and&lt;br /&gt;    registry key verification information for Microsoft Internet&lt;br /&gt;    Explorer 6 Service Pack 1 when installed on Microsoft Windows&lt;br /&gt;    2000 Service Pack 4.  &lt;br /&gt; - Originally posted: October 13, 2009&lt;br /&gt; - Updated: October 28, 2009&lt;br /&gt; - Bulletin Severity Rating: Critical&lt;br /&gt; - Version: 2.0&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1735953" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/Advisories+_2F00_+Bulletins/default.aspx">Advisories / Bulletins</category></item><item><title>Federal Deposit Insurance Corporation Warns Public of Fraudulent Email</title><link>http://msmvps.com/blogs/donpatterson/archive/2009/10/28/federal-deposit-insurance-corporation-warns-public-of-fraudulent-email.aspx</link><pubDate>Wed, 28 Oct 2009 12:33:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1735815</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1735815</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2009/10/28/federal-deposit-insurance-corporation-warns-public-of-fraudulent-email.aspx#comments</comments><description>&lt;p&gt;&lt;span style="font-family:Arial,Geneva,Helvetica;"&gt; The Federal Deposit Insurance
Corporation (FDIC) has released information warning the public about
fraudulent email messages purporting to come from the FDIC. These email
messages provides a link to a fraudulent FDIC website. Users are then
instructed to download their &amp;quot;personal FDIC Insurance File.&amp;quot;&lt;br /&gt;&lt;br /&gt;More information regarding these messages can be found in the &lt;a href="http://www.fdic.gov/consumers/consumer/alerts/index.html" target="_self"&gt;Federal Deposit Insurance Corporation&amp;#39;s Consumer Alerts&lt;/a&gt; website.&lt;br /&gt;&lt;br /&gt;Users are encouraged to take the following measures to protect themselves from this type of phishing scam:&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family:Arial,Geneva,Helvetica;"&gt;
&lt;li&gt;Do not follow unsolicited web links received in email messages.&lt;/li&gt;
&lt;li&gt;Verify the website by manually typing the URL when attempting to connect to web sites recommended in an email.&lt;/li&gt;
&lt;li&gt;Refer to the &lt;a href="http://www.us-cert.gov/cas/tips/ST04-014.html" target="_self"&gt;Avoiding Social Engineering and Phishing Attacks&lt;/a&gt; document for more information on social engineering attacks&lt;/li&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Source: &lt;a href="http://www.us-cert.gov/current/index.html#federal_deposit_insurance_corporation_warns"&gt;US-CERT&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1735815" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/Alerts/default.aspx">Alerts</category></item><item><title>Mozilla Releases Firefox 3.5.4</title><link>http://msmvps.com/blogs/donpatterson/archive/2009/10/28/mozilla-releases-firefox-3-5-4.aspx</link><pubDate>Wed, 28 Oct 2009 09:20:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1735791</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1735791</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2009/10/28/mozilla-releases-firefox-3-5-4.aspx#comments</comments><description>&lt;p&gt;Firefox 3.5.4 is &lt;a href="http://www.mozilla.com/en-US/"&gt;available for download&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/known-vulnerabilities/firefox35.html"&gt;Fixed in Firefox 3.5.4&lt;/a&gt;:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-64.html"&gt;MFSA 2009-64&lt;/a&gt; Crashes with evidence of memory corruption (rv:1.9.1.4/ 1.9.0.15)&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-63.html"&gt;MFSA 2009-63&lt;/a&gt; Upgrade media libraries to fix memory safety bugs&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-62.html"&gt;MFSA 2009-62&lt;/a&gt; Download filename spoofing with RTL override&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-61.html"&gt;MFSA 2009-61&lt;/a&gt; Cross-origin data theft through document.getSelection()&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-59.html"&gt;MFSA 2009-59&lt;/a&gt; Heap buffer overflow in string to number conversion&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-57.html"&gt;MFSA 2009-57&lt;/a&gt; Chrome privilege escalation in XPCVariant::VariantDataToJS()&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-56.html"&gt;MFSA 2009-56&lt;/a&gt; Heap buffer overflow in GIF color map parser&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-55.html"&gt;MFSA 2009-55&lt;/a&gt; Crash in proxy auto-configuration regexp parsing&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-54.html"&gt;MFSA 2009-54&lt;/a&gt; Crash with recursive web-worker calls&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-53.html"&gt;MFSA 2009-53&lt;/a&gt; Local downloaded file tampering&lt;br /&gt;&lt;a href="http://www.mozilla.org/security/announce/2009/mfsa2009-52.html"&gt;MFSA 2009-52&lt;/a&gt; Form history vulnerable to stealing&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1735791" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/News/default.aspx">News</category></item><item><title>Microsoft Security Bulletin Major Revisions - October 27, 2009</title><link>http://msmvps.com/blogs/donpatterson/archive/2009/10/28/microsoft-security-bulletin-major-revisions-october-27-2009.aspx</link><pubDate>Wed, 28 Oct 2009 09:04:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1735789</guid><dc:creator>Don</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donpatterson/rsscomments.aspx?PostID=1735789</wfw:commentRss><comments>http://msmvps.com/blogs/donpatterson/archive/2009/10/28/microsoft-security-bulletin-major-revisions-october-27-2009.aspx#comments</comments><description>&lt;p&gt;Issued: October 27, 2009&lt;br /&gt;&lt;br /&gt;&lt;span style="text-decoration:underline;"&gt;&lt;b&gt;Summary&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The following bulletins have undergone a major revision increment. &lt;br /&gt;Please see the appropriate bulletin for more details.&lt;br /&gt;&lt;br /&gt;  * MS09-043 - Critical&lt;br /&gt;&lt;br /&gt;&lt;span style="text-decoration:underline;"&gt;&lt;b&gt;Bulletin Information:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;* &lt;b&gt;MS09-043 - Critical&lt;/b&gt;&lt;br /&gt;&lt;br /&gt; - &lt;a class="moz-txt-link-freetext" href="http://www.microsoft.com/technet/security/bulletin/ms09-043.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/ms09-043.mspx&lt;/a&gt;&lt;br /&gt; - Reason for Revision: V2.0 (October 27, 2009): Bulletin revised to&lt;br /&gt;    communicate the rerelease of the update for Microsoft Office&lt;br /&gt;    2003 Service Pack 3 and Microsoft Office 2003 Web Components&lt;br /&gt;    Service Pack 3 to fix a detection issue. This is a detection&lt;br /&gt;    change only; there were no changes to the binaries. Customers&lt;br /&gt;    who have successfully updated their systems do not need to&lt;br /&gt;    reinstall this update.  &lt;br /&gt; - Originally posted: August 11, 2009&lt;br /&gt; - Updated: October 27, 2009&lt;br /&gt; - Bulletin Severity Rating: Critical&lt;br /&gt; - Version: 2.0&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1735789" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donpatterson/archive/tags/Advisories+_2F00_+Bulletins/default.aspx">Advisories / Bulletins</category></item></channel></rss>