Skip Navigation

  • Home
  • Contact us
  • FAQ
  • Glossary
  • Public key
  • Sitemap
  • Cymraeg
  • What's new
CPNI - Centre for the Protection of National Infastructure

Advanced search

  • About CPNI
  • The threats
  • Security planning
  • Methods of attack
  • Protecting your assets
  • Products and services
    • CSIRTUK advisories
      • Advisories archive
    • General protective security publications
    • InfoSec briefings
    • InfoSec technical notes
    • InfoSec vulnerability disclosures
    • Good practice guidelines
    • Viewpoints
    • Information exchanges
    • Risk Management Delivery Group
  • Research
Home > Products and services > CSIRTUK advisories > Advisories archive > September 2007 > 3406 - Microsoft Security Bulletin MS07-042 Re-Release

September 2007

3406 - Microsoft Security Bulletin MS07-042 Re-Release

ID: 3406
Date: 28 September 2007 10:07

Title: 3406 - Microsoft Security Bulletin MS07-042 Re-Release
Abstract: Major revision of MS07-042 Security Bulletin
Vendors affected:Microsoft
Applications affected:Word, Excel, and PowerPoint 2007
Availability of fix: Available
Type of fix: Patch
Source: Microsoft Corporation
Reliability of source: Trusted
Source URL: http://www.microsoft.com/technet/security/bulletin/ms07-042.mspx

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

********************************************************************
Title: Microsoft Security Bulletin Re-Release
Issued: September 27, 2007
********************************************************************

Summary
=======
The following bulletin has undergone a major revision increment.
Please see the appropriate bulletin for more details.

  * MS07-042 - Critical

Bulletin Information:
=====================

* MS07-042 - Critical

 - http://www.microsoft.com/technet/security/bulletin/ms07-042.mspx
 - Reason for Revision: Bulletin Updated: Added Microsoft Office
    Compatibility Pack for Word, Excel, and PowerPoint 2007 File
    Formats and Microsoft Expression Web as affected products.
    The Bulletin has also been updated to inform customers that a
    potential reliability issue exists in applications that have
    installed Microsoft XML Core Services 4.0 on Windows Vista,
    which can be addressed by applying the download available in
    Microsoft Knowledge Base Article 941833. 
 - Originally posted: August 14, 2007
 - Updated: September 27, 2007
 - Bulletin Severity Rating: Critical
 - Version: 2.0
       

Other Information
=================

Recognize and avoid fraudulent e-mail to Microsoft customers:
=============================================================
If you receive an e-mail message that claims to be distributing a Microsoft security update, it is a hoax that may contain malware or pointers to malicious Web sites. Microsoft does not distribute security updates via e-mail.

The Microsoft Security Response Center (MSRC) uses PGP to digitally sign all security notifications. However, it is not required to read security notifications, security bulletins, security advisories, or install security updates. You can obtain the MSRC public PGP key at https://www.microsoft.com/technet/security/bulletin/pgp.mspx.

To receive automatic notifications whenever Microsoft Security Bulletins and Microsoft Security Advisories are issued or revised, subscribe to Microsoft Technical Security Notifications on http://www.microsoft.com/technet/security/bulletin/notify.mspx.


********************************************************************
THE INFORMATION PROVIDED IN THIS MICROSOFT COMMUNICATION IS
PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT
DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING
THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
PURPOSE.
IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE
LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT,
INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL
DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN
ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY
FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING
LIMITATION MAY NOT APPLY.
********************************************************************

-----BEGIN PGP SIGNATURE-----
Version: PGP 8.1

iQIVAwUBRvwlPIlDklrxMhdPAQKcTg/+LQ2V2lF02wcdzi3mKC/b5zCOfRTsjdvD
OBcDcYMitsRSwuRhgYPWzKVVXBn3g4fVCh0lnONGuWBVa+YeEsdm69IbQAS8ECZY
iYrkNIRx5zlTsAz+nhB02gcpCgbrbRUs1di9X/XbvG/jBQ7GO6kxDvOZ57KxOwLH
lZwr1uGKVRfh+35UFT7tFwQPLPJVmKVOMsAHV3v1ZAjJAWZTh7WL3aOhTk1DKb+o
SWn8/BnPrqY4yCM4SA7JA5lXCXWNxlUxpx9JOIU7dHe+2MHy+cVaHnVgskmRglA7
Bgh8+LyBZbncaSuYqpkgi/UvMmWMeU9jKS/JtDL9GKtJ/qUMbuu2AFqmlc58i5Li
Jv+PGgiCIwZkieCgAHOEuaHBZ4Bd9UquImPIMYNH075nzsNbEVt6H59Ib7gUyDbV
Ct68XiRbmLiM/wAqvSRf+BMy0aJUv7SwVynLZmi+kONKT9/VzVK4FloYOEDtaEIA
4kpgdr/fyZTT6ac6KLnhF0rPcKdQ/ouXIcOfYukYtrBgD2Dek390+LRdXRQ4OiaA
RnO8sGqmK4K//Ki0uxYAka4HDwDDZv1PnJdJ6P5gqn9cLEOP4xJhmQ5NoXSgkUs4
NMPwFqrhboB5EePQ0+1ysYAa6arPV7FxPKDSiujOMT/WxOaDc7R47OYiXx7Zc0Eb
svjWFoRlzX0=
=2aRP
-----END PGP SIGNATURE-----


 

This advisory contains information released by the original author. Some of the information may have changed since it was released. If the issue affects you, it may be prudent to retrieve the advisory from the site of the original source to ensure that you receive the most current information concerning that problem. Reference to any specific commercial product, process, or service by trade name, trademark manufacturer, or otherwise, does not constitute or imply its endorsement, recommendation, or favouring by CPNI.

The views and opinions of authors expressed within this notice shall not be used for advertising or product endorsement purposes. CPNI shall not accept responsibility for any errors or omissions contained within this advisory. In particular, they shall not be liable for any loss or damage whatsoever, arising from or in connection with the usage of information contained within this advisory.

CSIRTUK is a member of the Forum of Incident Response and Security Teams (FIRST) and has contacts with other international Incident Response Teams (IRTs) in order to foster cooperation and coordination in incident prevention, to prompt rapid reaction to incidents, and to promote information sharing amongst its members and the community at large.

  • Accessibility |
  • Terms and conditions |
  • Privacy statement |
  • Data protection act |
  • Freedom of information |