MS Bulletins - July 2015

classic Classic list List threaded Threaded
7 messages Options
Reply | Threaded
Open this post in threaded view
|  
Report Content as Inappropriate

MS Bulletins - July 2015

Kumarswamy S
Hi,

      Please find the attached bulletins for the month of July 2015.

      ms15-058-mitre.xml contains two updates:
         - def:21029 is updated to check version range for Service Pack.
         - def:15044, def:21029, def:12454 and def:15497 are updated
because time format was giving validation error.


Regards
Kumarswamy S
Saner Personal
A free vulnerability mitigation
software. Build strong defense.
http://www.secpod.com/saner-personal.html

To unsubscribe, send an email message to [hidden email] with
SIGNOFF OVAL-DISCUSSION-LIST
in the BODY of the message.  If you have difficulties, write to [hidden email].

ms15-058-mitre.xml (92K) Download Attachment
ms15-065-066-mitre.xml (381K) Download Attachment
ms15-067-mitre.xml (30K) Download Attachment
ms15-068-mitre.xml (41K) Download Attachment
ms15-069-mitre.xml (68K) Download Attachment
ms15-071-mitre.xml (64K) Download Attachment
ms15-072-mitre.xml (89K) Download Attachment
ms15-073-mitre.xml (114K) Download Attachment
ms15-074-mitre.xml (89K) Download Attachment
ms15-075-mitre.xml (97K) Download Attachment
ms15-076-mitre.xml (89K) Download Attachment
ms15-077-mitre.xml (80K) Download Attachment
ms15-078-mitre.xml (62K) Download Attachment
Reply | Threaded
Open this post in threaded view
|  
Report Content as Inappropriate

Re: MS Bulletins - July 2015

mcokus
Hi Kumarswamy,

Thank you for your submissions.  They have been processed and are in the repository.  The static download page should be updated shortly.

--mike


Mike Cokus
Systems Engineer
The MITRE Corporation
+1.757.896.8553
+1.757.826.8316 (fax)
[hidden email]

>-----Original Message-----
>From: Kumarswamy S [mailto:[hidden email]]
>Sent: Wednesday, July 22, 2015 10:11 AM
>To: oval-discussion-list OVAL Discussion List/Closed Public Discussi <oval-
>[hidden email]>
>Subject: [OVAL-DISCUSSION-LIST] MS Bulletins - July 2015
>
>Hi,
>
>      Please find the attached bulletins for the month of July 2015.
>
>      ms15-058-mitre.xml contains two updates:
>         - def:21029 is updated to check version range for Service Pack.
>         - def:15044, def:21029, def:12454 and def:15497 are updated
>because time format was giving validation error.
>
>
>Regards
>Kumarswamy S
>Saner Personal
>A free vulnerability mitigation
>software. Build strong defense.
>http://www.secpod.com/saner-personal.html
>
>To unsubscribe, send an email message to [hidden email] with
>SIGNOFF OVAL-DISCUSSION-LIST
>in the BODY of the message.  If you have difficulties, write to OVAL-
>[hidden email].
Reply | Threaded
Open this post in threaded view
|  
Report Content as Inappropriate

Re: MS Bulletins - July 2015

Maria Mikhno
Hello,
What about MS 15-067? It has not been processed yet but the other content is in the repository already.

With Best Regards,
Maria Mikhno
ALTEX-SOFT
[hidden email] | altx-soft.ru | altex-soft.com

----- Исходное сообщение -----
От: "Cokus, Michael S." <[hidden email]>
Кому: "OVAL-DISCUSSION-LIST" <[hidden email]>
Отправленные: Четверг, 23 Июль 2015 г 18:44:43
Тема: Re: [OVAL-DISCUSSION-LIST] MS Bulletins - July 2015

Hi Kumarswamy,

Thank you for your submissions.  They have been processed and are in the repository.  The static download page should be updated shortly.

--mike


Mike Cokus
Systems Engineer
The MITRE Corporation
+1.757.896.8553
+1.757.826.8316 (fax)
[hidden email]

>-----Original Message-----
>From: Kumarswamy S [mailto:[hidden email]]
>Sent: Wednesday, July 22, 2015 10:11 AM
>To: oval-discussion-list OVAL Discussion List/Closed Public Discussi <oval-
>[hidden email]>
>Subject: [OVAL-DISCUSSION-LIST] MS Bulletins - July 2015
>
>Hi,
>
>      Please find the attached bulletins for the month of July 2015.
>
>      ms15-058-mitre.xml contains two updates:
>         - def:21029 is updated to check version range for Service Pack.
>         - def:15044, def:21029, def:12454 and def:15497 are updated
>because time format was giving validation error.
>
>
>Regards
>Kumarswamy S
>Saner Personal
>A free vulnerability mitigation
>software. Build strong defense.
>http://www.secpod.com/saner-personal.html
>
>To unsubscribe, send an email message to [hidden email] with
>SIGNOFF OVAL-DISCUSSION-LIST
>in the BODY of the message.  If you have difficulties, write to OVAL-
>[hidden email].

To unsubscribe, send an email message to [hidden email] with
SIGNOFF OVAL-DISCUSSION-LIST
in the BODY of the message.  If you have difficulties, write to [hidden email].
Reply | Threaded
Open this post in threaded view
|  
Report Content as Inappropriate

Re: MS Bulletins - July 2015

mcokus
Hi Maria,

This was due to my mistake; thank you for finding and telling me about the error.  I have corrected this and the submission for MS 15-067 should now be in the repository.

Thanks,

--mike

Mike Cokus
Systems Engineer
The MITRE Corporation
+1.757.896.8553
+1.757.826.8316 (fax)
[hidden email]

>-----Original Message-----
>From: Maria Mikhno [mailto:[hidden email]]
>Sent: Friday, July 24, 2015 4:59 AM
>To: oval-discussion-list OVAL Discussion List/Closed Public Discussi <oval-
>[hidden email]>
>Subject: Re: [OVAL-DISCUSSION-LIST] MS Bulletins - July 2015
>
>Hello,
>What about MS 15-067? It has not been processed yet but the other content
>is in the repository already.
>
>With Best Regards,
>Maria Mikhno
>ALTEX-SOFT
>[hidden email] | altx-soft.ru | altex-soft.com
>
>----- Исходное сообщение -----
>От: "Cokus, Michael S." <[hidden email]>
>Кому: "OVAL-DISCUSSION-LIST" <OVAL-DISCUSSION-
>[hidden email]>
>Отправленные: Четверг, 23 Июль 2015 г 18:44:43
>Тема: Re: [OVAL-DISCUSSION-LIST] MS Bulletins - July 2015
>
>Hi Kumarswamy,
>
>Thank you for your submissions.  They have been processed and are in the
>repository.  The static download page should be updated shortly.
>
>--mike
>
>
>Mike Cokus
>Systems Engineer
>The MITRE Corporation
>+1.757.896.8553
>+1.757.826.8316 (fax)
>[hidden email]
>
>>-----Original Message-----
>>From: Kumarswamy S [mailto:[hidden email]]
>>Sent: Wednesday, July 22, 2015 10:11 AM
>>To: oval-discussion-list OVAL Discussion List/Closed Public Discussi <oval-
>>[hidden email]>
>>Subject: [OVAL-DISCUSSION-LIST] MS Bulletins - July 2015
>>
>>Hi,
>>
>>      Please find the attached bulletins for the month of July 2015.
>>
>>      ms15-058-mitre.xml contains two updates:
>>         - def:21029 is updated to check version range for Service Pack.
>>         - def:15044, def:21029, def:12454 and def:15497 are updated
>>because time format was giving validation error.
>>
>>
>>Regards
>>Kumarswamy S
>>Saner Personal
>>A free vulnerability mitigation
>>software. Build strong defense.
>>http://www.secpod.com/saner-personal.html
>>
>>To unsubscribe, send an email message to [hidden email] with
>>SIGNOFF OVAL-DISCUSSION-LIST
>>in the BODY of the message.  If you have difficulties, write to OVAL-
>>[hidden email].
>
>To unsubscribe, send an email message to [hidden email] with
>SIGNOFF OVAL-DISCUSSION-LIST
>in the BODY of the message.  If you have difficulties, write to OVAL-
>[hidden email].
Reply | Threaded
Open this post in threaded view
|  
Report Content as Inappropriate

Re: MS Bulletins - July 2015

Maria Mikhno
Hello,

I have a question about two vulnerabilities: CVE-2015-2368 and CVE-2015-2369 (criteria Win 7 / R2)

CVE-2015-2368 fixed with KB3070738 on Win 7 / R2 and CVE-2015-2369 fixed with KB3067903 on Win 7 / R2

In https://support.microsoft.com/en-us/kb/3067903 Cewmdm.dll should be checked.

In https://support.microsoft.com/en-us/kb/3070738 wksprt.exe should be checked.

Why do you check both files in both vulnerabilities?

There are two files in attachment which are more correct in my opinion.

With Best Regards,
Maria Mikhno
ALTEX-SOFT
[hidden email] | altx-soft.ru | altex-soft.com

----- Исходное сообщение -----
От: "Cokus, Michael S." <[hidden email]>
Кому: "OVAL-DISCUSSION-LIST" <[hidden email]>
Отправленные: Пятница, 24 Июль 2015 г 15:24:22
Тема: Re: [OVAL-DISCUSSION-LIST] MS Bulletins - July 2015

Hi Maria,

This was due to my mistake; thank you for finding and telling me about the error.  I have corrected this and the submission for MS 15-067 should now be in the repository.

Thanks,

--mike

Mike Cokus
Systems Engineer
The MITRE Corporation
+1.757.896.8553
+1.757.826.8316 (fax)
[hidden email]

>-----Original Message-----
>From: Maria Mikhno [mailto:[hidden email]]
>Sent: Friday, July 24, 2015 4:59 AM
>To: oval-discussion-list OVAL Discussion List/Closed Public Discussi <oval-
>[hidden email]>
>Subject: Re: [OVAL-DISCUSSION-LIST] MS Bulletins - July 2015
>
>Hello,
>What about MS 15-067? It has not been processed yet but the other content
>is in the repository already.
>
>With Best Regards,
>Maria Mikhno
>ALTEX-SOFT
>[hidden email] | altx-soft.ru | altex-soft.com
>
>----- Исходное сообщение -----
>От: "Cokus, Michael S." <[hidden email]>
>Кому: "OVAL-DISCUSSION-LIST" <OVAL-DISCUSSION-
>[hidden email]>
>Отправленные: Четверг, 23 Июль 2015 г 18:44:43
>Тема: Re: [OVAL-DISCUSSION-LIST] MS Bulletins - July 2015
>
>Hi Kumarswamy,
>
>Thank you for your submissions.  They have been processed and are in the
>repository.  The static download page should be updated shortly.
>
>--mike
>
>
>Mike Cokus
>Systems Engineer
>The MITRE Corporation
>+1.757.896.8553
>+1.757.826.8316 (fax)
>[hidden email]
>
>>-----Original Message-----
>>From: Kumarswamy S [mailto:[hidden email]]
>>Sent: Wednesday, July 22, 2015 10:11 AM
>>To: oval-discussion-list OVAL Discussion List/Closed Public Discussi <oval-
>>[hidden email]>
>>Subject: [OVAL-DISCUSSION-LIST] MS Bulletins - July 2015
>>
>>Hi,
>>
>>      Please find the attached bulletins for the month of July 2015.
>>
>>      ms15-058-mitre.xml contains two updates:
>>         - def:21029 is updated to check version range for Service Pack.
>>         - def:15044, def:21029, def:12454 and def:15497 are updated
>>because time format was giving validation error.
>>
>>
>>Regards
>>Kumarswamy S
>>Saner Personal
>>A free vulnerability mitigation
>>software. Build strong defense.
>>http://www.secpod.com/saner-personal.html
>>
>>To unsubscribe, send an email message to [hidden email] with
>>SIGNOFF OVAL-DISCUSSION-LIST
>>in the BODY of the message.  If you have difficulties, write to OVAL-
>>[hidden email].
>
>To unsubscribe, send an email message to [hidden email] with
>SIGNOFF OVAL-DISCUSSION-LIST
>in the BODY of the message.  If you have difficulties, write to OVAL-
>[hidden email].
To unsubscribe, send an email message to [hidden email] with
SIGNOFF OVAL-DISCUSSION-LIST
in the BODY of the message.  If you have difficulties, write to [hidden email].

oval-org.mitre.oval-def-29149.xml (75K) Download Attachment
oval-org.mitre.oval-def-29280 (1).xml (44K) Download Attachment
Reply | Threaded
Open this post in threaded view
|  
Report Content as Inappropriate

Re: MS Bulletins - July 2015

Kumarswamy S
Hi Maria,

             The update you proposed for CVE-2015-2368 and CVE-2015-2369
is proper.

Regards
Kumarswamy S
Saner Personal
A free vulnerability mitigation
software. Build strong defense.
http://www.secpod.com/saner-personal.html

> Hello,
>
> I have a question about two vulnerabilities:  (criteria Win 7 / R2)
>
> CVE-2015-2368 fixed with KB3070738 on Win 7 / R2 and CVE-2015-2369 fixed with KB3067903 on Win 7 / R2
>
> In https://support.microsoft.com/en-us/kb/3067903 Cewmdm.dll should be checked.
>
> In https://support.microsoft.com/en-us/kb/3070738 wksprt.exe should be checked.
>
> Why do you check both files in both vulnerabilities?
>
> There are two files in attachment which are more correct in my opinion.
>
> With Best Regards,
> Maria Mikhno
> ALTEX-SOFT
> [hidden email] | altx-soft.ru | altex-soft.com
>
> ----- Исходное сообщение -----
> От: "Cokus, Michael S." <[hidden email]>
> Кому: "OVAL-DISCUSSION-LIST" <[hidden email]>
> Отправленные: Пятница, 24 Июль 2015 г 15:24:22
> Тема: Re: [OVAL-DISCUSSION-LIST] MS Bulletins - July 2015
>
> Hi Maria,
>
> This was due to my mistake; thank you for finding and telling me about the error.  I have corrected this and the submission for MS 15-067 should now be in the repository.
>
> Thanks,
>
> --mike
>
> Mike Cokus
> Systems Engineer
> The MITRE Corporation
> +1.757.896.8553
> +1.757.826.8316 (fax)
> [hidden email]
>
>> -----Original Message-----
>> From: Maria Mikhno [mailto:[hidden email]]
>> Sent: Friday, July 24, 2015 4:59 AM
>> To: oval-discussion-list OVAL Discussion List/Closed Public Discussi <oval-
>> [hidden email]>
>> Subject: Re: [OVAL-DISCUSSION-LIST] MS Bulletins - July 2015
>>
>> Hello,
>> What about MS 15-067? It has not been processed yet but the other content
>> is in the repository already.
>>
>> With Best Regards,
>> Maria Mikhno
>> ALTEX-SOFT
>> [hidden email] | altx-soft.ru | altex-soft.com
>>
>> ----- Исходное сообщение -----
>> От: "Cokus, Michael S." <[hidden email]>
>> Кому: "OVAL-DISCUSSION-LIST" <OVAL-DISCUSSION-
>> [hidden email]>
>> Отправленные: Четверг, 23 Июль 2015 г 18:44:43
>> Тема: Re: [OVAL-DISCUSSION-LIST] MS Bulletins - July 2015
>>
>> Hi Kumarswamy,
>>
>> Thank you for your submissions.  They have been processed and are in the
>> repository.  The static download page should be updated shortly.
>>
>> --mike
>>
>>
>> Mike Cokus
>> Systems Engineer
>> The MITRE Corporation
>> +1.757.896.8553
>> +1.757.826.8316 (fax)
>> [hidden email]
>>
>>> -----Original Message-----
>>> From: Kumarswamy S [mailto:[hidden email]]
>>> Sent: Wednesday, July 22, 2015 10:11 AM
>>> To: oval-discussion-list OVAL Discussion List/Closed Public Discussi <oval-
>>> [hidden email]>
>>> Subject: [OVAL-DISCUSSION-LIST] MS Bulletins - July 2015
>>>
>>> Hi,
>>>
>>>       Please find the attached bulletins for the month of July 2015.
>>>
>>>       ms15-058-mitre.xml contains two updates:
>>>          - def:21029 is updated to check version range for Service Pack.
>>>          - def:15044, def:21029, def:12454 and def:15497 are updated
>>> because time format was giving validation error.
>>>
>>>
>>> Regards
>>> Kumarswamy S
>>> Saner Personal
>>> A free vulnerability mitigation
>>> software. Build strong defense.
>>> http://www.secpod.com/saner-personal.html
>>>
>>> To unsubscribe, send an email message to [hidden email] with
>>> SIGNOFF OVAL-DISCUSSION-LIST
>>> in the BODY of the message.  If you have difficulties, write to OVAL-
>>> [hidden email].
>> To unsubscribe, send an email message to [hidden email] with
>> SIGNOFF OVAL-DISCUSSION-LIST
>> in the BODY of the message.  If you have difficulties, write to OVAL-
>> [hidden email].

To unsubscribe, send an email message to [hidden email] with
SIGNOFF OVAL-DISCUSSION-LIST
in the BODY of the message.  If you have difficulties, write to [hidden email].
Reply | Threaded
Open this post in threaded view
|  
Report Content as Inappropriate

Re: MS Bulletins - July 2015

mcokus
Hello Maria

Thank you for your submissions.  They have been processed and are in the repository.  The static download page should be updated shortly.

--mike


Mike Cokus
Systems Engineer
The MITRE Corporation
+1.757.896.8553
+1.757.826.8316 (fax)
[hidden email]

>-----Original Message-----
>From: Kumarswamy S [mailto:[hidden email]]
>Sent: Monday, July 27, 2015 3:56 AM
>To: oval-discussion-list OVAL Discussion List/Closed Public Discussi <oval-
>[hidden email]>
>Subject: Re: [OVAL-DISCUSSION-LIST] MS Bulletins - July 2015
>
>Hi Maria,
>
>             The update you proposed for CVE-2015-2368 and CVE-2015-2369
>is proper.
>
>Regards
>Kumarswamy S
>Saner Personal
>A free vulnerability mitigation
>software. Build strong defense.
>http://www.secpod.com/saner-personal.html
>
>> Hello,
>>
>> I have a question about two vulnerabilities:  (criteria Win 7 / R2)
>>
>> CVE-2015-2368 fixed with KB3070738 on Win 7 / R2 and CVE-2015-2369 fixed
>with KB3067903 on Win 7 / R2
>>
>> In https://support.microsoft.com/en-us/kb/3067903 Cewmdm.dll should be
>checked.
>>
>> In https://support.microsoft.com/en-us/kb/3070738 wksprt.exe should be
>checked.
>>
>> Why do you check both files in both vulnerabilities?
>>
>> There are two files in attachment which are more correct in my opinion.
>>
>> With Best Regards,
>> Maria Mikhno
>> ALTEX-SOFT
>> [hidden email] | altx-soft.ru | altex-soft.com
>>
>> ----- Исходное сообщение -----
>> От: "Cokus, Michael S." <[hidden email]>
>> Кому: "OVAL-DISCUSSION-LIST" <OVAL-DISCUSSION-
>[hidden email]>
>> Отправленные: Пятница, 24 Июль 2015 г 15:24:22
>> Тема: Re: [OVAL-DISCUSSION-LIST] MS Bulletins - July 2015
>>
>> Hi Maria,
>>
>> This was due to my mistake; thank you for finding and telling me about the
>error.  I have corrected this and the submission for MS 15-067 should now be
>in the repository.
>>
>> Thanks,
>>
>> --mike
>>
>> Mike Cokus
>> Systems Engineer
>> The MITRE Corporation
>> +1.757.896.8553
>> +1.757.826.8316 (fax)
>> [hidden email]
>>
>>> -----Original Message-----
>>> From: Maria Mikhno [mailto:[hidden email]]
>>> Sent: Friday, July 24, 2015 4:59 AM
>>> To: oval-discussion-list OVAL Discussion List/Closed Public Discussi <oval-
>>> [hidden email]>
>>> Subject: Re: [OVAL-DISCUSSION-LIST] MS Bulletins - July 2015
>>>
>>> Hello,
>>> What about MS 15-067? It has not been processed yet but the other
>content
>>> is in the repository already.
>>>
>>> With Best Regards,
>>> Maria Mikhno
>>> ALTEX-SOFT
>>> [hidden email] | altx-soft.ru | altex-soft.com
>>>
>>> ----- Исходное сообщение -----
>>> От: "Cokus, Michael S." <[hidden email]>
>>> Кому: "OVAL-DISCUSSION-LIST" <OVAL-DISCUSSION-
>>> [hidden email]>
>>> Отправленные: Четверг, 23 Июль 2015 г 18:44:43
>>> Тема: Re: [OVAL-DISCUSSION-LIST] MS Bulletins - July 2015
>>>
>>> Hi Kumarswamy,
>>>
>>> Thank you for your submissions.  They have been processed and are in the
>>> repository.  The static download page should be updated shortly.
>>>
>>> --mike
>>>
>>>
>>> Mike Cokus
>>> Systems Engineer
>>> The MITRE Corporation
>>> +1.757.896.8553
>>> +1.757.826.8316 (fax)
>>> [hidden email]
>>>
>>>> -----Original Message-----
>>>> From: Kumarswamy S [mailto:[hidden email]]
>>>> Sent: Wednesday, July 22, 2015 10:11 AM
>>>> To: oval-discussion-list OVAL Discussion List/Closed Public Discussi <oval-
>>>> [hidden email]>
>>>> Subject: [OVAL-DISCUSSION-LIST] MS Bulletins - July 2015
>>>>
>>>> Hi,
>>>>
>>>>       Please find the attached bulletins for the month of July 2015.
>>>>
>>>>       ms15-058-mitre.xml contains two updates:
>>>>          - def:21029 is updated to check version range for Service Pack.
>>>>          - def:15044, def:21029, def:12454 and def:15497 are updated
>>>> because time format was giving validation error.
>>>>
>>>>
>>>> Regards
>>>> Kumarswamy S
>>>> Saner Personal
>>>> A free vulnerability mitigation
>>>> software. Build strong defense.
>>>> http://www.secpod.com/saner-personal.html
>>>>
>>>> To unsubscribe, send an email message to [hidden email]
>with
>>>> SIGNOFF OVAL-DISCUSSION-LIST
>>>> in the BODY of the message.  If you have difficulties, write to OVAL-
>>>> [hidden email].
>>> To unsubscribe, send an email message to [hidden email]
>with
>>> SIGNOFF OVAL-DISCUSSION-LIST
>>> in the BODY of the message.  If you have difficulties, write to OVAL-
>>> [hidden email].
>
>To unsubscribe, send an email message to [hidden email] with
>SIGNOFF OVAL-DISCUSSION-LIST
>in the BODY of the message.  If you have difficulties, write to OVAL-
>[hidden email].
Loading...