Patch issues: MS09-035 and KB969898
With MS09-035 it may be more of a Microsoft issue, however, with KB969898 it seems to be a reporting issue with Altiris.
I know there was already this thread that was open: https://www-secure.symantec.com/connect/forums/ms09-035-kb973544-isnt-detected-applicable
but, as stated in that thread, MS did re-release this patch and i've been trying to get this last segment for over a week now.
MS09-035 as i'm sure most know is a wonderful mess of a Visual Studio patch. They've already re-released it once. I've gotten to the point where I have 35 machines remaining that need different portions of the patch and no matter how many times i've installed it, it keeps showing up as vulnerable. I've tried through the patch cycle, manually installing it, deploying from DS, even ripping it apart and using the msp within it (as suggested by a post I saw online about a conflict when VS wasn't installed with a 'typical' install or without Visual C++). No dice. Pretty much all of them need some combination of:
vs80sp1-kb971090
vs80sp1-kb973673
vs90sp1-kb971092
vs90sp1-kb973675
As for KB969898, it seems there's a reporting issue with any 2008 servers (there are a few others on the list, but the bulk are Server 2008) It keeps saying they're vulnerable, but after some testing, the patch no longer applies or has already been applied. I have over 30 machines still listed as vulnerable for this as well.
Any help is greatly appreciated.
Rich
Comments
Check the rules
Rich,
AKB 42107 has links and information to several other articles that go into why this can happen. It is a fairly common occurrence for the rules defined in the PMImport to need a bit of tweaking, particularly around non-default installs of applications. In some cases, the rule may specify that a certain file must be version x.yyyy.zzzz.aaaa or higher to be "patched", but depending on the circumstance the file may not be present at all depending on the way the patch was installed.
Do you have an Altiris support contract? If not, you should be able to report this (after verifying using the above) to support and get an incident opened. It can be addressed in the next PMImport.
Thanks,
Kyle
Symantec Trusted Advisor
For Forum threads, please click "Mark as Solution" if answered.
For all content, please give a thumbs up if you agree with or support the post.
Would you like to reply?
Login or Register to post your comment.