Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Question Re Patch for Bulletin MS02-039

Status
Not open for further replies.

SheetsERR

MIS
Nov 13, 2001
66
US
How does one go about verifying that the patch (hotfix Q323875_SQL2000_SP2_en.EXE) for the Buffer Overrun issue in MS02-039 was successfully applied? My client was running on build .578. When he runs a SELECT @@VERSION now, the identical build is returned. Does he have to check individual files for version #'s or dates?

Thanks so much!
Sheetserr
 
Thanks for your help, SQLBill!

Just had my client re-apply the hotfix from Bulletin MS02-039. Per the chart, @@VERSION should reflect 8.00.655. It does not. In fact, it's still showing 8.00.578. Now, I checked out the current log and found....
"Using 'SSNETLIB.DLL' version '8.00.636'"

What's your take on this?

Thanks,
Sheetserr
 
Install the patch available from MS02-061 rather than MS02-039. It is easier to apply because it is now packaged with an installer.

Microsoft Security Bulletin MS02-061

Download link:
Terry L. Broadbent - DBA
SQL Server Page:
If you want to get the best answer for your question read faq183-874.
 
Terry,

You're right! It sure beats the old copy/paste and stop/start of other hotfixes. I installed that patch on our group's test server.

Problem is, our DBA group and systems folks haven't officially tested the cumulative patch from MS02-061 yet. I don't think I have the authority to tell our client to use that patch.

Take care!
Sheetserr
 
I guess you have to measure the risk. Is the risk of virus infection greater or less than the risk of installing the security patch? In most situations, getting a virus into the system will cause more problems or damage than installing a secuity patch. We have an established policy of applying security patches as soon as possible. I realize, however, that each site and situation is different. Terry L. Broadbent - DBA
SQL Server Page:
If you want to get the best answer for your question read faq183-874.
 
Terry,

Thanks for your responses. I agree with you.

I got an update from our Sr DBA. Apparently, there's a reason the build number isn't updated in SQL Server after running the hotfix for MS02-039. This particular hotfix doesn't require replacement of the executable, only ssnetlib.dll and ssnetlib.pdb (if it exists).

Sheetserr
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top