Slashdot Log In
MS06-049 Causing Silent Data Corruption
Posted by
Hemos
on Mon Sep 11, 2006 09:30 AM
from the oh-who-wants-encryption-anyway dept.
from the oh-who-wants-encryption-anyway dept.
Uncle Mike writes "It looks like there is a problem with the recently released MS06-049 / KB920958 patch. If you have compression activated on any folder, then the compressed data is at risk from corruption. New files that are close to a multiple of 4K in size will have their last 4,000 bytes or so overwritten with 0xDF. Although this problem has been reported to Microsoft, as yet there appears to have been no official announcement.
"
This discussion has been archived.
No new comments can be posted.
MS06-049 Causing Silent Data Corruption
|
Log In/Create an Account
| Top
| 205 comments
| Search Discussion
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.

interesting (Score:5, Insightful)
(http://www.soulfire.cc/)
When you have a monopoly (Score:5, Insightful)
Re:When you have a monopoly (Score:5, Insightful)
>
> What're your customers going to do?
The guy at the keyboard of a Windows Vista box, using Microsoft Office at work, and Windows Media Player at home is not the customer, he is the product. The customers are Dell, AOL, media licensing conglomerates, and so on.
Re:When you have a monopoly (Score:4, Insightful)
(http://slashdot.org/ | Last Journal: Saturday April 01 2006, @07:15PM)
Microsoft may be able to leverage all those customers into a product for another customer (such as advertising or licensing DRM solutions), just like the movie theater leverages their movie watching customers into a product for advertising. Until Windows is free (as in beer), the guy using Windows is a still a customer.
Re:interesting (Score:4, Funny)
(http://www.linuxhomepage.com/?graphical=no | Last Journal: Wednesday November 24 2004, @01:09PM)
Are you this person [amazon.com] by chance?
Re:interesting (Score:4, Informative)
(http://keleus.freeshell.org/ | Last Journal: Sunday October 28, @02:17PM)
That does make a big difference, win2k is not MS' top priority.
Not that I condone their delay or lack of forsight, however.
How does something like this happen (Score:1, Insightful)
(http://www.valerieandevi.be/)
Re:How does something like this happen (Score:5, Insightful)
The programmer is not to blame here. The real question you should be asking is "What type of QA department fails to catch a bug like this?"
Re:How does something like this happen (Score:5, Funny)
(http://www.robertjohnkaper.com/)
So this is how Microsoft claims support for ODF. Clever.
Re:How does something like this happen (Score:4, Insightful)
(Last Journal: Sunday August 20 2006, @01:37PM)
Re:How does something like this happen (Score:5, Funny)
Every programmer that's ever worked on something longer than 6 or 7 lines of code? Except you, of course. I've been in the bathroom after you and am always impressed by the way it smells just like roses.
Re:You can stop now (Score:5, Funny)
Original troll never writes any bugs, so his hello world is more like this:
Re:How does something like this happen (Score:4, Insightful)
(http://www.tigershaunt.com/)
I love Linux, hate Windows, but point it, sh!t happens.
A Paradox... (Score:5, Funny)
(http://www.creimer.ws/ | Last Journal: Friday January 26 2007, @12:40PM)
How to avoid (Score:5, Informative)
(http://twoturtlelovers.blogspot.com/ | Last Journal: Friday May 25, @03:01PM)
It has been confirmed that either turning off the compression attribute (disk space permitting) OR uninstalling KB920958 will prevent further loss of data.
Re:How to avoid (Score:5, Funny)
(Last Journal: Friday March 31 2006, @11:17AM)
Re:How to avoid (Score:5, Funny)
If the RIAA et al subpoena you (Score:1, Funny)
RAID (Score:3, Funny)
Close? (Score:2)
How close is close? Is 162k close to 164k? Sounds like it is to me. From the examples in the discussion cited, it seems that anything over 4k is at risk, not just things 'near' a 4k boundary.
I would even hazzard to guess that the size matters not at all, but rather the contents of the files. If the contents match a certain pattern, the compression goes awry and adds the garbage to the end. (Accidentally overwriting the real data.)
Who wants 'encryption'?? (Score:1)
(http://www.llabmik.net/ | Last Journal: Monday March 21 2005, @04:31PM)
And BTW, I got this same story rejected last week. Fuckers.
what i think (Score:5, Funny)
MS06-049 ... (Score:1, Informative)
0xDF (Score:1)
this reminds me of a virus for the Amiga computer that replaced all the files content with the word LAMMER :)
Jorge
http://www.retroreview.com
Strange (Score:3, Funny)
More background please... (Score:5, Informative)
After a bit of research, here's what should have been included: MS06-049 [microsoft.com] was an elevation of privledge issue discovered in the kernel of Windows 2000 SP4 only. The patch for the issue, KB920958 [microsoft.com], appears to have a bug resulting in corruption of compressed folder.
The title is misleading as well. MS06-649 is the issue and KB920958 is the patch; the patch is what's causing the corruption, not the original issue.
Why even bother with compression anymore? (Score:2)
Those files were important. (Score:3, Funny)
Quick! (Score:2)
(http://del.icio.us/jvz | Last Journal: Sunday December 03 2006, @12:45PM)
Still no response from Microsoft (Score:1)
scandisk (Score:1, Flamebait)
(Last Journal: Sunday November 04, @03:38AM)
To avoid seeing this message again, get a Mac.
Forget it, it's a bug (Score:2)
(Last Journal: Monday September 25 2006, @01:19PM)
I personally haven't seen any files corrupted though. We'd see much more than a few newsgroup postings if this was a widespread problem.
Compressed files, are you kidding me?! (Score:3, Informative)
Is anyone out there seriously using disk compression in a production environment? Didn't anyone teach you guys that disk compression is a crutch and not a solution? For as long as I've been working with servers, all of my mentors have led me to believe that it is pretty much generally accepted practice not to use disk compression due to the potential for data corruption and the performance hit your servers take. If you need to compress files to save space, throw them onto some LTO or DLT media and pull them completely offline.
If you're working for a company that can't come up with more money for disk space, maybe you need to click on the Dice.com adds that are all over /. here.
Good for Microsoft (Score:1)
(http://www.hormel.com/)
MS06-049 = Lotto649 ? (Score:1)
The LAMER Exterminator !!! (Score:2)
(http://www.faqs.org/rfcs/rfc3675.html)
What kind of idiot ... (Score:2)
(http://www.faqs.org/rfcs/rfc3675.html)
... makes such massive changes to the VM of a stable kernel that allows this sort of thing to happen in the first place?
Oh wait...
classic excuse (Score:2, Funny)
Re:And this is NEWS? (Score:1)
(http://slashdot.org/ | Last Journal: Monday August 20, @10:21AM)
I've never heard of this, how about some proof?
You made a potentially libelous allegation, please back it up with some facts.
2000 only. (Score:2)
(http://aqfl.net/ | Last Journal: Wednesday July 09 2003, @01:16AM)
Re:Has anyone seen this problem? (Score:3, Funny)
(http://www.cooldark.com/ | Last Journal: Monday April 26 2004, @05:31PM)
You might want to double check.
Re:Has anyone seen this problem? (Score:2)