Microsoft KB Archive/838905

= Description of the Office 2003 security update: September 14, 2004 =

Article ID: 838905

Article Last Modified on 1/9/2007

-

APPLIES TO


 * Microsoft Office Professional Edition 2003
 * Microsoft Office Excel 2003
 * Microsoft Office FrontPage 2003
 * Microsoft Office Outlook 2003
 * Microsoft Office PowerPoint 2003
 * Microsoft Office Publisher 2003
 * Microsoft Office Word 2003
 * Microsoft Office Standard Edition 2003
 * Microsoft Office Student and Teacher Edition 2003
 * Microsoft Office Small Business Edition 2003
 * Microsoft Office Basic Edition 2003
 * Microsoft Office Access 2003

-



SUMMARY
''Microsoft has released an update to Microsoft Office 2003. This article describes how to download and how to install the Office 2003 security update: KB838905.

This update was first included in Office 2003 Service Pack 2.

For more information about the latest service pack for Office 2003, click the following article number to view the article in the Microsoft Knowledge Base:''

870924How to obtain the latest service pack for Office 2003



INTRODUCTION
The Office 2003 security update: KB838905 offers the highest level of reliability that is available for Office 2003. This update fixes a vulnerability where a specially crafted image could allow an attacker’s code to run on a user’s computer because of a security vulnerability in the graphics interpreter code.

Microsoft has released security bulletin MS04-028. The security bulletin contains all the relevant information about the security update, including file manifest information and deployment options. To view the whole security bulletin, visit the following Microsoft Web site:

http://www.microsoft.com/technet/security/bulletin/ms04-028.mspx



Client update
If you installed Office 2003 from a CD-ROM, you have the following two options:
 * Use the Microsoft Office Update Web site to automatically install all the latest updates that include all the available service packs, security updates, and updates.
 * Install only the Office 2003 security update: KB838905. To do this, follow the steps that are listed later in this article.

Note We recommend that you install the client update by using the Office Update Web site. The Office Update Web site detects your particular installation of Microsoft Office and prompts you to install exactly what you must have to make sure that your Office installation is up-to-date.

Office Update Web site
To have the Office Update Web site detect the updates that you must install on your computer, visit the following Microsoft Web site and then click Check for Updates:

http://office.microsoft.com/officeupdate/default.aspx

After detection is complete, you receive a list of recommended updates for your approval. Click Start Installation to complete the process.

Install only the Office 2003 security update: KB838905
To download and install the client update, follow these steps:  Download the update.

The following file is available for download from the Microsoft Download Center:

Download the Office 2003 Security Update: KB838905 client package now.

Release Date: September 14, 2004

For additional information about how to download Microsoft Support files, click the following article number to view the article in the Microsoft Knowledge Base:

119591 How to obtain Microsoft support files from online services

Microsoft scanned this file for viruses. Microsoft used the most current virus-detection software that was available on the date that the file was posted. The file is stored on security-enhanced servers that help to prevent any unauthorized changes to the file.

Note To obtain a localized client version of the Office 2003 security update: KB838905, visit the following Microsoft Web site:

http://www.microsoft.com/downloads/details.aspx?FamilyId=106BCF99-1BA9-4035-94C5-2A7FA90E5971

 Click Open to start the download and installation of the Office2003-kb838905-client-enu.exe file. If you are prompted to install the update, click Yes. Click Yes to accept the license agreement. Insert your Office 2003 CD-ROM when you are prompted to, and then click OK. When you receive a message that indicates that the installation was successful, click OK.</ol>

Note After you install the update, you cannot remove it. To revert to an installation before you installed the update, you must remove Office 2003 and reinstall it from the original CD-ROM.

Administrative update
If you installed Office 2003 from a server location, the server administrator must update the server location with the administrative update and deploy that update to your computer.

If you are the server administrator, follow these steps to download the administrative update: <ol> In Microsoft Windows Explorer, create a new folder and name it KB838905 .</li> Download the update.

The following file is available for download from the Microsoft Download Center:

Download the Office 2003 security update: KB838905 full-file package now.

Release Date: September 14, 2004

For additional information about how to download Microsoft Support files, click the following article number to view the article in the Microsoft Knowledge Base:

119591 How to obtain Microsoft support files from online services

Microsoft scanned this file for viruses. Microsoft used the most current virus-detection software that was available on the date that the file was posted. The file is stored on security-enhanced servers that help to prevent any unauthorized changes to the file.

Note To obtain a localized full-file version of the Office 2003 security update: KB838905, visit the following Microsoft Web site:

http://www.microsoft.com/downloads/details.aspx?FamilyId=106BCF99-1BA9-4035-94C5-2A7FA90E5971

</li> Click Save to save the Office2003-kb838905-fullfile-enu.exe file in the KB838905 folder.</li> In Windows Explorer, double-click the Office2003-kb838905-fullfile-enu.exe file.</li> If you are prompted to install the update, click Yes.</li> Click Yes to accept the license agreement.</li> In the Type the location where you want to put the extracted files box, type c:\kb838905, and then click OK.</li> If you are familiar with the procedure for updating your administrative installation, click Start, click Run, type the following command in the Open box:

msiexec /a \ /p c:\kb838905\  shortfilenames=true

In this command,  is the path of your administrative installation point for Office 2003--for example, C:\Office2003,   is the .msi database package for the Office 2003 product--for example, Pro11.msi, and   is the name of the administrative update--for example, gdiplus-FullFile-GLB.msp.

Note You can append the /qb+ switch to the command line so that the Office 2003 Administrative Installation dialog box and the End User License Agreement dialog box do not appear.</li> To deploy the update to the client workstations, click Start, click Run, type the following command in the Open box:

msiexec /i \  reinstall=  REINSTALLMODE=VOMU

In this command,  is the path of your administrative installation point for Office 2003--for example, C:\Office2003,   is the MSI database package for the Office 2003 product--for example, Pro11.msi, and   is the case-sensitive list of feature names that must be reinstalled for the update. To install all the features, you can use the REINSTALL=ALL value, or you can install the following feature:

ProductNonBootFiles

</li></ol>

For additional information about how to update your administrative installation and how to deploy to client workstations, click the following article number to view the article in the Microsoft Knowledge Base:

829197 How to install updates to an administrative installation of Office 2003

Determine whether the update is installed
The update contains updated versions of the following files: <pre class="fixed_text">  File name    Version ---  Gdiplus.dll  6.0.3264.0 To determine the version of the Gdiplus.dll file that is installed on your computer, follow these steps.

Note Because there are several versions of Microsoft Windows, the following steps may be different on your computer. If they are, see your product documentation to complete these steps.
 * 1) Click Start, and then click Search.
 * 2) In the Search Results pane, click All files and folders under Search Companion.
 * 3) In the All or part of the file name box, type Gdiplus.dll, and then click Search.
 * 4) In the list of files, right-click Gdiplus.dll, and then click Properties.
 * 5) On the Version tab, determine the version of the Gdiplus.dll file that is installed on your computer.

Note If the Office 2003 security update: KB838905 is already installed on your computer, you receive the following error message when you try to install the Office 2003 security update: KB838905:

This update has already been applied or is included in an update that has already been applied.

List of issues that are fixed by the update
The Office 2003 security update: KB838905 fixes the issues that are described in the following Microsoft Knowledge Base articles:

837256 Description of Office 2003 hotfix package: March 19, 2004

831939 Description of the Office 2003 hotfix package: January 29, 2004

The Office 2003 security update: KB838905 fixes the following issue that was not previously documented in the Microsoft Knowledge Base:
 * Office program quits unexpected when you insert a JPEG image

When you insert a JPEG image into an Office program, the Office program may quit unexpectedly and arbitrary code could run.

<div class="references_section">