v23 patches

classic Classic list List threaded Threaded
8 messages Options
Reply | Threaded
Open this post in threaded view
|

v23 patches

Maguin, Eugene

We are getting 23 installed and I want to check on the patch level for 23 (32 bit Windows OS). I swam around and found my way to fix central and it looks as though there are no patches for 23, meaning 23.0.0 is the current version. Is this true?

 

On my way to fix central I passed through a page describing a schedule for patch releases; however, I don’t know that it applied to spss statistics. Is there such a schedule and what are the dates?

Thanks, Gene Maguin

===================== To manage your subscription to SPSSX-L, send a message to [hidden email] (not to SPSSX-L), with no body text except the command. To leave the list, send the command SIGNOFF SPSSX-L For a list of commands to manage subscriptions, send the command INFO REFCARD
Reply | Threaded
Open this post in threaded view
|

Re: v23 patches

Bruce Weaver
Administrator
Gene, I just found your message in the archives, because we are also now due to start using v23.  As far as I can tell, there are still no patches for v23.

http://www-01.ibm.com/software/analytics/support/fixes/pbi_releases.html#stats_fixlists



Maguin, Eugene wrote
We are getting 23 installed and I want to check on the patch level for 23 (32 bit Windows OS). I swam around and found my way to fix central and it looks as though there are no patches for 23, meaning 23.0.0 is the current version. Is this true?

On my way to fix central I passed through a page describing a schedule for patch releases; however, I don't know that it applied to spss statistics. Is there such a schedule and what are the dates?
Thanks, Gene Maguin

=====================
To manage your subscription to SPSSX-L, send a message to
[hidden email] (not to SPSSX-L), with no body text except the
command. To leave the list, send the command
SIGNOFF SPSSX-L
For a list of commands to manage subscriptions, send the command
INFO REFCARD
--
Bruce Weaver
bweaver@lakeheadu.ca
http://sites.google.com/a/lakeheadu.ca/bweaver/

"When all else fails, RTFM."

PLEASE NOTE THE FOLLOWING: 
1. My Hotmail account is not monitored regularly. To send me an e-mail, please use the address shown above.
2. The SPSSX Discussion forum on Nabble is no longer linked to the SPSSX-L listserv administered by UGA (https://listserv.uga.edu/).
Reply | Threaded
Open this post in threaded view
|

Re: v23 patches

Maguin, Eugene
Hi Bruce,
No, there is an interim patch and it applies to both 32 and 64 bit MS OS machines. It has a severity/importance (don't recall the exact word used, whatever that really means) of 30, I think. The link to issues addressed doesn't work but the readme.txt says this:
2. The related defect id(s):
ECM00214406: Logjam Vulnerability Exists in Statistics
 
Gene Maguin


-----Original Message-----
From: SPSSX(r) Discussion [mailto:[hidden email]] On Behalf Of Bruce Weaver
Sent: Thursday, September 03, 2015 4:10 PM
To: [hidden email]
Subject: Re: v23 patches

Gene, I just found your message in the archives, because we are also now due to start using v23.  As far as I can tell, there are still no patches for v23.

http://www-01.ibm.com/software/analytics/support/fixes/pbi_releases.html#stats_fixlists




Maguin, Eugene wrote

> We are getting 23 installed and I want to check on the patch level for
> 23
> (32 bit Windows OS). I swam around and found my way to fix central and
> it looks as though there are no patches for 23, meaning 23.0.0 is the
> current version. Is this true?
>
> On my way to fix central I passed through a page describing a schedule
> for patch releases; however, I don't know that it applied to spss statistics.
> Is there such a schedule and what are the dates?
> Thanks, Gene Maguin
>
> =====================
> To manage your subscription to SPSSX-L, send a message to

> LISTSERV@.UGA

>  (not to SPSSX-L), with no body text except the command. To leave the
> list, send the command SIGNOFF SPSSX-L For a list of commands to
> manage subscriptions, send the command INFO REFCARD





-----
--
Bruce Weaver
[hidden email]
http://sites.google.com/a/lakeheadu.ca/bweaver/

"When all else fails, RTFM."

NOTE: My Hotmail account is not monitored regularly.
To send me an e-mail, please use the address shown above.

--
View this message in context: http://spssx-discussion.1045642.n5.nabble.com/v23-patches-tp5730010p5730576.html
Sent from the SPSSX Discussion mailing list archive at Nabble.com.

=====================
To manage your subscription to SPSSX-L, send a message to [hidden email] (not to SPSSX-L), with no body text except the command. To leave the list, send the command SIGNOFF SPSSX-L For a list of commands to manage subscriptions, send the command INFO REFCARD

=====================
To manage your subscription to SPSSX-L, send a message to
[hidden email] (not to SPSSX-L), with no body text except the
command. To leave the list, send the command
SIGNOFF SPSSX-L
For a list of commands to manage subscriptions, send the command
INFO REFCARD
Reply | Threaded
Open this post in threaded view
|

Re: v23 patches

Bruce Weaver
Administrator
Thanks Gene.  After your prompt, I searched for "SPSS 23 interim fix", and found one here:

  http://www-01.ibm.com/support/docview.wss?uid=swg24040357

-----------------------------------------------------
1. interim fix: 23.0-IM-S23STATC-WIN32-IF016
Interim Fix for ECM00214406/APAR PI44002
Platforms:   Windows 32-bit, x86
Applies to versions:   23.0.0.0
Upgrades to:   23.0.0.0
Severity:   30 - Moderate Impact/High Probability of Occurrence
Categories:   Usability
Abstract:   This is an Interim Fix for IBM SPSS Statistics Client 23.0.0.0

More Information
-----------------------------------------------------
       
The "more information" link is still not working (it generates an apology).

I've not installed v23 yet, as I didn't want to take the time to restart my system today.  When I do, perhaps more info will come to light.  



Maguin, Eugene wrote
Hi Bruce,
No, there is an interim patch and it applies to both 32 and 64 bit MS OS machines. It has a severity/importance (don't recall the exact word used, whatever that really means) of 30, I think. The link to issues addressed doesn't work but the readme.txt says this:
2. The related defect id(s):
ECM00214406: Logjam Vulnerability Exists in Statistics
 
Gene Maguin


-----Original Message-----
From: SPSSX(r) Discussion [mailto:[hidden email]] On Behalf Of Bruce Weaver
Sent: Thursday, September 03, 2015 4:10 PM
To: [hidden email]
Subject: Re: v23 patches

Gene, I just found your message in the archives, because we are also now due to start using v23.  As far as I can tell, there are still no patches for v23.

http://www-01.ibm.com/software/analytics/support/fixes/pbi_releases.html#stats_fixlists




Maguin, Eugene wrote
> We are getting 23 installed and I want to check on the patch level for
> 23
> (32 bit Windows OS). I swam around and found my way to fix central and
> it looks as though there are no patches for 23, meaning 23.0.0 is the
> current version. Is this true?
>
> On my way to fix central I passed through a page describing a schedule
> for patch releases; however, I don't know that it applied to spss statistics.
> Is there such a schedule and what are the dates?
> Thanks, Gene Maguin
>
> =====================
> To manage your subscription to SPSSX-L, send a message to

> LISTSERV@.UGA

>  (not to SPSSX-L), with no body text except the command. To leave the
> list, send the command SIGNOFF SPSSX-L For a list of commands to
> manage subscriptions, send the command INFO REFCARD





-----
--
Bruce Weaver
[hidden email]
http://sites.google.com/a/lakeheadu.ca/bweaver/

"When all else fails, RTFM."

NOTE: My Hotmail account is not monitored regularly.
To send me an e-mail, please use the address shown above.

--
View this message in context: http://spssx-discussion.1045642.n5.nabble.com/v23-patches-tp5730010p5730576.html
Sent from the SPSSX Discussion mailing list archive at Nabble.com.

=====================
To manage your subscription to SPSSX-L, send a message to [hidden email] (not to SPSSX-L), with no body text except the command. To leave the list, send the command SIGNOFF SPSSX-L For a list of commands to manage subscriptions, send the command INFO REFCARD

=====================
To manage your subscription to SPSSX-L, send a message to
[hidden email] (not to SPSSX-L), with no body text except the
command. To leave the list, send the command
SIGNOFF SPSSX-L
For a list of commands to manage subscriptions, send the command
INFO REFCARD
--
Bruce Weaver
bweaver@lakeheadu.ca
http://sites.google.com/a/lakeheadu.ca/bweaver/

"When all else fails, RTFM."

PLEASE NOTE THE FOLLOWING: 
1. My Hotmail account is not monitored regularly. To send me an e-mail, please use the address shown above.
2. The SPSSX Discussion forum on Nabble is no longer linked to the SPSSX-L listserv administered by UGA (https://listserv.uga.edu/).
Reply | Threaded
Open this post in threaded view
|

Re: v23 patches

Adrian Barnett
Hi Bruce
There is a link on the page now that says it's a security fix to patch a vulnerability in IBM's Java implementation:

Summary

TLS connections using Diffie-Hellman (DH) key exchange protocol, “Logjam” attack, affects IBM Java SDK 1.6, 1.7 that is used by IBM SPSS Statistics.

Vulnerability Details

CVEID: CVE-2015-4000
DESCRIPTION:
 The TLS protocol could allow a remote attacker to obtain sensitive information, caused by the failure to properly convey a DHE_EXPORT ciphersuite choice. An attacker could exploit this vulnerability using man-in-the-middle techniques to force a downgrade to 512-bit export-grade cipher. Successful exploitation could allow an attacker to recover the session key as well as modify the contents of the traffic. This vulnerability is commonly referred to as "Logjam".
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/103294 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N)

Affected Products and Versions

IBM SPSS Statistics 19.0.0.2
IBM SPSS Statistics 20.0.0.2
IBM SPSS Statistics 21.0.0.2
IBM SPSS Statistics 22.0.0.2
IBM SPSS Statistics 23.0.0.0
 
Regards,

Adrian
--
Adrian Barnett        | "It's always the trombone player"
                      | (Faye Dunaway in 'The Arrangement')
Email: [hidden email]


From: Bruce Weaver <[hidden email]>
To: [hidden email]
Sent: Friday, 4 September 2015, 7:27
Subject: Re: v23 patches

Thanks Gene.  After your prompt, I searched for "SPSS 23 interim fix", and
found one here:

  http://www-01.ibm.com/support/docview.wss?uid=swg24040357

-----------------------------------------------------
1. interim fix: 23.0-IM-S23STATC-WIN32-IF016
Interim Fix for ECM00214406/APAR PI44002
Platforms:      Windows 32-bit, x86
Applies to versions:      23.0.0.0
Upgrades to:      23.0.0.0
Severity:      30 - Moderate Impact/High Probability of Occurrence
Categories:      Usability
Abstract:      This is an Interim Fix for IBM SPSS Statistics Client 23.0.0.0

More Information
-----------------------------------------------------
   
The "more information" link is still not working (it generates an apology).

I've not installed v23 yet, as I didn't want to take the time to restart my
system today.  When I do, perhaps more info will come to light. 




Maguin, Eugene wrote

> Hi Bruce,
> No, there is an interim patch and it applies to both 32 and 64 bit MS OS
> machines. It has a severity/importance (don't recall the exact word used,
> whatever that really means) of 30, I think. The link to issues addressed
> doesn't work but the readme.txt says this:
> 2. The related defect id(s):
> ECM00214406: Logjam Vulnerability Exists in Statistics

> Gene Maguin
>
>
> -----Original Message-----
> From: SPSSX(r) Discussion [mailto:

> [hidden email]

> ] On Behalf Of Bruce Weaver
> Sent: Thursday, September 03, 2015 4:10 PM
> To:

> [hidden email]

> Subject: Re: v23 patches
>
> Gene, I just found your message in the archives, because we are also now
> due to start using v23.  As far as I can tell, there are still no patches
> for v23.
>
> http://www-01.ibm.com/software/analytics/support/fixes/pbi_releases.html#stats_fixlists
>
>
>
>
> Maguin, Eugene wrote
>> We are getting 23 installed and I want to check on the patch level for
>> 23
>> (32 bit Windows OS). I swam around and found my way to fix central and
>> it looks as though there are no patches for 23, meaning 23.0.0 is the
>> current version. Is this true?
>>
>> On my way to fix central I passed through a page describing a schedule
>> for patch releases; however, I don't know that it applied to spss
>> statistics.
>> Is there such a schedule and what are the dates?
>> Thanks, Gene Maguin
>>
>> =====================
>> To manage your subscription to SPSSX-L, send a message to
>
>> [hidden email]
>
>>  (not to SPSSX-L), with no body text except the command. To leave the
>> list, send the command SIGNOFF SPSSX-L For a list of commands to
>> manage subscriptions, send the command INFO REFCARD
>
>
>
>
>
> -----
> --
> Bruce Weaver

> bweaver@

> http://sites.google.com/a/lakeheadu.ca/bweaver/
>
> "When all else fails, RTFM."
>
> NOTE: My Hotmail account is not monitored regularly.
> To send me an e-mail, please use the address shown above.
>
> --
> View this message in context:
> http://spssx-discussion.1045642.n5.nabble.com/v23-patches-tp5730010p5730576.html
> Sent from the SPSSX Discussion mailing list archive at Nabble.com.
>
> =====================
> To manage your subscription to SPSSX-L, send a message to

> [hidden email]

>  (not to SPSSX-L), with no body text except the command. To leave the
> list, send the command SIGNOFF SPSSX-L For a list of commands to manage
> subscriptions, send the command INFO REFCARD
>
> =====================
> To manage your subscription to SPSSX-L, send a message to

> [hidden email]

>  (not to SPSSX-L), with no body text except the
> command. To leave the list, send the command
> SIGNOFF SPSSX-L
> For a list of commands to manage subscriptions, send the command
> INFO REFCARD





-----
--
Bruce Weaver
[hidden email]
http://sites.google.com/a/lakeheadu.ca/bweaver/

"When all else fails, RTFM."

NOTE: My Hotmail account is not monitored regularly.
To send me an e-mail, please use the address shown above.

--
View this message in context: http://spssx-discussion.1045642.n5.nabble.com/v23-patches-tp5730010p5730578.html



Sent from the SPSSX Discussion mailing list archive at Nabble.com.

=====================
To manage your subscription to SPSSX-L, send a message to
[hidden email] (not to SPSSX-L), with no body text except the
command. To leave the list, send the command
SIGNOFF SPSSX-L
For a list of commands to manage subscriptions, send the command
INFO REFCARD


===================== To manage your subscription to SPSSX-L, send a message to [hidden email] (not to SPSSX-L), with no body text except the command. To leave the list, send the command SIGNOFF SPSSX-L For a list of commands to manage subscriptions, send the command INFO REFCARD
Reply | Threaded
Open this post in threaded view
|

Re: v23 patches

Bruce Weaver
Administrator
Thanks for posting that, Adrian.  For some reason, I am still seeing this apology when I click "More information":

Our apologies...
The page you requested cannot be displayed


Adrian Barnett wrote
Hi BruceThere is a link on the page now that says it's a security fix to patch a vulnerability in IBM's Java implementation:

Summary
TLS connections using Diffie-Hellman (DH) key exchange protocol, “Logjam” attack, affects IBM Java SDK 1.6, 1.7 that is used by IBM SPSS Statistics.
Vulnerability Details
CVEID: CVE-2015-4000
DESCRIPTION: The TLS protocol could allow a remote attacker to obtain sensitive information, caused by the failure to properly convey a DHE_EXPORT ciphersuite choice. An attacker could exploit this vulnerability using man-in-the-middle techniques to force a downgrade to 512-bit export-grade cipher. Successful exploitation could allow an attacker to recover the session key as well as modify the contents of the traffic. This vulnerability is commonly referred to as "Logjam".
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/103294 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N)
Affected Products and Versions
IBM SPSS Statistics 19.0.0.2IBM SPSS Statistics 20.0.0.2IBM SPSS Statistics 21.0.0.2IBM SPSS Statistics 22.0.0.2IBM SPSS Statistics 23.0.0.0 Regards,

Adrian
--
Adrian Barnett        | "It's always the trombone player"
                      | (Faye Dunaway in 'The Arrangement')
Email: [hidden email]
 
      From: Bruce Weaver <[hidden email]>
 To: [hidden email] 
 Sent: Friday, 4 September 2015, 7:27
 Subject: Re: v23 patches
   
Thanks Gene.  After your prompt, I searched for "SPSS 23 interim fix", and
found one here:

  http://www-01.ibm.com/support/docview.wss?uid=swg24040357

-----------------------------------------------------
1. interim fix: 23.0-IM-S23STATC-WIN32-IF016
Interim Fix for ECM00214406/APAR PI44002
Platforms:      Windows 32-bit, x86
Applies to versions:      23.0.0.0
Upgrades to:      23.0.0.0
Severity:      30 - Moderate Impact/High Probability of Occurrence
Categories:      Usability
Abstract:      This is an Interim Fix for IBM SPSS Statistics Client 23.0.0.0

More Information
-----------------------------------------------------
   
The "more information" link is still not working (it generates an apology).

I've not installed v23 yet, as I didn't want to take the time to restart my
system today.  When I do, perhaps more info will come to light. 




Maguin, Eugene wrote
> Hi Bruce,
> No, there is an interim patch and it applies to both 32 and 64 bit MS OS
> machines. It has a severity/importance (don't recall the exact word used,
> whatever that really means) of 30, I think. The link to issues addressed
> doesn't work but the readme.txt says this:
> 2. The related defect id(s):
> ECM00214406: Logjam Vulnerability Exists in Statistics

> Gene Maguin
>
>
> -----Original Message-----
> From: SPSSX(r) Discussion [mailto:

> SPSSX-L@.UGA

> ] On Behalf Of Bruce Weaver
> Sent: Thursday, September 03, 2015 4:10 PM
> To:

> SPSSX-L@.UGA

> Subject: Re: v23 patches
>
> Gene, I just found your message in the archives, because we are also now
> due to start using v23.  As far as I can tell, there are still no patches
> for v23.
>
> http://www-01.ibm.com/software/analytics/support/fixes/pbi_releases.html#stats_fixlists
>
>
>
>
> Maguin, Eugene wrote
>> We are getting 23 installed and I want to check on the patch level for
>> 23
>> (32 bit Windows OS). I swam around and found my way to fix central and
>> it looks as though there are no patches for 23, meaning 23.0.0 is the
>> current version. Is this true?
>>
>> On my way to fix central I passed through a page describing a schedule
>> for patch releases; however, I don't know that it applied to spss
>> statistics.
>> Is there such a schedule and what are the dates?
>> Thanks, Gene Maguin
>>
>> =====================
>> To manage your subscription to SPSSX-L, send a message to
>
>> LISTSERV@.UGA
>
>>  (not to SPSSX-L), with no body text except the command. To leave the
>> list, send the command SIGNOFF SPSSX-L For a list of commands to
>> manage subscriptions, send the command INFO REFCARD
>
>
>
>
>
> -----
> --
> Bruce Weaver

> bweaver@

> http://sites.google.com/a/lakeheadu.ca/bweaver/
>
> "When all else fails, RTFM."
>
> NOTE: My Hotmail account is not monitored regularly.
> To send me an e-mail, please use the address shown above.
>
> --
> View this message in context:
> http://spssx-discussion.1045642.n5.nabble.com/v23-patches-tp5730010p5730576.html
> Sent from the SPSSX Discussion mailing list archive at Nabble.com.
>
> =====================
> To manage your subscription to SPSSX-L, send a message to

> LISTSERV@.UGA

>  (not to SPSSX-L), with no body text except the command. To leave the
> list, send the command SIGNOFF SPSSX-L For a list of commands to manage
> subscriptions, send the command INFO REFCARD
>
> =====================
> To manage your subscription to SPSSX-L, send a message to

> LISTSERV@.UGA

>  (not to SPSSX-L), with no body text except the
> command. To leave the list, send the command
> SIGNOFF SPSSX-L
> For a list of commands to manage subscriptions, send the command
> INFO REFCARD





-----
--
Bruce Weaver
[hidden email]
http://sites.google.com/a/lakeheadu.ca/bweaver/

"When all else fails, RTFM."

NOTE: My Hotmail account is not monitored regularly.
To send me an e-mail, please use the address shown above.

--
View this message in context: http://spssx-discussion.1045642.n5.nabble.com/v23-patches-tp5730010p5730578.html


Sent from the SPSSX Discussion mailing list archive at Nabble.com.

=====================
To manage your subscription to SPSSX-L, send a message to
[hidden email] (not to SPSSX-L), with no body text except the
command. To leave the list, send the command
SIGNOFF SPSSX-L
For a list of commands to manage subscriptions, send the command
INFO REFCARD


   

=====================
To manage your subscription to SPSSX-L, send a message to
[hidden email] (not to SPSSX-L), with no body text except the
command. To leave the list, send the command
SIGNOFF SPSSX-L
For a list of commands to manage subscriptions, send the command
INFO REFCARD
--
Bruce Weaver
bweaver@lakeheadu.ca
http://sites.google.com/a/lakeheadu.ca/bweaver/

"When all else fails, RTFM."

PLEASE NOTE THE FOLLOWING: 
1. My Hotmail account is not monitored regularly. To send me an e-mail, please use the address shown above.
2. The SPSSX Discussion forum on Nabble is no longer linked to the SPSSX-L listserv administered by UGA (https://listserv.uga.edu/).
Reply | Threaded
Open this post in threaded view
|

Re: v23 patches

Bruce Weaver
Administrator
UPDATE:  I just checked again today and discovered a "FixPack 002" for IBM SPSS (File name:  23.0-IM-S23STATC-WIN32-FP002.EXE).  After running it, Help > About shows that I am now patched to Release 23.0.0.2.  

Q. Will SPSS ever become as web-savvy as Stata when it comes to updates?  (See http://www.ats.ucla.edu/stat/stata/icu/updating.htm, for example.)  


Bruce Weaver wrote
Thanks for posting that, Adrian.  For some reason, I am still seeing this apology when I click "More information":

Our apologies...
The page you requested cannot be displayed


Adrian Barnett wrote
Hi BruceThere is a link on the page now that says it's a security fix to patch a vulnerability in IBM's Java implementation:

Summary
TLS connections using Diffie-Hellman (DH) key exchange protocol, “Logjam” attack, affects IBM Java SDK 1.6, 1.7 that is used by IBM SPSS Statistics.
Vulnerability Details
CVEID: CVE-2015-4000
DESCRIPTION: The TLS protocol could allow a remote attacker to obtain sensitive information, caused by the failure to properly convey a DHE_EXPORT ciphersuite choice. An attacker could exploit this vulnerability using man-in-the-middle techniques to force a downgrade to 512-bit export-grade cipher. Successful exploitation could allow an attacker to recover the session key as well as modify the contents of the traffic. This vulnerability is commonly referred to as "Logjam".
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/103294 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N)
Affected Products and Versions
IBM SPSS Statistics 19.0.0.2IBM SPSS Statistics 20.0.0.2IBM SPSS Statistics 21.0.0.2IBM SPSS Statistics 22.0.0.2IBM SPSS Statistics 23.0.0.0 Regards,

Adrian
--
Adrian Barnett        | "It's always the trombone player"
                      | (Faye Dunaway in 'The Arrangement')
Email: [hidden email]
 
      From: Bruce Weaver <[hidden email]>
 To: [hidden email] 
 Sent: Friday, 4 September 2015, 7:27
 Subject: Re: v23 patches
   
Thanks Gene.  After your prompt, I searched for "SPSS 23 interim fix", and
found one here:

  http://www-01.ibm.com/support/docview.wss?uid=swg24040357

-----------------------------------------------------
1. interim fix: 23.0-IM-S23STATC-WIN32-IF016
Interim Fix for ECM00214406/APAR PI44002
Platforms:      Windows 32-bit, x86
Applies to versions:      23.0.0.0
Upgrades to:      23.0.0.0
Severity:      30 - Moderate Impact/High Probability of Occurrence
Categories:      Usability
Abstract:      This is an Interim Fix for IBM SPSS Statistics Client 23.0.0.0

More Information
-----------------------------------------------------
   
The "more information" link is still not working (it generates an apology).

I've not installed v23 yet, as I didn't want to take the time to restart my
system today.  When I do, perhaps more info will come to light. 




Maguin, Eugene wrote
> Hi Bruce,
> No, there is an interim patch and it applies to both 32 and 64 bit MS OS
> machines. It has a severity/importance (don't recall the exact word used,
> whatever that really means) of 30, I think. The link to issues addressed
> doesn't work but the readme.txt says this:
> 2. The related defect id(s):
> ECM00214406: Logjam Vulnerability Exists in Statistics

> Gene Maguin
>
>
> -----Original Message-----
> From: SPSSX(r) Discussion [mailto:

> SPSSX-L@.UGA

> ] On Behalf Of Bruce Weaver
> Sent: Thursday, September 03, 2015 4:10 PM
> To:

> SPSSX-L@.UGA

> Subject: Re: v23 patches
>
> Gene, I just found your message in the archives, because we are also now
> due to start using v23.  As far as I can tell, there are still no patches
> for v23.
>
> http://www-01.ibm.com/software/analytics/support/fixes/pbi_releases.html#stats_fixlists
>
>
>
>
> Maguin, Eugene wrote
>> We are getting 23 installed and I want to check on the patch level for
>> 23
>> (32 bit Windows OS). I swam around and found my way to fix central and
>> it looks as though there are no patches for 23, meaning 23.0.0 is the
>> current version. Is this true?
>>
>> On my way to fix central I passed through a page describing a schedule
>> for patch releases; however, I don't know that it applied to spss
>> statistics.
>> Is there such a schedule and what are the dates?
>> Thanks, Gene Maguin
>>
>> =====================
>> To manage your subscription to SPSSX-L, send a message to
>
>> LISTSERV@.UGA
>
>>  (not to SPSSX-L), with no body text except the command. To leave the
>> list, send the command SIGNOFF SPSSX-L For a list of commands to
>> manage subscriptions, send the command INFO REFCARD
>
>
>
>
>
> -----
> --
> Bruce Weaver

> bweaver@

> http://sites.google.com/a/lakeheadu.ca/bweaver/
>
> "When all else fails, RTFM."
>
> NOTE: My Hotmail account is not monitored regularly.
> To send me an e-mail, please use the address shown above.
>
> --
> View this message in context:
> http://spssx-discussion.1045642.n5.nabble.com/v23-patches-tp5730010p5730576.html
> Sent from the SPSSX Discussion mailing list archive at Nabble.com.
>
> =====================
> To manage your subscription to SPSSX-L, send a message to

> LISTSERV@.UGA

>  (not to SPSSX-L), with no body text except the command. To leave the
> list, send the command SIGNOFF SPSSX-L For a list of commands to manage
> subscriptions, send the command INFO REFCARD
>
> =====================
> To manage your subscription to SPSSX-L, send a message to

> LISTSERV@.UGA

>  (not to SPSSX-L), with no body text except the
> command. To leave the list, send the command
> SIGNOFF SPSSX-L
> For a list of commands to manage subscriptions, send the command
> INFO REFCARD





-----
--
Bruce Weaver
[hidden email]
http://sites.google.com/a/lakeheadu.ca/bweaver/

"When all else fails, RTFM."

NOTE: My Hotmail account is not monitored regularly.
To send me an e-mail, please use the address shown above.

--
View this message in context: http://spssx-discussion.1045642.n5.nabble.com/v23-patches-tp5730010p5730578.html


Sent from the SPSSX Discussion mailing list archive at Nabble.com.

=====================
To manage your subscription to SPSSX-L, send a message to
[hidden email] (not to SPSSX-L), with no body text except the
command. To leave the list, send the command
SIGNOFF SPSSX-L
For a list of commands to manage subscriptions, send the command
INFO REFCARD


   

=====================
To manage your subscription to SPSSX-L, send a message to
[hidden email] (not to SPSSX-L), with no body text except the
command. To leave the list, send the command
SIGNOFF SPSSX-L
For a list of commands to manage subscriptions, send the command
INFO REFCARD
--
Bruce Weaver
bweaver@lakeheadu.ca
http://sites.google.com/a/lakeheadu.ca/bweaver/

"When all else fails, RTFM."

PLEASE NOTE THE FOLLOWING: 
1. My Hotmail account is not monitored regularly. To send me an e-mail, please use the address shown above.
2. The SPSSX Discussion forum on Nabble is no longer linked to the SPSSX-L listserv administered by UGA (https://listserv.uga.edu/).
Reply | Threaded
Open this post in threaded view
|

Re: v23 patches

Adrian Barnett
Thanks Bruce.

Interesting question you pose!
Why make users jump through hoops to get something that's of no use unless they have a legitimate copy of SPSS? 

Stata once published a 100-page report on the performance optimizations in Stata and their effect when run on single- through to 16-core processors (which proved considerable!).
I'd like to add that to the SPSS wish-list (but I'm not holding my breath for it)
 
Regards,

Adrian
--
Adrian Barnett        | "It's always the trombone player"
                      | (Faye Dunaway in 'The Arrangement')
Email: [hidden email]


From: Bruce Weaver <[hidden email]>
To: [hidden email]
Sent: Wednesday, 21 October 2015, 7:11
Subject: Re: v23 patches

*UPDATE*:  I just checked again today and discovered a "FixPack 002" for IBM
SPSS (File name:  23.0-IM-S23STATC-WIN32-FP002.EXE).  After running it, Help
> About shows that I am now patched to Release 23.0.0.2. 

Q. Will SPSS /ever/ become as web-savvy as Stata when it comes to updates?
(See http://www.ats.ucla.edu/stat/stata/icu/updating.htm, for example.) 



Bruce Weaver wrote

> Thanks for posting that, Adrian.  For some reason, I am still seeing this
> apology when I click "More information":
>
> Our apologies...
> The page you requested cannot be displayed
>
> Adrian Barnett wrote
>> Hi BruceThere is a link on the page now that says it's a security fix to
>> patch a vulnerability in IBM's Java implementation:
>>
>> Summary
>> TLS connections using Diffie-Hellman (DH) key exchange protocol, “Logjam”
>> attack, affects IBM Java SDK 1.6, 1.7 that is used by IBM SPSS
>> Statistics.
>> Vulnerability Details
>> CVEID: CVE-2015-4000
>> DESCRIPTION: The TLS protocol could allow a remote attacker to obtain
>> sensitive information, caused by the failure to properly convey a
>> DHE_EXPORT ciphersuite choice. An attacker could exploit this
>> vulnerability using man-in-the-middle techniques to force a downgrade to
>> 512-bit export-grade cipher. Successful exploitation could allow an
>> attacker to recover the session key as well as modify the contents of the
>> traffic. This vulnerability is commonly referred to as "Logjam".
>> CVSS Base Score: 4.3
>> CVSS Temporal Score:
>> See https://exchange.xforce.ibmcloud.com/vulnerabilities/103294 for the
>> current score
>> CVSS Environmental Score*: Undefined
>> CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N)
>> Affected Products and Versions
>> IBM SPSS Statistics 19.0.0.2IBM SPSS Statistics 20.0.0.2IBM SPSS
>> Statistics 21.0.0.2IBM SPSS Statistics 22.0.0.2IBM SPSS Statistics
>> 23.0.0.0 Regards,
>>
>> Adrian
>> --
>> Adrian Barnett        | "It's always the trombone player"
>>                       | (Faye Dunaway in 'The Arrangement')
>> Email:

>> [hidden email]

>> 
>>      From: Bruce Weaver &lt;

>> bruce.weaver@

>> &gt;
>>  To:

>> [hidden email]

>> 
>>  Sent: Friday, 4 September 2015, 7:27
>>  Subject: Re: v23 patches
>>   
>> Thanks Gene.  After your prompt, I searched for "SPSS 23 interim fix",
>> and
>> found one here:
>>
>>   http://www-01.ibm.com/support/docview.wss?uid=swg24040357
>>
>> -----------------------------------------------------
>> 1. interim fix: 23.0-IM-S23STATC-WIN32-IF016
>> Interim Fix for ECM00214406/APAR PI44002
>> Platforms:      Windows 32-bit, x86
>> Applies to versions:      23.0.0.0
>> Upgrades to:      23.0.0.0
>> Severity:      30 - Moderate Impact/High Probability of Occurrence
>> Categories:      Usability
>> Abstract:      This is an Interim Fix for IBM SPSS Statistics Client
>> 23.0.0.0
>>
>> More Information
>> -----------------------------------------------------
>>    
>> The "more information" link is still not working (it generates an
>> apology).
>>
>> I've not installed v23 yet, as I didn't want to take the time to restart
>> my
>> system today.  When I do, perhaps more info will come to light. 
>>
>>
>>
>>
>> Maguin, Eugene wrote
>>> Hi Bruce,
>>> No, there is an interim patch and it applies to both 32 and 64 bit MS OS
>>> machines. It has a severity/importance (don't recall the exact word
>>> used,
>>> whatever that really means) of 30, I think. The link to issues addressed
>>> doesn't work but the readme.txt says this:
>>> 2. The related defect id(s):
>>> ECM00214406: Logjam Vulnerability Exists in Statistics
>>> 
>>> Gene Maguin
>>>
>>>
>>> -----Original Message-----
>>> From: SPSSX(r) Discussion [mailto:
>>
>>> [hidden email]
>>
>>> ] On Behalf Of Bruce Weaver
>>> Sent: Thursday, September 03, 2015 4:10 PM
>>> To:
>>
>>> [hidden email]
>>
>>> Subject: Re: v23 patches
>>>
>>> Gene, I just found your message in the archives, because we are also now
>>> due to start using v23.  As far as I can tell, there are still no
>>> patches
>>> for v23.
>>>
>>> http://www-01.ibm.com/software/analytics/support/fixes/pbi_releases.html#stats_fixlists
>>>
>>>
>>>
>>>
>>> Maguin, Eugene wrote
>>>> We are getting 23 installed and I want to check on the patch level for
>>>> 23
>>>> (32 bit Windows OS). I swam around and found my way to fix central and
>>>> it looks as though there are no patches for 23, meaning 23.0.0 is the
>>>> current version. Is this true?
>>>>
>>>> On my way to fix central I passed through a page describing a schedule
>>>> for patch releases; however, I don't know that it applied to spss
>>>> statistics.
>>>> Is there such a schedule and what are the dates?
>>>> Thanks, Gene Maguin
>>>>
>>>> =====================
>>>> To manage your subscription to SPSSX-L, send a message to
>>>
>>>> [hidden email]
>>>
>>>>  (not to SPSSX-L), with no body text except the command. To leave the
>>>> list, send the command SIGNOFF SPSSX-L For a list of commands to
>>>> manage subscriptions, send the command INFO REFCARD
>>>
>>>
>>>
>>>
>>>
>>> -----
>>> --
>>> Bruce Weaver
>>
>>> bweaver@
>>
>>> http://sites.google.com/a/lakeheadu.ca/bweaver/
>>>
>>> "When all else fails, RTFM."
>>>
>>> NOTE: My Hotmail account is not monitored regularly.
>>> To send me an e-mail, please use the address shown above.
>>>
>>> --
>>> View this message in context:
>>> http://spssx-discussion.1045642.n5.nabble.com/v23-patches-tp5730010p5730576.html
>>> Sent from the SPSSX Discussion mailing list archive at Nabble.com.
>>>
>>> =====================
>>> To manage your subscription to SPSSX-L, send a message to
>>
>>> [hidden email]
>>
>>>  (not to SPSSX-L), with no body text except the command. To leave the
>>> list, send the command SIGNOFF SPSSX-L For a list of commands to manage
>>> subscriptions, send the command INFO REFCARD
>>>
>>> =====================
>>> To manage your subscription to SPSSX-L, send a message to
>>
>>> [hidden email]
>>
>>>  (not to SPSSX-L), with no body text except the
>>> command. To leave the list, send the command
>>> SIGNOFF SPSSX-L
>>> For a list of commands to manage subscriptions, send the command
>>> INFO REFCARD
>>
>>
>>
>>
>>
>> -----
>> --
>> Bruce Weaver

>> bweaver@

>> http://sites.google.com/a/lakeheadu.ca/bweaver/
>>
>> "When all else fails, RTFM."
>>
>> NOTE: My Hotmail account is not monitored regularly.
>> To send me an e-mail, please use the address shown above.
>>
>> --
>> View this message in context:
>> http://spssx-discussion.1045642.n5.nabble.com/v23-patches-tp5730010p5730578.html
>>
>>
>> Sent from the SPSSX Discussion mailing list archive at Nabble.com.
>>
>> =====================
>> To manage your subscription to SPSSX-L, send a message to

>> [hidden email]

>>  (not to SPSSX-L), with no body text except the
>> command. To leave the list, send the command
>> SIGNOFF SPSSX-L
>> For a list of commands to manage subscriptions, send the command
>> INFO REFCARD
>>
>>
>>   
>>
>> =====================
>> To manage your subscription to SPSSX-L, send a message to

>> [hidden email]

>>  (not to SPSSX-L), with no body text except the
>> command. To leave the list, send the command
>> SIGNOFF SPSSX-L
>> For a list of commands to manage subscriptions, send the command
>> INFO REFCARD





-----
--
Bruce Weaver
[hidden email]
http://sites.google.com/a/lakeheadu.ca/bweaver/

"When all else fails, RTFM."

NOTE: My Hotmail account is not monitored regularly.
To send me an e-mail, please use the address shown above.

--
View this message in context: http://spssx-discussion.1045642.n5.nabble.com/v23-patches-tp5730010p5730800.html
Sent from the SPSSX Discussion mailing list archive at Nabble.com.

=====================
To manage your subscription to SPSSX-L, send a message to
[hidden email] (not to SPSSX-L), with no body text except the
command. To leave the list, send the command
SIGNOFF SPSSX-L
For a list of commands to manage subscriptions, send the command
INFO REFCARD

===================== To manage your subscription to SPSSX-L, send a message to [hidden email] (not to SPSSX-L), with no body text except the command. To leave the list, send the command SIGNOFF SPSSX-L For a list of commands to manage subscriptions, send the command INFO REFCARD