We are getting 23 installed and I want to check on the patch level for 23 (32 bit Windows OS). I swam around and found my way to fix central and it looks as though there are no patches for 23, meaning 23.0.0 is the current version. Is this
true? On my way to fix central I passed through a page describing a schedule for patch releases; however, I don’t know that it applied to spss statistics. Is there such a schedule and what are the dates? Thanks, Gene Maguin |
Administrator
|
Gene, I just found your message in the archives, because we are also now due to start using v23. As far as I can tell, there are still no patches for v23.
http://www-01.ibm.com/software/analytics/support/fixes/pbi_releases.html#stats_fixlists
--
Bruce Weaver bweaver@lakeheadu.ca http://sites.google.com/a/lakeheadu.ca/bweaver/ "When all else fails, RTFM." PLEASE NOTE THE FOLLOWING: 1. My Hotmail account is not monitored regularly. To send me an e-mail, please use the address shown above. 2. The SPSSX Discussion forum on Nabble is no longer linked to the SPSSX-L listserv administered by UGA (https://listserv.uga.edu/). |
Hi Bruce,
No, there is an interim patch and it applies to both 32 and 64 bit MS OS machines. It has a severity/importance (don't recall the exact word used, whatever that really means) of 30, I think. The link to issues addressed doesn't work but the readme.txt says this: 2. The related defect id(s): ECM00214406: Logjam Vulnerability Exists in Statistics Gene Maguin -----Original Message----- From: SPSSX(r) Discussion [mailto:[hidden email]] On Behalf Of Bruce Weaver Sent: Thursday, September 03, 2015 4:10 PM To: [hidden email] Subject: Re: v23 patches Gene, I just found your message in the archives, because we are also now due to start using v23. As far as I can tell, there are still no patches for v23. http://www-01.ibm.com/software/analytics/support/fixes/pbi_releases.html#stats_fixlists Maguin, Eugene wrote > We are getting 23 installed and I want to check on the patch level for > 23 > (32 bit Windows OS). I swam around and found my way to fix central and > it looks as though there are no patches for 23, meaning 23.0.0 is the > current version. Is this true? > > On my way to fix central I passed through a page describing a schedule > for patch releases; however, I don't know that it applied to spss statistics. > Is there such a schedule and what are the dates? > Thanks, Gene Maguin > > ===================== > To manage your subscription to SPSSX-L, send a message to > LISTSERV@.UGA > (not to SPSSX-L), with no body text except the command. To leave the > list, send the command SIGNOFF SPSSX-L For a list of commands to > manage subscriptions, send the command INFO REFCARD ----- -- Bruce Weaver [hidden email] http://sites.google.com/a/lakeheadu.ca/bweaver/ "When all else fails, RTFM." NOTE: My Hotmail account is not monitored regularly. To send me an e-mail, please use the address shown above. -- View this message in context: http://spssx-discussion.1045642.n5.nabble.com/v23-patches-tp5730010p5730576.html Sent from the SPSSX Discussion mailing list archive at Nabble.com. ===================== To manage your subscription to SPSSX-L, send a message to [hidden email] (not to SPSSX-L), with no body text except the command. To leave the list, send the command SIGNOFF SPSSX-L For a list of commands to manage subscriptions, send the command INFO REFCARD ===================== To manage your subscription to SPSSX-L, send a message to [hidden email] (not to SPSSX-L), with no body text except the command. To leave the list, send the command SIGNOFF SPSSX-L For a list of commands to manage subscriptions, send the command INFO REFCARD |
Administrator
|
Thanks Gene. After your prompt, I searched for "SPSS 23 interim fix", and found one here:
http://www-01.ibm.com/support/docview.wss?uid=swg24040357 ----------------------------------------------------- 1. interim fix: 23.0-IM-S23STATC-WIN32-IF016 Interim Fix for ECM00214406/APAR PI44002 Platforms: Windows 32-bit, x86 Applies to versions: 23.0.0.0 Upgrades to: 23.0.0.0 Severity: 30 - Moderate Impact/High Probability of Occurrence Categories: Usability Abstract: This is an Interim Fix for IBM SPSS Statistics Client 23.0.0.0 More Information ----------------------------------------------------- The "more information" link is still not working (it generates an apology). I've not installed v23 yet, as I didn't want to take the time to restart my system today. When I do, perhaps more info will come to light.
--
Bruce Weaver bweaver@lakeheadu.ca http://sites.google.com/a/lakeheadu.ca/bweaver/ "When all else fails, RTFM." PLEASE NOTE THE FOLLOWING: 1. My Hotmail account is not monitored regularly. To send me an e-mail, please use the address shown above. 2. The SPSSX Discussion forum on Nabble is no longer linked to the SPSSX-L listserv administered by UGA (https://listserv.uga.edu/). |
Hi Bruce There is a link on the page now that says it's a security fix to patch a vulnerability in IBM's Java implementation: SummaryTLS connections using Diffie-Hellman (DH) key exchange protocol, “Logjam” attack, affects IBM Java SDK 1.6, 1.7 that is used by IBM SPSS Statistics. Vulnerability DetailsCVEID: CVE-2015-4000 DESCRIPTION: The TLS protocol could allow a remote attacker to obtain sensitive information, caused by the failure to properly convey a DHE_EXPORT ciphersuite choice. An attacker could exploit this vulnerability using man-in-the-middle techniques to force a downgrade to 512-bit export-grade cipher. Successful exploitation could allow an attacker to recover the session key as well as modify the contents of the traffic. This vulnerability is commonly referred to as "Logjam". CVSS Base Score: 4.3 CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/103294 for the current score CVSS Environmental Score*: Undefined CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N) Affected Products and VersionsIBM SPSS Statistics 19.0.0.2 IBM SPSS Statistics 20.0.0.2 IBM SPSS Statistics 21.0.0.2 IBM SPSS Statistics 22.0.0.2 IBM SPSS Statistics 23.0.0.0 Regards, Adrian -- Adrian Barnett | "It's always the trombone player" | (Faye Dunaway in 'The Arrangement') Email: [hidden email]
|
Administrator
|
Thanks for posting that, Adrian. For some reason, I am still seeing this apology when I click "More information":
Our apologies... The page you requested cannot be displayed
--
Bruce Weaver bweaver@lakeheadu.ca http://sites.google.com/a/lakeheadu.ca/bweaver/ "When all else fails, RTFM." PLEASE NOTE THE FOLLOWING: 1. My Hotmail account is not monitored regularly. To send me an e-mail, please use the address shown above. 2. The SPSSX Discussion forum on Nabble is no longer linked to the SPSSX-L listserv administered by UGA (https://listserv.uga.edu/). |
Administrator
|
UPDATE: I just checked again today and discovered a "FixPack 002" for IBM SPSS (File name: 23.0-IM-S23STATC-WIN32-FP002.EXE). After running it, Help > About shows that I am now patched to Release 23.0.0.2.
Q. Will SPSS ever become as web-savvy as Stata when it comes to updates? (See http://www.ats.ucla.edu/stat/stata/icu/updating.htm, for example.)
--
Bruce Weaver bweaver@lakeheadu.ca http://sites.google.com/a/lakeheadu.ca/bweaver/ "When all else fails, RTFM." PLEASE NOTE THE FOLLOWING: 1. My Hotmail account is not monitored regularly. To send me an e-mail, please use the address shown above. 2. The SPSSX Discussion forum on Nabble is no longer linked to the SPSSX-L listserv administered by UGA (https://listserv.uga.edu/). |
Thanks Bruce. Interesting question you pose! Why make users jump through hoops to get something that's of no use unless they have a legitimate copy of SPSS? Stata once published a 100-page report on the performance optimizations in Stata and their effect when run on single- through to 16-core processors (which proved considerable!). I'd like to add that to the SPSS wish-list (but I'm not holding my breath for it) Regards, Adrian -- Adrian Barnett | "It's always the trombone player" | (Faye Dunaway in 'The Arrangement') Email: [hidden email]
|
Free forum by Nabble | Edit this page |