|
-
September 30th, 2004, 12:21 PM
#31
I ran the GDI scan from that tutorial this morning. I came up with a file at C:\WINDOWS\SYSTEM32\gdiplus.dll that I don't know what to do with. The tutorial says "that I need to visit the web site of this application and see if there is any update available." I don't know where at Microsoft I'm supposed to find an update for it (or what application it applies to).
-
September 30th, 2004, 07:54 PM
#32
DuaneB--It is unfortunate that there are two threads on this subject. Your last post has been anticipated in the other thread. And I see the problems you have had.
http://discussions.virtualdr.com/sho...424#post868424
As far as learning what the other non-Microsoft applications are doing about the new gdiplus.dll, you have to go to their websites and see/ask. So far I have had no response.
Last edited by Welshjim; October 1st, 2004 at 02:26 PM.
Jim
WIN7 Ultimate SP1 64bit, IE 11, NTFS,
cable, MS Security Essentials, Windows 7 firewall
-
September 30th, 2004, 07:57 PM
#33
Thanks, Jim. I think there are actually three threads on this issue.
-
October 1st, 2004, 08:09 AM
#34
Originally posted by Welshjim
Vernon Frazee--So what are those who are not offered the GDI+ security update (since they do not run Office components) to do about the vulnerability in IE?
Since IE is a Microsoft product, I'd try their http://windowsupdate.microsoft.com site first?
-
October 1st, 2004, 08:11 AM
#35
Originally posted by 104456
Or MS Works which also does not have a patch either
Since MSWorks is also a Microsoft product, I'd try their http://windowsupdate.microsoft.com site.
-
October 1st, 2004, 08:13 AM
#36
Originally posted by Welshjim
Has anybody here actually replaced the "vulnerable" version with the new version? Systems still work? Always nice to learn from someone else's experience.
Yes, I have, on a new machine running Windows XP Home with SP2 applied. So far it's working fine.
-
October 1st, 2004, 08:15 AM
#37
Originally posted by DuaneB
I ran the GDI scan from that tutorial this morning. I came up with a file at C:\WINDOWS\SYSTEM32\gdiplus.dll that I don't know what to do with. The tutorial says "that I need to visit the web site of this application and see if there is any update available." I don't know where at Microsoft I'm supposed to find an update for it (or what application it applies to).
I'd try http://windowsupdate.microsoft.com first and see if it recommends any critical updates.
-
October 1st, 2004, 08:16 AM
#38
Been there Vernon they dont seem to offer many updates for older versions of Works its seems like Offices lost cousin
I ended up just replacing the file with that posted on the MS link you kindly provided.
-
October 1st, 2004, 08:16 AM
#39
Originally posted by DuaneB
Thanks, Jim. I think there are actually three threads on this issue.
Yes, there are. Here are links to the other two:
Security News / Warnings / Updates > GDI+ JPEG exploit worse than first thought
http://discussions.virtualdr.com/sho...hreadid=173931
Windows XP > A new Critical Update is available
http://discussions.virtualdr.com/sho...hreadid=173155
And then this one,
Security News / Warnings / Updates > Security vulnerability in Jpegs
http://discussions.virtualdr.com/sho...hreadid=173136
-
October 1st, 2004, 02:27 PM
#40
Nothing on this at the Windows Update site as of a few minutes ago, and still no response from providers of non-Microsoft programs.
Jim
WIN7 Ultimate SP1 64bit, IE 11, NTFS,
cable, MS Security Essentials, Windows 7 firewall
-
October 1st, 2004, 08:53 PM
#41
One of the non-Microsoft program sites has replied that I should use the updated gdiplus.dll file from MS.
However, does anyone have a comment why a "vulnerable" gdiplus.dll file in the Program Files folder for a piece of hardware should mean that the PC is vulnerable to this security exploit? Especially when the gdiplus.dll files in the MS files, such as C:\I386, have been updated?
Jim
WIN7 Ultimate SP1 64bit, IE 11, NTFS,
cable, MS Security Essentials, Windows 7 firewall
-
October 2nd, 2004, 08:19 AM
#42
Microsoft Security Bulletin MS04-028
http://www.microsoft.com/technet/sec.../MS04-028.mspx
Frequently asked questions (FAQ) related to this security update- What is GDI+?
GDI+ is a graphics device interface that provides two-dimensional vector graphics, imaging, and typography to applications and programmers.
Why are there several affected programs and components?
Windows XP, Windows XP Service Pack 1, and Windows Server 2003 provide an operating system version of the component that is vulnerable to this issue. Earlier versions of Windows did not provide an operating system version of this component. Therefore, when you install programs that require this functionality on earlier versions of Windows, this component is commonly installed. Typically, when these programs are installed on Windows XP, Windows XP Service Pack 1, or Windows Server 2003 they only use the version that is provided by the operating system, even if they install a copy of the vulnerable component.
The exceptions to this are Office XP, Visio 2002, Project 2002, Office 2003, Visio 2003, and Project 2003. To make sure that JPEG images are processed consistently across all operating systems, these programs use their own version of the vulnerable component. This version of the vulnerable component is installed on all operating systems that are supported by these programs. If you have installed these programs, you must install the update for these programs. You must also install an operating system update if you use Windows XP, Windows XP Service Pack 1, or Windows Server 2003. Also, please review the following FAQ questions relating to exceptions for application developers and third-party applications.
...continues...
-
October 2nd, 2004, 01:20 PM
#43
Thanks, Vernon--
I understand from the quote you provided to say that when the third-party applications requiring gdiplus.dll were installed they actually took the gdiplus.dll from the Windows file (like C:\I386). That would suggest that if those applications had been installed after the Windows files were updated with the new gdiplus.dll from MS, that the applications would have automatically put that "non-vulnerable"version into their program files. And that would suggest that we can substitute the old gdiplus.dll's with the new throughout the PC. (Except where not necessary, like the $NtServicePackUninstall$ and Win SxS folders.)
Would you agree?
The following just muddies the water, but read only if you want. P.S. The FAQ's in the Security Bulletin MS04-028 go on to say
"If the Gdiplus.dll file is installed on your system, you may have to install an update for that program. Not every program that installs this file is vulnerable to this issue because it may not use the Gdiplus.dll file to process JPEG images. Even when the third-party application uses the Gdiplus.dll file to process JPEG images it may not do so in a vulnerable way. For example if an application does not allow users to supply images for processing or performs additional validation on the images before processing, it may not be vulnerable. However, only the manufacturer of that program can make that determination. This could include, but is not limited to, third party applications that were developed using Visual Studio .NET 2002, Visual Studio .NET 2003, or the Microsoft .NET Framework 1.0 SDK Service Pack 2.
Additionally, Windows XP and Windows Server 2003 provide additional methods to help secure applications. These operating systems provide an operating system version of the affected component and can be centrally protected. This means that even if an application installs a version of the Gdiplus.dll file, that the application in most cases will use the operating system supplied version. The operating system version of Gdiplus.dll is updated when you install the appropriate operating system update and will protect most applications from this vulnerability."
So, based on that enlightenment, we are back to
1) not knowing if the "vulnerable" gdiplus.dll file in an application's folder can be activated, and
2) ideally being told by the application provider what the correct thing to do is. Good luck to that.
Jim
WIN7 Ultimate SP1 64bit, IE 11, NTFS,
cable, MS Security Essentials, Windows 7 firewall
-
October 2nd, 2004, 02:15 PM
#44
If third-party programmers have hard-coded their program to use the gdiplus.dll that they shipped with their program, and that gdiplus.dll happens to be one of the vunerable versions, then the first time you use that program to view a jpeg designed to exploit the vunerability, your PC is now at the mercy of whatever that jpeg was designed to do.
In this particular case you might be able to replace that third-party's vunerable gdiplus.dll file in its "c:\program files\whatever folder and it may fix the problem. However, if the third-party programmers also actually modified their copy of the gdiplus.dll, then replacing it would probably break their program.
This is why Microsoft states that you need to contact the third-party software manufacturers.
I'm also quite sure that not all third-party software manufacturers that this problem affects have had time to develop a patch. And some may not even attempt to, especially for their older versions.
Only time will tell how deep this vulnerability has and will continue to haunt us.
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|