republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » GDI+ vulnerability question
Search Topic:
Uniqs:
702
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
do company servers know where you've been? »
« ZoneAlarm Anti-Virus to free version  
AuthorAll Replies


Morac

join:2001-08-30
Riverside, NJ
·Comcast

GDI+ vulnerability question

Since a lot of programs include their own copy of gdiplus.dll, I've been trying to go through my system and see which ones are vulnerable and which ones aren't.

The Microsoft bulletin only states which versions are included with the patches, not which are vulnerable.

Based on the lowest version number I could find in the KB article, it would seem that versions lower than 5.1.3102.3352 are vulnerable, but the current GDI+ platform SDK (updated today) is version 5.1.3102.1360. This would seem to indicate that anything older than 5.1.3102.1360 should be updated.

Many of the programs I have already contain version 5.1.3102.1360 of gdiplus.dll even those that were released over 4 years ago.

Is 5.1.3102.1360 or above safe?
--

The Comcast Disney Avatar has been retired.


Morac

join:2001-08-30
Riverside, NJ
·Comcast

Well I think I answered my own question. I downloaded the GDI+ Platform SDK and despite the version number listed as being 5.1.3102.1360 on the page, it extracted a gdiplus.dll version 5.1.3102.5581 (the same as the XP SP3 version).

So I'm guessing that 5.1.3102.1360 is vulnerable.
--

The Comcast Disney Avatar has been retired.


therube

join:2004-11-11
Randallstown, MD

And so what, you're replacing all other versions that you have with the .5591 version?

(.5591 is what I've got in /windows/system32/.)

I'm not really familiar with gdiplus.dll but have you verified that the programs work/work correctly with the updated version of gdiplus.dll. Wonder if the programs specifically need to have gdiplus.dll in their directories, or if gdiplus.dll would be found so long as it is in your PATH (as /windows/system32/ would be)?

(What ever happened to DLL hell?)


Morac

join:2001-08-30
Riverside, NJ
·Comcast

I did replace all the old versions I had with the .5591, but if you have XP or Vista you have other options.

My system doesn't have gdiplus.dll in the /windows/system32 directory. I'm not sure why, but it doesn't. It does have versions in the C:\WINDOWS\WinSxS\ (side-by-side) sub-directories. I'm not sure if deleting the "bad" gdiplus.dll files would have worked or not since I didn't try it. I supposed I could have just renamed the gdiplus.dll files and then tried to run the programs to see if they ran, but I didn't bother.

DLL hell was "replaced" with side-by-side, but not all programs use it since doing so results in the programs only working in Windows XP or later (no Win 2000 or Win 98).
--

The Comcast Disney Avatar has been retired.


therube

join:2004-11-11
Randallstown, MD
I was actually kidding about the DLL Hell part.

But thanks for the side-by-side information. Never knew that.
It says gdiplus.dll is a s-b-s assembly.
-
Forums » Up and Running » Security » Securitydo company servers know where you've been? »
« ZoneAlarm Anti-Virus to free version  


Saturday, 05-Dec 18:51:10 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [163] Comcast Releasing Promised Usage Meter
· [147] Avast Antivirus Has Gone Mad
· [128] Comcast Makes NBC Universal Acquisition Official
· [106] The Bandwidth Hog Does Not Exist
· [104] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [101] Google Invades ISP, OpenDNS Turf With Google Public DNS
· [85] FCC Ponders Moving From PSTN To IP Voice
· [81] Latest Consumer Reports Survey Not Kind To AT&T
· [80] New Bill Aims To Limit ETFs
· [74] Sprint Defuses GPS Privacy Media Bomb
Most people now reading
· False positive in Avast! or is it real? [Security]
· Wife might have to work in.... Iowa for a few months!!! [General Questions]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· UPS - What do you people think happened? [General Questions]
· Windows 7 boot manager editing questions [Microsoft Help]
· [How to] Install Asterisk on an Asus WL-520GU router [VOIP Tech Chat]
· RG Firmware update to VDSL2 this morning [AT&T U-verse]
· First commercial tool to crack BitLocker arrives (Updated) [Security]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· DNS options, what are YOU using? [TekSavvy]