Unsolved
This post is more than 5 years old
2 Intern
•
2.7K Posts
0
14670
September 28th, 2004 11:00
JPEG Vulnerability
I am a bit confused about this JPEG Vulnerabilty. If I have XP2 installed do I need to go through these programs and install updates individually for programs? For exmple I have Microsoft Picture IT! version 7. Would I need to use this site to install this update for Picture IT! or am I Ok since I have SP2?
http://www.microsoft.com/technet/security/bulletin/MS04-028.mspx
0 events found
No Events found!


WildOne46
195 Posts
0
September 28th, 2004 13:00
aps,
Found this over at WindowsITpro ( http://www.winnetmag.com/ )concening JPEG vulnerability..
"MS04-028, which Microsoft deems critical, addresses problems with JPEG Graphics Development Interface Plus (GDI+). If after reading the bulletin, you're uncertain whether any of your systems have an application that uses GDI+, you can download a GDI Detection Tool from Microsoft that will help you determine which of your systems might be affected. Read more about the tool in the Microsoft article "Description of the Microsoft GDI+ Detection Tool: September 14, 2004" [http://support.microsoft.com/?kbid=873374]."
It's confusing to me too, but I think if you have SP2 installed you're ok...a section of the bulletin seems to indicate this, but it is confusing....
WildOne
Message Edited by WildOne46 on 09-28-2004 10:22 AM
Annie70
2 Intern
•
2.7K Posts
0
September 28th, 2004 16:00
1Bowtie
723 Posts
0
September 28th, 2004 19:00
Hi aps
I was curious after reading your post so i went to control panel/security center, and had it check for updates and it brought up 2, one for .net framework 1.1 and one for the JPEG Vulnerability toghther they were 10.4mb and i am running SP 2. Just food for thought.
Mary G
6 Operator
•
20.1K Posts
0
September 28th, 2004 19:00
Annie70
2 Intern
•
2.7K Posts
0
September 28th, 2004 20:00
MaryG, Thanks for your answer and the site to confirm this question.
"Windows' Graphic Device Interface Plus (GDI+) software contains a JPEG-processing vulnerability that affects dozens of Microsoft products, including the Office suite. Windows XP and Windows Server versions are vulnerable unless a Microsoft patch has been installed in the last few weeks or, in the case of XP, if the systems have been upgraded to Service Pack 2."
The JPEG Vulnerability did show on the windows update site last week and I did install it but if it did anything I cannot tell.After several days of searching you have been the first to give a definite answer. I have SP2 so therefore I will cross this off my list of things to research. Thanks.
Annie70
2 Intern
•
2.7K Posts
0
September 28th, 2004 22:00
Wickham43
8 Posts
0
September 29th, 2004 05:00
I have SP2 and I also found this update listed as critical after installing SP2.
I was also confused so I downloaded it. I was given the chance to run the detector immediately which I did but nothing was found.
I now can't find the detector to run it again!
I then assumed that it was part of SP2 and therefore somehow irrelevant and not available anymore.
JRosenfeld
2 Intern
•
4.4K Posts
0
September 29th, 2004 17:00
Unfortunately, the MS tool only looks at MS products for vulnerable versions of gdiplus.dll. This MS file is bundled with quite a few third party programs. To check these there is another tool available, called gdiscan that you can download from:
http://isc.sans.org/gdiscan.php
Advice on use and what to do from:
http://www.bleepingcomputer.com/forums/topict3077.html
I found vulnerable versions in HP print screen utility (came bundled with my HP deskjet printer) and in Sonic MyDVD v 5. In both cases I replaced the versions of gdiplus.dll in those app folders by one from SP2: v 5.1.3102.2180 that I found in a folder
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.2180_x-ww_522f9f82
that got put there during install of SP2 (using the full SP2 update file
WindowsXP-KB835935-SP2-ENU.exe)
Both apps function normally with this updated version as far as I've tested them.
The SP2 update file is a self extracting zipped file, if you open it with Winzip or similar, that version of gdiplus is in that package and you can extract it from there.
Also a discussion of the threat in
http://forums.net-integration.net/index.php?s=ef88fc55ae22451b2f9cf6819ad53d4b&showtopic=22839
Message Edited by JRosenfeld on 09-29-2004 07:16 PM
chast
121 Posts
0
October 1st, 2004 02:00
JR...
I was going to manually exchange the Gdiplus.dll files of some HP printer software like you did, but changed my mind after reading this part of the JPEG bulletin. Thought I would just bring it to your attention.
Microsoft Security Bulletin MS04-028
http://www.microsoft.com/technet/security/Bulletin/MS04-028.mspxscroll down to...
"Frequently asked questions (FAQ) related to this security update"
then look under...
"If I use third-party applications that distribute the gdiplus.dll file, could I still be vulnerable even after I have installed all required Microsoft security updates?"
then scroll down to this paragraph...
"It is also important to note that you should install any available security updates instead of manually updating the affected component, if possible. Manually updating the affected component could create application compatibility issues and is not supported. Also, applications that feature ‘Detect and Repair’ functionality will not receive the necessary information required to prevent these features from potentially introducing the vulnerability upon execution if the affected component is manually updated."
JRosenfeld
2 Intern
•
4.4K Posts
0
October 3rd, 2004 16:00
Chast,
Yes, thank you, I was aware of that. However neither the HP printscreen utility and Sonic MyDVD v 4.5 had updates to cover this vulnerability (nor are they likely to). Neither app has a detect and repair function.
So I first copied their (vulnerable) versions of gdiplus to a temp folder, updated the gdiplus in each app and tested the app. They both worked OK with the updated gdiplus.
I hardly ever use either program anyway.
northkestrel
2 Posts
0
October 4th, 2004 14:00