Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


September 23, 2004

Update: New Tools Help with JPEG GDI+ Updates

RSS
Subscribe to Windows IT Pro | See More Hotfixes Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

Eric Brunsen released a new tool that can help you locate all copies of gdiplus.dll files on your systems to determine which copies might need to be updated to defend against the recently discovered JPEG GDI+ vulnerability (MS04-028).

Brunsen's toolkit, which requires Microsoft .NET Framework 1.1 to operate, can scan systems, both locally and over a network, and produce a report that reveals where the files are located, what the DLL version is, and what the file creation dates were. You can download a copy of the tool which is available for free on the Web, and read more about what Brunsen had to say about the tool in the Patch Management mailing list archives.

But be aware that you might need to replace more files than just the gdiplus.dll in order to completely protect yourselves against intrusion. Be sure to read Microsoft's bulletin for complete details, which explains nuances with products such as Office XP, Visio 2002, Project 2002, and Internet Explorer 6 Service Pack 1 (SP1) that might need to have other files updated too, such as mso.dll.

To help with identifying all affected DLLs (including gdiplus.dll, mso.dll, sxs.dll, and wsxs.dll), Tim Liston wrote a tool, gdiscan.exe, which can locate such files and produced a report that helps you patch the right files. Liston's tool, which is available as a Windows desktop application or command line tool, can colorize its report so that vulnerable DLLs appear in a red font.

Liston's tool is a different from Brunsen's tool in that Liston's tool requires no options. As soon as the tool is run it begins scanning the Windows system drive for vulnerable DLL files. It appears that Liston's tool won't scan over a network, or scan drives other than the drive that contains the Windows system directory. Nevertheless you might find the tool handy, especially since there is a command line version available, which is useful for scripting purposes. You can download a copy of online. There's a Web page describing the tool and links to the download at the Internet Storm Center.

End of Article



Reader Comments
Very helpful

tomgerst September 29, 2004 (Article Rating: )


Note: The GDIScan tool posted on the Internet Storm Center site has been updated: it now allows scanning of arbitrary drives. In addition, there is also a GUI-based version.

kpaetow September 29, 2004 (Article Rating: )


Need the tool to keep up to date

Anonymous User February 17, 2005 (Article Rating: )


You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
Battery Life Issues Almost Certainly Not Windows 7's Fault

While Microsoft is still investigating a notebook battery life issue that was supposedly caused by Windows 7, some interesting trends have emerged. ...

Confirmed: Battery Life Issues Not Windows 7's Fault

Microsoft on Monday issued a lengthy statement about the recent Windows 7 battery controversy, echoing my assessment from earlier in the day, but backing it up with hard, cold evidence. ...

Getting your iPhone to Sync with Exchange 2003

Follow these steps to use an iPhone with Exchange. ...


Security Whitepapers Reducing the Costs and Risks of Branch Office Data Protection

Solving Desktop Management Challenges in Healthcare

Solving Desktop Management Challenges in Education

Related Events Are your IT systems distributed? Or convoluted?

The Increasing Threat of Financially Motivated Data Theft

Cutting Costs with Client Management

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2010 Penton Media, Inc. Terms of Use | Privacy Statement