Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Update > GDI exploit still on after WU

Reply
Thread Tools Display Modes

GDI exploit still on after WU

 
 
rr
Guest
Posts: n/a

 
      10-29-2004
I have a Windows 2003 server with all current patches from WU (office is not
intalled)

Wu comes up cleanly and says all patches installed and is current.

However when I do a GDi scan using the Sans tool it reports my 1.1 SP1 .Net
framework gdiplus.dll is vulnerable.

Does WU not check on vulnerable security files.

thanks
rr


 
Reply With Quote
 
 
 
 
Mike D
Guest
Posts: n/a

 
      10-29-2004
search ms knowledge base for GDI patch and reinstall it and it will help you
with this
MikeD
"rr" <> wrote in message
news:%23$...
>I have a Windows 2003 server with all current patches from WU (office is
>not
> intalled)
>
> Wu comes up cleanly and says all patches installed and is current.
>
> However when I do a GDi scan using the Sans tool it reports my 1.1 SP1
> .Net
> framework gdiplus.dll is vulnerable.
>
> Does WU not check on vulnerable security files.
>
> thanks
> rr
>
>



 
Reply With Quote
 
Torgeir Bakken \(MVP\)
Guest
Posts: n/a

 
      10-30-2004
rr wrote:

> I have a Windows 2003 server with all current patches from WU
> (office is not intalled)
>
> Wu comes up cleanly and says all patches installed and is current.
>
> However when I do a GDi scan using the Sans tool it reports my
> 1.1 SP1 .Net framework gdiplus.dll is vulnerable.
>
> Does WU not check on vulnerable security files.

Hi

1)
Where exactly is the file placed, and what version number does it have?


2)
What is the version number on this file:

%windir%\Microsoft.NET\Framework\v1.1.4322\mscorli b.dll

(%windir% is typically C:\Windows)



--
torgeir, Microsoft MVP Scripting and WMI, Porsgrunn Norway
Administration scripting examples and an ONLINE version of
the 1328 page Scripting Guide:
http://www.microsoft.com/technet/scr...r/default.mspx
 
Reply With Quote
 
rr
Guest
Posts: n/a

 
      11-02-2004
Thanks for the replies.

The vulnerable file is
C:WINNT\Microsoft.NET\Framework\v1.1.4322\gdiplus. dll it is version
5.1.3101.0.

Mscorlib.dll is version 1.1.4322.2032

I did a reinstall and its still there.

I am thinking of just replacing the gdiplus with the redistributable
version.
However this would only fix this machine and I have a few others that show
this as well.
Besides I'd like to find out why WU is missing this and if its a problem to
get it fixed.

thanks
rr


"Torgeir Bakken (MVP)" <Torgeir.Bakken-> wrote in message
news:...
> rr wrote:
>
> > I have a Windows 2003 server with all current patches from WU
> > (office is not intalled)
> >
> > Wu comes up cleanly and says all patches installed and is current.
> >
> > However when I do a GDi scan using the Sans tool it reports my
> > 1.1 SP1 .Net framework gdiplus.dll is vulnerable.
> >
> > Does WU not check on vulnerable security files.

> Hi
>
> 1)
> Where exactly is the file placed, and what version number does it have?
>
>
> 2)
> What is the version number on this file:
>
> %windir%\Microsoft.NET\Framework\v1.1.4322\mscorli b.dll
>
> (%windir% is typically C:\Windows)
>
>
>
> --
> torgeir, Microsoft MVP Scripting and WMI, Porsgrunn Norway
> Administration scripting examples and an ONLINE version of
> the 1328 page Scripting Guide:
> http://www.microsoft.com/technet/scr...r/default.mspx



 
Reply With Quote
 
Torgeir Bakken \(MVP\)
Guest
Posts: n/a

 
      11-02-2004
rr wrote:

> Thanks for the replies.
>
> The vulnerable file is
> C:WINNT\Microsoft.NET\Framework\v1.1.4322\gdiplus. dll it is version
> 5.1.3101.0.


My Win2k3 Server installation does not have a gdiplus.dll file in that
folder. I suspect some other application have put that file there, and
that is why it is not updated by Windows Updates.


> Mscorlib.dll is version 1.1.4322.2032


That means that you have SP1 of .Net Framework 1.1 installed (latest
version currently available).


> I did a reinstall and its still there.
>
> I am thinking of just replacing the gdiplus with the redistributable
> version.


Yes, that is what I would have done as well...


> However this would only fix this machine and I have a few others that show
> this as well.
> Besides I'd like to find out why WU is missing this and if its a problem to
> get it fixed.


See my earlier reasoning in this post.



--
torgeir, Microsoft MVP Scripting and WMI, Porsgrunn Norway
Administration scripting examples and an ONLINE version of
the 1328 page Scripting Guide:
http://www.microsoft.com/technet/scr...r/default.mspx
 
Reply With Quote
 
rr
Guest
Posts: n/a

 
      11-03-2004
Thanks Torgeir for verifying this. If other apps put vulnerable gdi files
in there it will make it tougher to find. I'll just update the dll on the
servers and rerun the gdiscan tool.

thanks for your help
rr



"Torgeir Bakken (MVP)" <Torgeir.Bakken-> wrote in message
news:%...
> rr wrote:
>
> > Thanks for the replies.
> >
> > The vulnerable file is
> > C:WINNT\Microsoft.NET\Framework\v1.1.4322\gdiplus. dll it is version
> > 5.1.3101.0.

>
> My Win2k3 Server installation does not have a gdiplus.dll file in that
> folder. I suspect some other application have put that file there, and
> that is why it is not updated by Windows Updates.
>
>
> > Mscorlib.dll is version 1.1.4322.2032

>
> That means that you have SP1 of .Net Framework 1.1 installed (latest
> version currently available).
>
>
> > I did a reinstall and its still there.
> >
> > I am thinking of just replacing the gdiplus with the redistributable
> > version.

>
> Yes, that is what I would have done as well...
>
>
> > However this would only fix this machine and I have a few others that

show
> > this as well.
> > Besides I'd like to find out why WU is missing this and if its a problem

to
> > get it fixed.

>
> See my earlier reasoning in this post.
>
>
>
> --
> torgeir, Microsoft MVP Scripting and WMI, Porsgrunn Norway
> Administration scripting examples and an ONLINE version of
> the 1328 page Scripting Guide:
> http://www.microsoft.com/technet/scr...r/default.mspx



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Bloodhound.Exploit.13 @@@lgyys Windows Vista Security 5 02-14-2009 10:35 PM
DOS Exploit????What is this? Paul Zavodnyik Windows Update 1 08-21-2004 03:12 AM
DSO Exploit Gennar Windows Update 2 05-18-2004 04:25 AM
Bloodhound.Exploit.6 Ross Ingram Windows Update 2 04-06-2004 03:16 PM
MIME exploit Ko Giezen Windows Update 0 02-27-2004 08:49 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59