GDI+ Exploit

JingleBells

FH is my second home
Joined
Mar 25, 2004
Messages
2,224
I downloaded the scanning tool: Slashdot article,
and its results say i have these two dlls:
C:\program files\Symantec\Web Tools\GDIPlus.dll
C:\program files\WS_FTP Pro\gdiplus.dll
that are vulnerable to the GDI exploit. Can i just replace them with a newer version of GDIPlus.dll?
 

Xavier

Can't get enough of FH
Joined
Dec 22, 2003
Messages
1,542
If you've patched Windows via Windows Update you shouldn't have any worries as the machine will use the copy of GDIPlus within windows/system32 over copies supplied within application folders...

go! update!

http://windowsupdate.microsoft.com
 

JingleBells

FH is my second home
Joined
Mar 25, 2004
Messages
2,224
Ran windows update ages ago when the exploit was first announced, nowt new on there, check most days, scanner still says that WS-FTP and Symantec have old versions of the dll, I had to go on quite a hunt through the windows site to find the relevant office and VS patches though.
Live Update hasn't updated the dll, and to update WS-FTP will require me to get the latest version (v9 as opposed to v8).
 

Xavier

Can't get enough of FH
Joined
Dec 22, 2003
Messages
1,542
as a test, I'd rename the old copies and see if it forces the apps to use the native windows version...
 

Users who are viewing this thread

Top Bottom