Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

September 23, 2004 12:00 AM

Update: New Tools Help with JPEG GDI+ Updates

Windows IT Pro
InstantDoc ID #44003
Rating: (3)

Eric Brunsen released a new tool that can help you locate all copies of gdiplus.dll files on your systems to determine which copies might need to be updated to defend against the recently discovered JPEG GDI+ vulnerability (MS04-028).

Brunsen's toolkit, which requires Microsoft .NET Framework 1.1 to operate, can scan systems, both locally and over a network, and produce a report that reveals where the files are located, what the DLL version is, and what the file creation dates were. You can download a copy of the tool which is available for free on the Web, and read more about what Brunsen had to say about the tool in the Patch Management mailing list archives.

But be aware that you might need to replace more files than just the gdiplus.dll in order to completely protect yourselves against intrusion. Be sure to read Microsoft's bulletin for complete details, which explains nuances with products such as Office XP, Visio 2002, Project 2002, and Internet Explorer 6 Service Pack 1 (SP1) that might need to have other files updated too, such as mso.dll.

To help with identifying all affected DLLs (including gdiplus.dll, mso.dll, sxs.dll, and wsxs.dll), Tim Liston wrote a tool, gdiscan.exe, which can locate such files and produced a report that helps you patch the right files. Liston's tool, which is available as a Windows desktop application or command line tool, can colorize its report so that vulnerable DLLs appear in a red font.

Liston's tool is a different from Brunsen's tool in that Liston's tool requires no options. As soon as the tool is run it begins scanning the Windows system drive for vulnerable DLL files. It appears that Liston's tool won't scan over a network, or scan drives other than the drive that contains the Windows system directory. Nevertheless you might find the tool handy, especially since there is a command line version available, which is useful for scripting purposes. You can download a copy of online. There's a Web page describing the tool and links to the download at the Internet Storm Center.

Related Content:

ARTICLE TOOLS

Comments
  • Anonymous User
    7 years ago
    Feb 17, 2005

    Need the tool to keep up to date

  • KARL
    8 years ago
    Sep 29, 2004

    Note: The GDIScan tool posted on the Internet Storm Center site has been updated: it now allows scanning of arbitrary drives. In addition, there is also a GUI-based version.

  • TOM
    8 years ago
    Sep 29, 2004

    Very helpful

You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.