Re: Need to purge vulnerable gdiplus.dll?

From: Matthias Fichtner (mf-list_at_FICHTNER-MEYER.COM)
Date: 09/29/04

  • Next message: David Sentelle: "Re: WindowsUpdate V5 on XPSP1 broken"
    Date:         Wed, 29 Sep 2004 18:43:53 +0200

    Russ wrote:
    > I have received in excess of 10 responses from people
    > who have, one way or another, been replacing vulnerable
    > versions of gdiplus.dll (anywhere they find them) with the
    > updated version. *They* say they have not encountered any
    > problems.

    I've tried that approach and failed. For example, the
    current version of Microsoft's PowerPoint 2003 Viewer (as
    downloaded yesterday) crashes, if you replace its vulnerable
    gdiplus.dll with an updated version of the DLL.


    Matthias Fichtner [MF70-RIPE]
    NTBugtraq Editor's Note:
    Want to reply to the person who sent this message? This list is configured such that just hitting reply is going to result in the message coming to the list, not to the individual who sent the message. This was done to help reduce the number of Out of Office messages posters received. So if you want to send a reply just to the poster, you'll have to copy their email address out of the message and place it in your TO: field.

  • Next message: David Sentelle: "Re: WindowsUpdate V5 on XPSP1 broken"