Microsoft's GDI Detetection Tool faults

albatross_at_tim.it
Date: 09/24/04

  • Next message: Sune Kloppenborg Jeppesen: "[ GLSA 200409-31 ] jabberd 1.x: Denial of Service vulnerability"
    Date: 24 Sep 2004 14:17:25 -0000
    To: bugtraq@securityfocus.com
    
    
    ('binary' encoding is not supported, stored as-is)

    Today I downloaded the a gdi+ vulnerability (MS04-028) detection tool published by The SANS. In contraddiction as the report provided by MS gdidettool.exe it found two version of vulnerable dlls.

    Be warned don't trust only MS's detection tool! Do all steps to patch your machines.

    albatross

    P.S. I think this will be another nightmare for many people.... any news about SUS 2.0/WUS?


  • Next message: Sune Kloppenborg Jeppesen: "[ GLSA 200409-31 ] jabberd 1.x: Denial of Service vulnerability"

    Relevant Pages

    • Automatically patching machine with hotfix KB824146 using mbsafu.
      ... I didn't want to spend as many hours patching machines with KB824146 exploit ... Mbsafu is an automatic remote patching tool that applies Security updates ... Download and install mbsa. ... Setup a network share with full privileges for the account you will patch ...
      (NT-Bugtraq)
    • Re: Event ID 6161 for HP 6840
      ... patch related to an exposure via the print spooler service. ... download which offers the option of a local port. ... >> There were no problems with the install and the printer works find so long ... >> 3) All machines on the network can connect to the printer via Internet ...
      (microsoft.public.windowsxp.print_fax)
    • Re: [fw-wiz] terminal services
      ... >> pointing out the danger of opening extra holes in your firewall. ... >that a VPN is a hole in the firewall, albeit generally a mitigated hole, ... >people didn't patch their machines. ...
      (Firewall-Wizards)
    • Re: 5.3-RELEASE TODO
      ... I haven't tested the last one (memory tuning on 4GB machines) ... * There may be a problem with swapping: ... >> He suggested a patch, but it did not fix the problem. ...
      (freebsd-current)
    • RE: [Full-Disclosure] RE: Probable new MS DCOM RPC worm for Windo ws
      ... machines that are missing them. ... While we have other decent tools available to check whether a patch has ... > installation logs. ... Full-Disclosure - We believe in it. ...
      (Full-Disclosure)