Results 1 to 4 of 4

Thread: Gdiplus.dll concern - security

  1. #1
    JPM Guest

    Gdiplus.dll concern - security

    One of Microsoft's latest security updates, MS04-028 concerns the buffer overrun/jpg problem which involves updating GDI+. I see that the AutoCAD installation has a couple of instances of gdiplus.dll. Is the buffer overrun of concern in the AutoCAD environment?
    Thanks,
    JPM

  2. #2
    Cy Shuster Guest
    It's my understanding that AutoCAD (and 3ds max) included gdiplus.dll from
    Microsoft with those products, since it wasn't always part of the OS. Now
    that Microsoft has updated it, you should use the updated DLL (which is
    included with XP SP2).

    It should be safe to copy the updated DLL to replace any existing
    gdiplus.dll's currently installed. If you have XP, I believe that after
    installing Microsoft's updated DLL in the Windows folder, you can simply
    delete the other copies of the dll, but this might have implications for
    uninstall or patching.

    The vulnerability comes from opening JPGs, regardless of the calling
    program.

    --Cy--

    From Discreet:

    From Late Breaking 3dsmax bulletins @
    http://www.discreet.com/support/max/...dstudio&id=862

    GDIPlus.dll Security Threat Hotfix
    Posted: September 30, 2004

    Background:

    3ds max uses a DLL called GdiPlus.dll, provided by Microsoft. Older versions
    of the file, including that of Discreet, have been discovered to contain a
    vulnerability that allows worms/viruses to be executed from within JPG
    images.

    Resolution:

    To resolve this Security Threat:

    Go to http://isc.sans.org/gdiscan.php
    Download the utility
    Run the test
    If the result is the same as bellow, then follow steps 1 or 2 depending on
    your OS.

    C:\3dsmax6\GdiPlus.dll
    Version: 5.1.3100.0

    For Windows XP, simply delete the file and run a windows update.

    For older versions of Windows, go to Microsoft's website, download the new
    GDIPlus.DLL and replace the older one.

    More information at:
    http://www.microsoft.com/technet/sec.../ms04-028.mspx



    "JPM" <nospam@address.withheld> wrote in message
    news:7959257.1097160488081.JavaMail.jive@jiveforum 1.autodesk.com...
    One of Microsoft's latest security updates, MS04-028 concerns the buffer
    overrun/jpg problem which involves updating GDI+. I see that the AutoCAD
    installation has a couple of instances of gdiplus.dll. Is the buffer
    overrun of concern in the AutoCAD environment?
    Thanks,
    JPM

  3. #3
    Bud Schroeder [Autodesk I Guest
    Hello,

    As Cy pointed out, you can use the latest version of this file from
    Microsoft. We are still doing some testing on this but that is the solution
    here. Once we have finished testing this a solution will be posted to the
    WEB Site.

    Hope this helps and thanks for posting to the News Groups.

    Bud Schroeder
    AutoCAD Test Development
    Autodesk Inc.


    "JPM" <nospam@address.withheld> wrote in message
    news:7959257.1097160488081.JavaMail.jive@jiveforum 1.autodesk.com...
    One of Microsoft's latest security updates, MS04-028 concerns the buffer
    overrun/jpg problem which involves updating GDI+. I see that the AutoCAD
    installation has a couple of instances of gdiplus.dll. Is the buffer
    overrun of concern in the AutoCAD environment?
    Thanks,
    JPM

  4. #4
    JPM Guest
    Cy and Bud,
    Thanks for your responses. I look forward to the results of AutoDesk's tests.
    It is unfortunate that it will be a bit of a problem to distribute the patch to all of my users (100+), but I will have to work on that.
    JPM

Similar Threads

  1. Security issue
    By dlevy in forum SolidWorks
    Replies: 7
    Last Post: 08-17-2005, 01:10 PM
  2. Security Alert- LienVandeKelder.exe
    By John Scheldroup in forum SolidWorks
    Replies: 7
    Last Post: 05-18-2005, 01:10 AM
  3. Security System
    By stevan in forum AutoCAD
    Replies: 3
    Last Post: 02-07-2005, 09:07 AM
  4. Solidworks 2005 Concern
    By Larry Zolla in forum SolidWorks
    Replies: 10
    Last Post: 12-18-2004, 04:44 PM
  5. Network Security?
    By Kerry Fontenot in forum Network
    Replies: 3
    Last Post: 08-18-2004, 09:55 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Other forums: Access Forum - Microsoft Office Forum - Exchange Server Forum