Tordex Community
gdiplus.dll virus vulnerability - Printable Version

+- Tordex Community (http://forum.tordex.com)
+-- Forum: True Launch Bar (http://forum.tordex.com/forum-3.html)
+--- Forum: Bugs (http://forum.tordex.com/forum-10.html)
+--- Thread: gdiplus.dll virus vulnerability (/thread-1650.html)



- masterbrox - 09-27-2004

TLB 3.1 includes a vulnerable version of the file gdiplus.dll. Potentially, someone could distribute a plugin or skin with a virus in a JPEG file. There are updated versions of the gdiplus.dll file, but it needs to be included in TBL.

http://www.microsoft.com/technet/security/bulletin/ms04-028.mspx

http://isc.sans.org/gdiscan.php


- rothlis - 09-28-2004

That's interesting... I'm running 3.1 and gdiscan doesn't report any such DLL as part of TLB. I wonder if it came with one of the plugins?


- Yuri Kobets - 09-28-2004

TLB Clock is the only plugin that uses gdiplus.dll
Thank you for note.


- Guest - 09-29-2004

Hi

just for your info the drivespace plugin uses gdiplus.dll to.

cu jens


- Yuri Kobets - 09-29-2004

jens you need update for Drive Space. The last version do not use gdiplus.

Also note if you download updated gdiplus.dll from microsoft the old version will not be installed.