Jump to content


This is a ready-only archive of the InstallSite Forum. You cannot post any new content here. / Dies ist ein Archiv des InstallSite Forums. Hier können keine neuen Beiträge veröffentlicht werden.
Photo

A Developer's View of the GDI+ Vulnerability


1 reply to this topic

Stefan Krueger

Stefan Krueger

    InstallSite.org

  • Administrators
  • 13,269 posts

Posted 21 September 2004 - 11:43

A Developer's View of the GDI+ Security Vulnerability

You've probably already heard about the critical security vulnerability that Microsoft has discovered in their GDI+ library. While most articles about this topic describe which actions you should take as a user of Microsoft products, I've written an article that focuses on the implications this vulnerability has for software developers, particularly in setup programs.

Note: You may be redistributing GDIPLUS.DLL without being aware of it. Many development tools have an option to automatically include required runtime files in your setup. In case of Windows Installer (MSI) tools this is usually accomplished by adding the gdiplus.msm merge module to your setup. Therefore it may not be immediately obvious to you that GDIPLUS.DLL is included in your setup.

Read the article:
http://www.installsi.../go/gdiplus.htm

Stefan Krueger

Stefan Krueger

    InstallSite.org

  • Administrators
  • 13,269 posts

Posted 28 September 2004 - 18:29

InstallShield has posted the fixed gdiplus.msm in their merge module gallery.