Windows WMF vulerability affects Fx users?. What can we do?

User Help for Mozilla Firefox
Post Reply
satsuma
Posts: 7
Joined: January 4th, 2006, 4:40 pm
Location: Canada

Post by satsuma »

monkeyman wrote:Also available at MS TechNet for you Admin types:
http://www.microsoft.com/technet/securi ... 6-001.mspx


Is this the update that was scheduled for Jan. 10?

Is it best to uninstall Windows WMF Metafile Vulnerability HotFix 1.4 and re-register shimvgw.dll first before updating the MS patch?

thanks,
maggie
Firefox 1.5 on Win XP Pro, Ubuntu 5.10 on 2nd HD
WDGC
Posts: 299
Joined: March 11th, 2004, 9:05 pm

Post by WDGC »

satsuma wrote:
Is this the update that was scheduled for Jan. 10?




Yes.

.
monkeyman
Posts: 1183
Joined: April 2nd, 2003, 11:07 pm

Post by monkeyman »

satsuma wrote:
monkeyman wrote:Also available at MS TechNet for you Admin types:
http://www.microsoft.com/technet/securi ... 6-001.mspx


Is this the update that was scheduled for Jan. 10?

Is it best to uninstall Windows WMF Metafile Vulnerability HotFix 1.4 and re-register shimvgw.dll first before updating the MS patch?

thanks,
maggie


You don't need to reregister the .dll. Install the MS fix and then uninstall the "Windows WMF Metafile Vulnerability Hotfix" from Control Panel\Add/Remove programs.
Last edited by monkeyman on January 5th, 2006, 2:42 pm, edited 1 time in total.
satsuma
Posts: 7
Joined: January 4th, 2006, 4:40 pm
Location: Canada

Post by satsuma »

Thanks WDGC - I just checked over at Castlecops. In their WMF Exploit FAQ here http://castlecops.com/a6445-WMF_Exploit_FAQ.html they say shimvgw.dll can be re-registered after the MS update (#11). IN #22, they're saying that the WMF fix from Guilfanov

"...is written in such a way that it won't interfere with the official Microsoft patch, claims the author. However, you can un-install it either before or after the Microsoft patch is installed on your system".
Firefox 1.5 on Win XP Pro, Ubuntu 5.10 on 2nd HD
aragorn_499
Posts: 74
Joined: February 17th, 2005, 7:52 am

Post by aragorn_499 »

It's good to know, though, that there is at least an unofficial patch for us who are still using Windows 98SE! :-)
Guest
Guest

Post by Guest »

the update did nothing to stop the exploit in my machine. my AV stopped it before and it hasn't changed.....
User avatar
trolly
Moderator
Posts: 39851
Joined: August 22nd, 2005, 7:25 am

Post by trolly »

The MS update? You can not know that because AV got it first. If you are feeling lucky disable AV and try again.
Think for yourself. Otherwise you have to believe what other people tell you.
A society based on individualism is an oxymoron. || Freedom is at first the freedom to starve.
Constitution says: One man, one vote. Supreme court says: One dollar, one vote.
User avatar
Alice
Posts: 2628
Joined: April 23rd, 2003, 11:47 am

Post by Alice »

Windows Auto-Update notification told me about a Windows XP update to the Graphics Rendering Engine today, which turned out to be the patch I wasn't expecting until Jan 10th (to my surprise) after I checked the asociated link.

After installing the update and rerebooting, since I only did the shimgvw.dll workaround and NOT the unofficial patch all I had to do was re-register shimgvw.dll using Start > Run and typing:
regsvr32 %windir%\system32\shimgvw.dll

Then I found a *.wmf file (in C:\Program Files\Microsoft Office\media\cagcat10) and it opened just fine in the Windows Picture and Fax Viewer (which I had left associated with .WMF). Thumbnails are also working.
Alice Wyman
satsuma
Posts: 7
Joined: January 4th, 2006, 4:40 pm
Location: Canada

Post by satsuma »

After doing the MS update & uninstalling the Windows WMF Metafile Vulnerability Hotfix 1.4, I left the .dll un-registered.

I went to change my desktop background back to one that came with XP, since I'd been using a BBC Dr. Who background after Canada got the Xmas special last week. Several that worked before no longer did. I re-registered "regsvr32 %windir%\system32\shimgvw.dll" (no quotes) and now they all work again.
Firefox 1.5 on Win XP Pro, Ubuntu 5.10 on 2nd HD
the best
Guest

Post by the best »

Norton caught it for me and FF kept it from executing. No problem.
Post Reply