JPEGScan 1.01

JPEGScan 1.01 Screenshot On September 14 2004, Nick DeBaggis discovered a buffer overrun vulnerability in gdiplus.

Developer:   DiamondCS
      software by DiamondCS →
Price:  0.00
License:   Freeware
File size:   0K
Language:   
OS:   Windows Vista (?)
Rating:   0 /5 (0 votes)

On September 14 2004, Nick DeBaggis discovered a buffer overrun vulnerability in gdiplus.dll - a library used by many common applications (including most Microsoft applications) for viewing JPEG images.

Subsequent analysis by the eEye team confirmed that the vulnerability could be exploited to execute arbitrary code, allowing an attacker to gain control of a remote system simply by enticing the victim to look at a specially-crafted JPEG image. MS04-028 is the tracking code assigned by Microsoft to this specific vulnerability.

If the program used to view the JPEG file uses a vulnerable version of gdiplus.dll then yes, and unfortunately a lot of software is affected. To scan for vulnerable versions of gdiplus.dll on your system please see these resources: Microsoft SANS

DiamondCS JPEGScan is a free, small, fast and easy-to-use scanner that has detection and repair capabilities for JPEG files infected with the MS04-028 exploit.

JPEGScan can detect all known variants of the exploit, and accomplishes this not by string searching or anti-viral signature scanning but rather by properly walking through all blocks in the JPEG searching for the undersized boundaries in comment sections that indicates the presence of MS04-028 infection.

Repairing renders the file harmless by readjusting undersized boundaries to their proper size, and if the file was based on a real JPEG then it should also become viewable.

If you simply want infected files deleted rather than repaired, JPEGScan can handle that also.

JPEGScan also allows for one-click integration into Explorer's context menu, allowing you to easily right-click on any file, directory or drive and start scanning immediately for infected JPEG images.

Although all users will find this tool useful, network administrators in particular will enjoy being able to sweep entire networks for infected images. For reasons of speed, optimization and accuracy, the main scan routines were written in assembly language, making JPEGScan basically as fast as it possibly can be

tags gdiplus dll  ms04 028  the file  for infected  undersized boundaries  the jpeg  jpeg images  jpegscan can  

JPEGScan 1.01 screenshot


Download JPEGScan 1.01

 Download JPEGScan 1.01


Similar software

JPEGScan 1.01 JPEGScan 1.01
DiamondCS

On September 14 2004, Nick DeBaggis discovered a buffer overrun vulnerability in gdiplus.

VNC Flaw Test 2.0 VNC Flaw Test 2.0
IntelliNavigator Inc

VNC Flaw Test - Test your VNC installations for vulnerability It was almost over a month ago that we discovered a major vulnerability in VNC 4.

Backdoor Guard 1.0.0.3 Backdoor Guard 1.0.0.3
Malware Remover

BackdoorGuard Award-Winning Firewall Software.

MSN Nick Changer for Windows Media Player 1b MSN Nick Changer for Windows Media Player 1b
S3ven

MSN Nick Changer for Windows Media Player is the second conversion of my plugin which allow you to display in your MSN messenger's nick the current song you're listening.

Buffer Synth 1.10 Buffer Synth 1.10
Niall Moody

Buffer Synth writes the input audio to a buffer and them lets you 'play' it (i.

MSN Nick Changer 0.4 MSN Nick Changer 0.4
S3ven

MSN Nick Changer is a winamp plugin wich allow you to insert the currently played winamp song in your msn nickname.

Heap/stack buffer overflow monitor 1.0 Heap/stack buffer overflow monitor 1.0
AVDOW Software

Heap/stack buffer overflow monitor is the next-generation in innovative anti-virus technology for PCs and servers.

IESecure 0.1 IESecure 0.1
Maxthon

A critical vulnerability has been found in Internet Explorer which is caused due to a boundary error in the handling of certain attributes in the IFRAME, FRAME, and EMBED HTML tags.

SOAPSonar Enterprise Edition 2.0 SOAPSonar Enterprise Edition 2.0
Crosscheck Networks

SOAP SONAR Enterprise Edition is a useful program that provides powerful Web Services Functional Testing, Performance Loading, Compliance Testing and Vulnerability Assessment to Enterprises focused on deploying enterprise-class robust Web Services within their infrastructure.

SecureCentral ScanFi Free Edition 4.1 SecureCentral ScanFi Free Edition 4.1
AdventNet Inc.

ScanFi is a web-based vulnerability assessment scanner for detecting and assessing network vulnerabilities across heterogeneous networks.