Request a statement on the WMF situation when using GFL SDK

Discussions on GFL SDK, the graphic library for reading and writing graphic files

Moderators: XnTriq, helmut, xnview

sekakemp
Posts: 1
Joined: Thu Jan 05, 2006 4:12 pm

Request a statement on the WMF situation when using GFL SDK

Post by sekakemp »

Has there been an official statement regarding whether using the GFL SDK for converting WMF files is subject to the vulnerability we're hearing about?

I saw a message in another forum that claimed XNView crashed when trying to load a tainted WMF. It is difficult to say whether that might have been due to the browsing dialog to find the file, or whether it was in the underlying GFL code. And then there is the question of whether that might have executed the malicious code embedded therein.
User avatar
xnview
Author of XnView
Posts: 44920
Joined: Mon Oct 13, 2003 7:31 am
Location: France

Re: Request a statement on the WMF situation when using GFL

Post by xnview »

sekakemp wrote:Has there been an official statement regarding whether using the GFL SDK for converting WMF files is subject to the vulnerability we're hearing about?

I saw a message in another forum that claimed XNView crashed when trying to load a tainted WMF. It is difficult to say whether that might have been due to the browsing dialog to find the file, or whether it was in the underlying GFL code. And then there is the question of whether that might have executed the malicious code embedded therein.
GFL SDK use windows API, so if the problem is fixed for windows API, it will be fixed for GFL SDK...
Pierre.