Secunia CSI7
Advisories
Research
Forums
Create Profile
Our Commitment
PSI
PSI API
CSI
OSI
xSI
Vulnerabilities
Programs
Open Discussions
My Threads
Create Thread
Statistics
About

Forum Thread: Scan results show zero threats; Insecure Programs list still show...

You are currently viewing a forum thread in the Secunia Community Forum. Please note that opinions expressed here are not of Secunia but solely reflect those of the user who wrote it.

This thread was submitted in the following forum:
PSI

This thread has been marked as locked.
This user no longer exists Scan results show zero threats; Insecure Programs list still shows the threat
Member 5th Feb, 2010 03:43
Ranking: 0
Posts: 4
User Since: 1st Jan, 1970
System Score: N/A
Location: N/A
My Operating System: Windows XP

I carried out the required update (to Adobe SVG Viewer 3.03) to fix the security threat, using both Firefox and IE, with identical results. The scan returned zero threats but the item remains on the Insecure Programs list after a re-scan.

How shall I proceed?

Regards,

thedillpickl RE: Scan results show zero threats; Insecure Programs list still shows the threat
Contributor 5th Feb, 2010 05:02
Score: 376
Posts: 872
User Since: 3rd May 2009
System Score: 100%
Location: US
Hi sb3straw;

You may have two threads for the same topic, if so, use one & let the other die.

Adobe products can be a pain. Often, after updating, there are leftover files that the updater 'forgot'.

To find out what's going on: To run PSI in Advanced mode, open PSI, in the top right corner, is "Simple" blue in color and "Advanced" black? If not click on "Advanced". Click on the "Insecure Programs" tab, click on the [+] to the left of the program to open the Toolbox. Click on the "Technical details" icon. Please tell us the file path, etc. In the "Folder" icon you will find the folder that PSI has found the insecure file(s). One or more may have an old date stamp or version # (hover mouse over filename for most or right click properties for the rest).

Post back with your findings.


regards;

Fred

--
XP Home
Chrome, Firefox, IE8
--
consilio et animis
Was this reply relevant?
+0
-0
This user no longer exists RE: Scan results show zero threats; Insecure Programs list still shows the threat
Member 5th Feb, 2010 22:21
Hi Fred,

Thanks for your reply. Following your instructions:

The potential threat is End of Life. Adobe has discontinued support for Adobe SVG Viewer.

The Path: C:\Program Files\Common Files\Adobe\SVGCore.dll

The link offered for further information is:
http://www.adobe.com/svg/eol.html

I have found the Folder with insecure file(s). It contains one Uninstall folder and 16 file folders, including SVG files,two Firefox documents and a zipped file. What should I do here?
Was this reply relevant?
+0
-0
thedillpickl RE: Scan results show zero threats; Insecure Programs list still shows the threat
Contributor 6th Feb, 2010 21:54
Score: 376
Posts: 872
User Since: 3rd May 2009
System Score: 100%
Location: US
Hi sb3straw;

After you reminded me that Adobe SVG is EOL I remembered that I had done this before. Please look at this thread with the same problem http://secunia.com/community/forum/thread/show/330... .

I had found some 'replacements' for SVG which should work. Be aware that I did no tests & no one has responded back on that thread with a report as to the use of my suggestion.

If one does work for you I would suggest removing the SVG folder to a thumb drive or other removable media unless you know the other files (that are not Adobe) are not needed. If everything works then you didn't need them.


Fred

--
XP Home
Chrome, Firefox, IE8
--
consilio et animis
Was this reply relevant?
+0
-0
This user no longer exists RE: Scan results show zero threats; Insecure Programs list still shows the threat
Member 9th Feb, 2010 05:12
Hi Fred,

Thanks for the further suggestions. I applied the "ignore" option. It seemed appropriate for the situation - no problems so far.

The idea of removing the files to a thumb drive is interesting and might come in handy in the future.

Regards,
Was this reply relevant?
+0
-0
thedillpickl RE: Scan results show zero threats; Insecure Programs list still shows the threat
Contributor 10th Feb, 2010 04:28
Score: 376
Posts: 872
User Since: 3rd May 2009
System Score: 100%
Location: US
Hi sb3straw;

The ignore rule will work if your not wanting to have PSI show it as insecure. Just be certain that's the best solution for you. The SVG will still be vulnerable even though it's not reported.


best of luck;

Fred

--
XP Home
Chrome, Firefox, IE8
--
consilio et animis
Was this reply relevant?
+0
-0

This thread has been marked as locked.


 Products Solutions Customers Partner Resources Company
 
 Corporate
Vulnerability Intelligence Manager (VIM)
Corporate Software Inspector (CSI)
Consumer
Personal Software Inspector (PSI)
Online Software Inspector (OSI)
 Industry
Compliance
Technology
Integration
 Customers
Testimonials
 VARS
MSSP
Technology Partners
References
 Reports
Webinars
Events
 About us
Careers
Memberships
Newsroom


 
© 2002-2014 Secunia ApS - Rued Langgaards Vej 8, 4th floor, DK-2300 Copenhagen, Denmark - +45 7020 5144
Terms & Conditions and Copyright - Privacy - Report Vulnerability