PT-2004-2820 · Microsoft · Internet Explorer
Arman Nayyeri
·
Publicado
2004-04-11
·
Atualizado
2021-07-23
·
CVE-2004-1922
CVSS v2.0
2.6
Baixa
| Vetor | AV:N/AC:H/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Internet Explorer versions 5.5 through 6.0
Description
The issue allows remote attackers to cause a denial of service due to memory consumption. This is achieved by using a small BMP file that has a large memory size, which causes the software to allocate memory based on the written memory size instead of the actual file size.
Recommendations
For Microsoft Internet Explorer versions 5.5 through 6.0, consider avoiding the use of BMP files with large memory sizes until a fix is available. As a temporary workaround, restrict access to potentially malicious BMP files to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Internet Explorer