PT-2004-2820 · Microsoft · Internet Explorer

Arman Nayyeri

·

Publicado

2004-04-11

·

Atualizado

2021-07-23

·

CVE-2004-1922

CVSS v2.0

2.6

Baixa

VetorAV:N/AC:H/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Internet Explorer versions 5.5 through 6.0
Description The issue allows remote attackers to cause a denial of service due to memory consumption. This is achieved by using a small BMP file that has a large memory size, which causes the software to allocate memory based on the written memory size instead of the actual file size.
Recommendations For Microsoft Internet Explorer versions 5.5 through 6.0, consider avoiding the use of BMP files with large memory sizes until a fix is available. As a temporary workaround, restrict access to potentially malicious BMP files to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-1922

Produtos afetados

Internet Explorer