PT-2006-4915 · Microsoft · Windows+1

Cyanid-E

·

Publicado

2006-08-10

·

Atualizado

2018-10-17

·

CVE-2006-4071

CVSS v2.0

2.6

Baixa

VetorAV:N/AC:H/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Windows versions prior to the fixed version
Description The issue is related to a sign extension vulnerability in the createBrushIndirect function within the GDI library (gdi32.dll). This vulnerability allows user-assisted attackers to cause a denial of service, resulting in an application crash, by using a crafted WMF file.
Recommendations For Microsoft Windows versions prior to the fixed version, update to the latest version to resolve the issue. As a temporary workaround, consider restricting the use of WMF files to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-4071

Produtos afetados

Gdi
Windows