PT-2002-2169 · Microsoft · Internet Explorer
Published
2002-12-11
·
Updated
2021-07-23
·
CVE-2002-1185
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
Internet Explorer versions 5.01 through 6.0
Description:
The issue arises from improper checking of certain parameters in a PNG file, leading to a heap-based buffer overflow when invalid length codes are encountered during decompression. This can cause a denial of service, resulting in a crash.
Recommendations:
For Internet Explorer versions 5.01 through 6.0, consider avoiding the use of PNG images until a patch is available, or restrict access to potentially malicious PNG files to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Internet Explorer