PT-2006-4910 · Microsoft · Msn Messenger+2
Published
2006-08-10
·
Updated
2018-10-17
·
CVE-2006-4066
CVSS v2.0
2.6
Low
| Vector | AV:N/AC:H/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows XP SP2
Description
The issue allows context-dependent attackers to cause a denial of service, resulting in an application crash, via certain images that trigger a divide-by-zero error. This can be demonstrated using specific file types, such as .ico, .png, and .jpg files, which can cause applications like MSN Messenger and Internet Explorer to crash.
Recommendations
For Microsoft Windows XP SP2, consider avoiding the use of potentially problematic image files until a resolution is provided. As a temporary workaround, restrict the handling of .ico, .png, and .jpg files in sensitive applications to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Internet Explorer
Msn Messenger
Windows Xp