PT-2007-1168 · Microsoft · Directx Sdk

Published

2007-07-18

·

Updated

2018-10-17

·

CVE-2006-4183

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Microsoft DirectX SDK versions prior to the fixed version
Description: A heap-based buffer overflow issue allows context-dependent attackers to execute arbitrary code via a crafted Targa file with run-length-encoding (RLE) compression that produces more data than expected when decoding. This issue affects Microsoft DirectX SDK, including 9.0c End User Runtimes.
Recommendations: For versions prior to the fixed version, update to a version that includes the fix for this issue to prevent exploitation. As a temporary workaround, consider restricting the handling of Targa files with RLE compression to minimize the risk of exploitation.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-4183

Affected Products

Directx Sdk