PT-2008-5426 · Microsoft · Internet Explorer
Published
2008-09-18
·
Updated
2021-07-23
·
CVE-2008-4127
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Internet Explorer versions 7.0.5730 through 8.0.6001
Description
The issue is related to a crafted PNG file that can cause a denial of service, specifically the failure of subsequent image rendering. This is due to an infinite loop in the
CDwnTaskExec::ThreadExec function.Recommendations
For Microsoft Internet Explorer version 7.0.5730, consider avoiding the use of crafted PNG files until a fix is available.
For Microsoft Internet Explorer version 8.0.6001, consider disabling the
CDwnTaskExec::ThreadExec function as a temporary workaround until a patch is available.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Internet Explorer