PT-2008-5426 · Microsoft · Internet Explorer

Published

2008-09-18

·

Updated

2021-07-23

·

CVE-2008-4127

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Internet Explorer versions 7.0.5730 through 8.0.6001
Description The issue is related to a crafted PNG file that can cause a denial of service, specifically the failure of subsequent image rendering. This is due to an infinite loop in the CDwnTaskExec::ThreadExec function.
Recommendations For Microsoft Internet Explorer version 7.0.5730, consider avoiding the use of crafted PNG files until a fix is available. For Microsoft Internet Explorer version 8.0.6001, consider disabling the CDwnTaskExec::ThreadExec function as a temporary workaround until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-4127

Affected Products

Internet Explorer