OSVDB ID: 9951

Title: Microsoft Multiple Products GDIPlus.dll JPEG Processing Overflow

Info

Disclosure

Sep 14, 2004

Discovery

Unknown

Dates

Exploit

Sep 21, 2004

Solution

Unknown

Description

A local overflow exists in multiple Microsoft products which rely on gdiplus.dll for image processing. The gdiplus.dll fails to validate JPEG image files resulting in a buffer overflow. With a specially crafted image file, an attacker can cause arbitrary code execution resulting in a loss of integrity.

Classification

Location: Local Access Required
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Available
Disclosure: OSVDB Verified

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, Microsoft has released a patch to address this vulnerability.

Products

Microsoft Corporation

Windows

XP
XP SP1
XP 64-Bit SP1
XP 64-Bit 2003
2003 Server x64
2003 Server

Office

XP SP3
XP SP2
2003

Outlook

2002
2003

Word

2002
2003

Excel

2002
2003

PowerPoint

2002
2003

FrontPage

2002
2003

Access

2002
2003

Publisher

2003

InfoPath

2003

OnePath

2003

Project

2002
2002 Service Pack 1
2003

Visio

2002 Service Pack 1
2002 Service Pack 2
2003

Visual Studio .NET

2002
2003

Visual Basic .NET

2002
2003

Visual C# .NET

2002
2003

Visual C++ .NET

2002
2003

.NET Framework SDK

1.0 Service Pack 2

Picture It!

2002
7.0
9

Greetings

2002

Digital Image Pro

7.0
9

Digital Image Suite

9

Producer for Microsoft Office PowerPoint

All Versions

Platform SDK Redistributable: GDI+

All Versions

Internet Explorer

6 Service Pack 1

.NET Framework

1.0 Service Pack 2
1.1

Business Objects

Crystal Enterprise

10

Website Pros

NetObjects Fusion

8.00.0000.5009

TiVo

TiVo Desktop for Windows

1.2

References

Credit

  • Nick DeBaggis - ndebaggisBrand New Doo Dooverizon.net -


Direct URL: http://osvdb.org/36218