Infesting you with Virus News
 

Vulnerabilities

Off-by-one error in the GpFont::SetData function in gdiplus.dll in Microsoft... (PC1-2009-0835)

Overview

Vulnerability chart

Overview:
Off-by-one error in the GpFont::SetData function in gdiplus.dll in Microsoft GDI+ on Windows XP was detected.
Vulnerable:
Windows XP
DDOS
Unknown patch
availability
Patch implementation
unknown

References to Advisories, Solutions, and Tools

Release date: 2009-04-01
Description:

By using off-by-one error in the GpFont::SetData function in gdiplus.dll in Microsoft GDI+ on Windows XP, remote attackers are enabled to provoke a denial of service, that is to say stack corruption and application termination. It is created through a crafted EMF file that triggers an integer overflow. It was established by voltage-exploit.emf, aka the "Microsoft GdiPlus EMF GpFont.SetData integer overflow."

Impact:

If off-by-one error in the GpFont::SetData function in gdiplus.dll in Microsoft GDI+ on Windows XP vulnerability is used, unauthorized revelation of information, unauthorized modification and disruption of service is enabled.

References: http://xforce.iss.net/xforce/xfdb/49438 http://www.vupen.com/english/advisories/2009/0832 http://blogs.technet.com/srd/archive/2009/03/26/new-emf-gdiplus-dll-crash-not-exploitable-for-code-execution.aspx http://bl4cksecurity.blogspot.com/2009/03/microsoft-gdiplus-emf-gpfontsetdata.html

Impact

CVSS Severity

CVSS Version 2 Metrics:

CVSS v2 Base Score:5.8 (MEDIUM)Access Vector: Network exploitable; Victim must voluntarily interact with attack mechanism
Impact Subscore: 10.0Access Complexity: Medium
Exploitability Subscore: 8.6Authentication: Not required to exploit
Impact Type:Allows unauthorized disclosure of information; Allows unauthorized modification; Allows disruption of service

Say something interesting!

Name:
Email:
Website:
Comment:
Please type 5-digit security code below:
Captcha image for spam protection

Home > Vulnerabilities > pc1-2009-0835