Описание
Microsoft Windows Graphics Device Interface (GDI+, GdiPlus.dll) allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, which triggers a divide-by-zero error.
Ссылки
- Broken Link
- Broken Link
- Third Party AdvisoryUS Government Resource
- Broken LinkThird Party AdvisoryVDB Entry
- Broken LinkThird Party AdvisoryVDB Entry
- Broken LinkThird Party AdvisoryVDB Entry
- Broken Link
- VDB EntryVendor Advisory
- Third Party AdvisoryVDB Entry
- Broken Link
- Broken Link
- Third Party AdvisoryUS Government Resource
- Broken LinkThird Party AdvisoryVDB Entry
- Broken LinkThird Party AdvisoryVDB Entry
- Broken LinkThird Party AdvisoryVDB Entry
- Broken Link
- VDB EntryVendor Advisory
- Third Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:o:microsoft:windows_xp:-:sp2:*:*:*:*:*:*
EPSS
Процентиль: 98%
0.60518
Средний
5.5 Medium
CVSS3
7.1 High
CVSS2
Дефекты
CWE-369
Связанные уязвимости
CVSS3: 5.5
github
почти 4 года назад
Microsoft Windows Graphics Device Interface (GDI+, GdiPlus.dll) allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, which triggers a divide-by-zero error.
EPSS
Процентиль: 98%
0.60518
Средний
5.5 Medium
CVSS3
7.1 High
CVSS2
Дефекты
CWE-369