CVE Database
/

CVE-2008-4327

Back to search

CVE-2008-4327

Published: Sep 30, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

gdiplus.dll in GDI+ in Microsoft Windows XP SP3 does not properly handle crafted .ico files, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a certain crash.ico file on a web site, and allows user-assisted attackers to cause a denial of service (divide-by-zero error and persistent application crash) via this crash.ico file on the desktop, a different vulnerability than CVE-2007-2237.

VendorProductVersions

n/a

n/a

affected
n/a

References

windowsxp-gdiplus-dos(45464)
vdb-entry
x_refsource_XF
31432
vdb-entry
x_refsource_BID
6588
exploit
x_refsource_EXPLOIT-DB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now