Secunia Advisory SA36634Microsoft Windows Paint JPEG Parsing Integer Overflow Vulnerability
|
||||
Description
Tielei Wang has discovered a vulnerability in Microsoft Windows, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an integer overflow error in Microsoft Paint when parsing certain image content. This can be exploited to cause a heap-based buffer overflow by tricking a user into viewing a specially crafted JPEG image. Successful exploitation may allow execution of arbitrary code. Solution Provided and/or discovered by Other references Technical Analysis Alternate/detailed remediation Deep Links Discuss this advisoryA new thread in our forum is automatically created for each posted Secunia Advisory. Activate the thread by commenting/discussing below.
|
||||