Skip to main content

Microsoft Products GDI+ Multiple Vulnerabilities( 10 September 2008 )

Last Update Date: 28 Jan 2011 Release Date: 10 Sep 2008 4617 Views

RISK: Medium Risk

1. GDI+ VML Buffer Overrun Vulnerability

A remote code execution vulnerability exists in the way that GDI+ handles gradient sizes. The vulnerability could allow remote code execution if a user browses to a Web site that contains specially crafted content. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

2. GDI+ EMF Memory Corruption Vulnerability

A remote code execution vulnerability exists in the way that GDI+ handles memory allocation. The vulnerability could allow remote code execution if a user opens a specially crafted EMF image file or browses to a Web site that contains specially crafted content. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

3. GDI+ GIF Parsing Vulnerability

A remote code execution vulnerability exists in the way that GDI+ parses GIF images. The vulnerability could allow remote code execution if a user opens a specially crafted GIF image file or browses to a Web site that contains specially crafted content. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts.

4. GDI+ WMF Buffer Overrun Vulnerability

A remote code execution vulnerability exists in the way that GDI+ allocates memory for WMF image files. The vulnerability could allow remote code execution if a user opens a specially crafted WMF image file or browses to a Web site that contains specially crafted content. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

5. GDI+ BMP Integer Overflow Vulnerability

A remote code execution vulnerability exists in the way that GDI+ handles integer calculations. The vulnerability could allow remote code execution if a user opens a specially crafted BMP image file. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.


Impact

  • Remote Code Execution

System / Technologies affected

  • Windows XP
  • Windows Server 2003
  • Windows Vista
  • Windows Server 2008
  • Microsoft Windows 2000
  • Microsoft Internet Explorer 6
  • Microsoft .NET Framework 1.0
  • Microsoft .NET Framework 1.1
  • Microsoft .NET Framework 2.0
  • Microsoft Office XP
  • Microsoft Office 2003
  • 2007 Microsoft Office System
  • Microsoft Visio 2002
  • Microsoft Office PowerPoint Viewer 2003
  • Microsoft Works 8
  • Microsoft Digital Image Suite 2006
  • SQL Server 2000 Reporting Services
  • SQL Server 2005
  • Microsoft Visual Studio .NET 2002
  • Microsoft Visual Studio .NET 2003
  • Microsoft Visual Studio 2005 Service Pack 1
  • Microsoft Visual Studio 2008
  • Microsoft Report Viewer 2005 Service Pack 1 Redistributable Package
  • Microsoft Report Viewer 2008 Redistributable Package
  • Microsoft Visual FoxPro 8.0 when installed on Microsoft Windows 2000 Service Pack 4
  • Microsoft Visual FoxPro 9.0 when installed on Microsoft Windows 2000 Service Pack 4
  • Microsoft Platform SDK Redistributable: GDI+
  • Microsoft Forefront Client Security 1.0 when installed on Microsoft Windows 2000 Service Pack 4

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

Download locations for this patch


Vulnerability Identifier


Source


Related Link