CVE-2010-1098 Information

Description

The ANI parser in Microsoft Windows before 7 on the x86 platform as used in Internet Explorer and other applications allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted biClrUsed value in the BITMAPINFO header of a .ANI file.

Reference

http://code.google.com/p/skylined/issues/detail?id=3 http://skypher.com/index.php/2010/03/08/ani-file-bitmapinfoheader-biclrused-bounds-check-missing/ http://www.securityfocus.com/bid/38579 https://exchange.xforce.ibmcloud.com/vulnerabilities/56756

Share on: