CVE-2006-4066

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/08/2006
Last modified:
03/04/2025

Description

The Graphical Device Interface Plus library (gdiplus.dll) in Microsoft Windows XP SP2 allows context-dependent attackers to cause a denial of service (application crash) via certain images that trigger a divide-by-zero error, as demonstrated by a (1) .ico file, (2) .png file that crashes MSN Messenger, and (3) .jpg file that crashes Internet Explorer. NOTE: another researcher has not been able to reproduce this issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:microsoft:windows_xp:*:sp2:tablet_pc:*:*:*:*:*