GDI Library Could Be Used to Cause DoS

he graphics device interface (GDI) library lacks validity checking, and this oversight could allow a specially crafted Enhanced MetaFile (EMF) to cause a denial of service (DoS) by crashing an affected application.

ITPro Today

March 20, 2005

1 Min Read
ITPro Today logo


Reported March 17,2005, by Hongzhen Zhou

VERSIONS AFFECTED

        Windows 2000 platforms

DESCRIPTION

The graphics deviceinterface (GDI) library lacks validity checking, and this oversightcould allow a specially crafted Enhanced MetaFile (EMF) to cause adenial of service (DoS) by crashing an affected application.

VENDOR RESPONSE

No patch is available yet to correct this problem.

CREDIT
Discovered by Hongzhen Zhou

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like