Buffer Overrun in Microsoft JPEG Processing (GDI+)

A buffer-overrun vulnerability in the processing of JPEG image formats could allow remote code execution on a vulnerable system.

Ken Pfeil

September 14, 2004

1 Min Read
ITPro Today logo

Reported September 14, 2004, byMicrosoft

VERSIONS AFFECTED

DESCRIPTION
A buffer-overrun vulnerability in the processing of JPEG image formats couldallow remote code execution on a vulnerable system. Any program that processesJPEG images on the affected systems could be vulnerable to this attack, ascould any system that uses the affected programs or components. A potentialattacker who successfully exploited this vulnerability could take completecontrol of an affected system.

VENDOR RESPONSE
Microsoft has releasedsecurity bulletin MS04-028, "Buffer Overrun in JPEG Processing (GDI+)Could Allow Code Execution (833987)," to address this vulnerability andrecommends that affected users immediately apply the appropriate patch listedin the bulletin.

CREDIT
Discovered by Nick DeBaggis.

Read more about:

Microsoft
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like