[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2005-4560Date: (C)2005-12-28   (M)2023-12-22


The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) format image with a crafted SETABORTPROC GDI Escape function call, related to the Windows Picture and Fax Viewer (SHIMGVW.DLL), a different vulnerability than CVE-2005-2123 and CVE-2005-2124, and as originally discovered in the wild on unionseek.com.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.5
Exploit Score: 10.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECTRACK-1015416
BID-16074
SECUNIA-18255
SECUNIA-18311
SECUNIA-18364
SECUNIA-18415
http://www.securityfocus.com/archive/1/420351/100/0/threaded
http://www.securityfocus.com/archive/1/420288/100/0/threaded
http://www.securityfocus.com/archive/1/420357/100/0/threaded
http://www.securityfocus.com/archive/1/420367/100/0/threaded
http://www.securityfocus.com/archive/1/420378/100/0/threaded
http://www.securityfocus.com/archive/1/420546/30/7730/threaded
http://www.securityfocus.com/archive/1/420446/100/0/threaded
http://www.securityfocus.com/archive/1/420664/30/7730/threaded
http://www.securityfocus.com/archive/1/420687/100/0/threaded
http://www.securityfocus.com/archive/1/420684/100/0/threaded
20060103
http://www.securityfocus.com/archive/1/420682/100/0/threaded
http://www.securityfocus.com/archive/1/420773/100/0/threaded
ADV-2005-3086
MS06-001
TA05-362A
TA06-005A
VU#181038
http://linuxbox.org/pipermail/funsec/2006-January/002455.html
http://support.avaya.com/elmodocs2/security/ASA-2006-001.htm
http://vil.mcafeesecurity.com/vil/content/v_137760.htm
http://www.f-secure.com/weblog/archives/archive-122005.html#00000753
http://www.microsoft.com/technet/security/advisory/912840.mspx
http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&DocumentOID=375341
http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&DocumentOID=375420
oval:org.mitre.oval:def:1431
oval:org.mitre.oval:def:1433
oval:org.mitre.oval:def:1460
oval:org.mitre.oval:def:1492
oval:org.mitre.oval:def:1564
oval:org.mitre.oval:def:1612
win-wmf-execute-code(23846)

CPE    5
cpe:/o:microsoft:windows_xp::sp1:media_center
cpe:/o:microsoft:windows_xp::sp2:media_center
cpe:/o:microsoft:windows_xp::gold:professional
cpe:/o:microsoft:windows_xp:::media_center
...
CWE    1
CWE-20
OVAL    6
oval:org.mitre.oval:def:1460
oval:org.mitre.oval:def:1492
oval:org.mitre.oval:def:1433
oval:org.mitre.oval:def:1564
...

© SecPod Technologies