CVE Vulnerabilities

CVE-2005-2123

Published: Nov 29, 2005 | Modified: Oct 12, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Multiple integer overflows in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allow remote attackers to execute arbitrary code via crafted Windows Metafile (WMF) and Enhanced Metafile (EMF) format images that lead to heap-based buffer overflows, as demonstrated using MRBP16::bCheckRecord.

Affected Software

Name Vendor Start Version End Version
Windows_2000 Microsoft * *
Windows_2003_server Microsoft 64-bit (including) 64-bit (including)
Windows_2003_server Microsoft itanium (including) itanium (including)
Windows_2003_server Microsoft r2 (including) r2 (including)
Windows_2003_server Microsoft sp1 (including) sp1 (including)
Windows_xp Microsoft * *

References