Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Microsoft GDI+ EMF Image Processing Memory Corruption Vulnerability

Microsoft GDI+ is prone to a remote memory-corruption vulnerability that occurs when an application that uses the library tries to process a specially crafted EMF (Enhanced Metafile) image file.

Successfully exploiting this issue would allow an attacker to execute arbitrary code in the context of the currently logged-in user.

UPDATE (March 25, 2009): Further investigation reveals that technical details and an exploit regarding 'GpFont.SetData()', which were added to this BID on March 24, 2009, actually pertain to a new issue. Please see BID 34250 'Microsoft GDI+ EMF 'GpFont.SetData()' Buffer Overflow Vulnerability' for details.







 

Privacy Statement
Copyright 2008, SecurityFocus