Security Advisory

CVE-2006-4071

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2006-08-10 01:00:00
Last updated 2024-08-07 18:57:45
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Sign extension vulnerability in the createBrushIndirect function in the GDI library (gdi32.dll) in Microsoft Windows XP, Server 2003, and possibly other versions, allows user-assisted attackers to cause a denial of service (application crash) via a crafted WMF file.