Vulnerabilities > CVE-2006-2378 - Unspecified vulnerability in Microsoft products

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
microsoft
nessus

Summary

Buffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and Sp2, Server 2003 SP1 and earlier, and Windows 98 and Me allows remote attackers to execute arbitrary code via a crafted ART image that causes heap corruption.

Nessus

NASL familyWindows : Microsoft Bulletins
NASL idSMB_NT_MS06-022.NASL
descriptionThe remote host is running a version of Windows that contains a flaw in the Hyperlink Object Library. An attacker may exploit this flaw to execute arbitrary code on the remote host. To exploit this flaw, an attacker would need to construct a malicious hyperlink and lure a victim into clicking it.
last seen2020-06-01
modified2020-06-02
plugin id21686
published2006-06-13
reporterThis script is Copyright (C) 2006-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/21686
titleMS06-022: Vulnerability in ART Image Rendering Could Allow Remote Code Execution (918439)

Oval

  • accepted2014-02-24T04:00:20.636-05:00
    classvulnerability
    contributors
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameShane Shaffer
      organizationG2, Inc.
    • nameSudhir Gandhe
      organizationTelos
    • nameShane Shaffer
      organizationG2, Inc.
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionBuffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and Sp2, Server 2003 SP1 and earlier, and Windows 98 and Me allows remote attackers to execute arbitrary code via a crafted ART image that causes heap corruption.
    familywindows
    idoval:org.mitre.oval:def:1590
    statusaccepted
    submitted2006-06-14T09:55:00.000-04:00
    titleART Image Rendering Vulnerability (2K/XP)
    version71
  • accepted2011-05-16T04:01:28.501-04:00
    classvulnerability
    contributors
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameDragos Prisaca
      organizationGideon Technologies, Inc.
    • nameShane Shaffer
      organizationG2, Inc.
    • nameSudhir Gandhe
      organizationTelos
    • nameShane Shaffer
      organizationG2, Inc.
    descriptionBuffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and Sp2, Server 2003 SP1 and earlier, and Windows 98 and Me allows remote attackers to execute arbitrary code via a crafted ART image that causes heap corruption.
    familywindows
    idoval:org.mitre.oval:def:1640
    statusaccepted
    submitted2006-06-14T09:55:00.000-04:00
    titleART Image Rendering Vulnerability (XP,SP2)
    version69
  • accepted2011-05-16T04:01:32.674-04:00
    classvulnerability
    contributors
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameShane Shaffer
      organizationG2, Inc.
    • nameSudhir Gandhe
      organizationTelos
    • nameShane Shaffer
      organizationG2, Inc.
    descriptionBuffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and Sp2, Server 2003 SP1 and earlier, and Windows 98 and Me allows remote attackers to execute arbitrary code via a crafted ART image that causes heap corruption.
    familywindows
    idoval:org.mitre.oval:def:1668
    statusaccepted
    submitted2006-06-14T09:55:00.000-04:00
    titleART Image Rendering Vulnerability (64-bit XP)
    version68
  • accepted2014-02-24T04:00:22.931-05:00
    classvulnerability
    contributors
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameAnna Min
      organizationBigFix, Inc
    • nameShane Shaffer
      organizationG2, Inc.
    • nameSudhir Gandhe
      organizationTelos
    • nameShane Shaffer
      organizationG2, Inc.
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionBuffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and Sp2, Server 2003 SP1 and earlier, and Windows 98 and Me allows remote attackers to execute arbitrary code via a crafted ART image that causes heap corruption.
    familywindows
    idoval:org.mitre.oval:def:1756
    statusaccepted
    submitted2006-06-14T09:55:00.000-04:00
    titleART Image Rendering Vulnerability (Win2K)
    version72
  • accepted2011-05-09T04:01:22.805-04:00
    classvulnerability
    contributors
    • nameRobert L. Hollis
      organizationThreatGuard, Inc.
    • nameShane Shaffer
      organizationG2, Inc.
    descriptionBuffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and Sp2, Server 2003 SP1 and earlier, and Windows 98 and Me allows remote attackers to execute arbitrary code via a crafted ART image that causes heap corruption.
    familywindows
    idoval:org.mitre.oval:def:1866
    statusaccepted
    submitted2006-06-14T09:55:00.000-04:00
    titleART Image Rendering Vulnerability (WinS03)
    version66