Vulnerabilities > CVE-2006-4071 - Remote Denial of Service vulnerability in Microsoft Windows 2003 Server and Windows XP
Attack vector
NETWORK Attack complexity
HIGH Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
PARTIAL Summary
Sign extension vulnerability in the createBrushIndirect function in the GDI library (gdi32.dll) in Microsoft Windows XP, Server 2003, and possibly other versions, allows user-assisted attackers to cause a denial of service (application crash) via a crafted WMF file.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 5 |
Exploit-Db
description | MS Windows Explorer (WMF) CreateBrushIndirect DoS Exploit. CVE-2006-4071. Dos exploit for windows platform |
file | exploits/windows/dos/3111.pl |
id | EDB-ID:3111 |
last seen | 2016-01-31 |
modified | 2007-01-13 |
platform | windows |
port | |
published | 2007-01-13 |
reporter | cyanid-E |
source | https://www.exploit-db.com/download/3111/ |
title | Microsoft Windows - Explorer WMF CreateBrushIndirect DoS Exploit |
type | dos |
References
- http://determina.blogspot.com/2007/01/whats-wrong-with-wmf.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-August/048530.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-August/048547.html
- http://secunia.com/advisories/21377
- http://securityreason.com/securityalert/1353
- http://www.securityfocus.com/archive/1/442420/100/0/threaded
- http://www.securityfocus.com/archive/1/442426/100/0/threaded
- http://www.securityfocus.com/archive/1/456585/100/0/threaded
- http://www.securityfocus.com/bid/19365
- http://www.securityfocus.com/bid/21992
- http://www.vupen.com/english/advisories/2006/3180
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28281
- https://www.exploit-db.com/exploits/3111