Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service (CPU consumption) via a certain PNG file with a large tEXt chunk that possibly triggers an integer overflow in PNG chunk size handling, as demonstrated by badlycrafted.png.
Weaknesses in this category are related to improper calculation or conversion of numbers.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/480594/100/0/threaded | mailing list |
http://www.securityfocus.com/archive/1/480854/100/0/threaded | mailing list |
http://www.securityfocus.com/archive/1/480706/100/0/threaded | mailing list |
http://www.securityfocus.com/archive/1/480827/100/0/threaded | mailing list |
http://www.securityfocus.com/bid/25816 | vdb entry exploit |
http://osvdb.org/45521 | vdb entry |
http://www.securityfocus.com/archive/1/480864/100/0/threaded | mailing list |