First published: Fri Sep 17 2004(Updated: )
Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft .NET Framework 4 | =1.0-sp2 | |
Microsoft Digital Image Pro | =7.0 | |
Microsoft Digital Image Pro | =9 | |
Microsoft Digital Image Suite | =9 | |
Microsoft Office Excel | =2002 | |
Microsoft Office Excel | =2003 | |
Microsoft Office FrontPage | =2002 | |
Microsoft Office FrontPage | =2003 | |
Microsoft Greetings | =2002 | |
Microsoft InfoPath 2016 | =2003 | |
Microsoft Office | =2003 | |
Microsoft Office | =xp-sp3 | |
Microsoft OneNote 2010 | =2003 | |
Microsoft Outlook | =2002 | |
Microsoft Outlook | =2003 | |
Microsoft Picture It! | =7.0 | |
Microsoft Picture It! | =9 | |
Microsoft Picture It! | =2002 | |
Microsoft PowerPoint 2010 | =2002 | |
Microsoft PowerPoint 2010 | =2003 | |
Microsoft Producer | =gold | |
Microsoft Project 2013 | =2002-sp1 | |
Microsoft Project 2013 | =2003 | |
Microsoft Publisher 2010 | =2002 | |
Microsoft Publisher 2010 | =2003 | |
Microsoft Visio Standard | =2002-sp2 | |
Microsoft Visio Standard | =2003 | |
Microsoft Visual Basic SDK | =2002 | |
Microsoft Visual Basic SDK | =2003 | |
Microsoft Visual C# | =2002 | |
Microsoft Visual C# | =2003 | |
Microsoft Visual C++ | =2002 | |
Microsoft Visual C++ | =2003 | |
Microsoft Visual J# .NET | =2003 | |
Microsoft Visual Studio | =2002-gold | |
Microsoft Visual Studio | =2003-gold | |
Microsoft Office Word | =2002 | |
Microsoft Office Word | =2003 | |
Microsoft Windows Server 2003 | =r2 | |
Microsoft Windows XP | ||
Microsoft Windows XP | =gold | |
Microsoft Windows XP | =sp1 | |
Microsoft Windows XP | =sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0200 is considered critical due to its potential for remote code execution.
To fix CVE-2004-0200, you should apply the latest security updates provided by Microsoft for the affected products.
CVE-2004-0200 affects multiple Microsoft products including Visual Studio.NET, Microsoft Word, and Microsoft Office FrontPage.
Yes, CVE-2004-0200 can be exploited by attackers through crafted JPEG images.
CVE-2004-0200 can allow attackers to execute arbitrary code, potentially compromising the affected system.