CVE-2004-0566: Integer Overflow
Published Jul 21, 2004
·Updated
Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to execute arbitrary code via a BMP image with a large bfOffBits value.
Affected Software
9 affected components
Microsoft Internet Explorer=5.5-sp2
Microsoft Internet Explorer=5.0
Microsoft Internet Explorer=5.0.1
Microsoft Internet Explorer=5.0.1-sp2
Microsoft Internet Explorer=5.0.1-sp3
Microsoft Internet Explorer=5.0.1-sp4
Microsoft Internet Explorer=5.0.1-sp1
Microsoft Internet Explorer=5.5
Microsoft Internet Explorer=5.5-sp1
Event History
Jul 21, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0566?
CVE-2004-0566 is classified as critical due to the potential for remote code execution.
2
How do I fix CVE-2004-0566?
To fix CVE-2004-0566, update your Internet Explorer to a non-vulnerable version or apply security patches provided by Microsoft.
3
Which versions of Internet Explorer are affected by CVE-2004-0566?
CVE-2004-0566 affects Internet Explorer versions 5.0, 5.0.1, and 5.5 across various service packs.
4
What type of attack can exploit CVE-2004-0566?
CVE-2004-0566 can be exploited through specially crafted BMP images that lead to arbitrary code execution.
5
Is there a workaround for CVE-2004-0566?
Disabling the ability to open BMP images or switching to a different browser may serve as a temporary workaround for CVE-2004-0566.