First published: Thu Dec 23 2004(Updated: )
The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number set to zero, which leads to resource exhaustion and hang.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nortel IP Softphone 2050 | ||
Nortel Multimedia Communication Server 5100 | =3.0 | |
Nortel Media Communication Server 5200 | =3.0 | |
Nortel Media Processing Server | ||
Nortel Periphonics | ||
Nortel Symposium Agent | ||
Nortel Symposium Network Control Center | ||
Nortel Symposium TAPI Service Provider | ||
Nortel Symposium Web Centre Portal | ||
Nortel Symposium Web Client | ||
Nortel Symposium Call Center Server | ||
Nortel Symposium Express Call Center | ||
Microsoft Windows 2000 | ||
Microsoft Windows 2000 | =sp1 | |
Microsoft Windows 2000 | =sp2 | |
Microsoft Windows 2000 | =sp3 | |
Microsoft Windows 2000 | =sp4 | |
Microsoft Windows Server 2003 | =enterprise | |
Microsoft Windows Server 2003 | =enterprise_64-bit | |
Microsoft Windows Server 2003 | =r2 | |
Microsoft Windows Server 2003 | =r2 | |
Microsoft Windows Server 2003 | =standard | |
Microsoft Windows Server 2003 | =web | |
Microsoft Windows 9x | =gold | |
Microsoft Windows 98 | ||
Microsoft Windows | ||
Microsoft Windows NT | =4.0 | |
Microsoft Windows NT | =4.0 | |
Microsoft Windows NT | =4.0 | |
Microsoft Windows NT | =4.0 | |
Microsoft Windows NT | =4.0-sp1 | |
Microsoft Windows NT | =4.0-sp1 | |
Microsoft Windows NT | =4.0-sp1 | |
Microsoft Windows NT | =4.0-sp1 | |
Microsoft Windows NT | =4.0-sp2 | |
Microsoft Windows NT | =4.0-sp2 | |
Microsoft Windows NT | =4.0-sp2 | |
Microsoft Windows NT | =4.0-sp2 | |
Microsoft Windows NT | =4.0-sp3 | |
Microsoft Windows NT | =4.0-sp3 | |
Microsoft Windows NT | =4.0-sp3 | |
Microsoft Windows NT | =4.0-sp3 | |
Microsoft Windows NT | =4.0-sp4 | |
Microsoft Windows NT | =4.0-sp4 | |
Microsoft Windows NT | =4.0-sp4 | |
Microsoft Windows NT | =4.0-sp4 | |
Microsoft Windows NT | =4.0-sp5 | |
Microsoft Windows NT | =4.0-sp5 | |
Microsoft Windows NT | =4.0-sp5 | |
Microsoft Windows NT | =4.0-sp5 | |
Microsoft Windows NT | =4.0-sp6 | |
Microsoft Windows NT | =4.0-sp6 | |
Microsoft Windows NT | =4.0-sp6 | |
Microsoft Windows NT | =4.0-sp6 | |
Microsoft Windows NT | =4.0-sp6a | |
Microsoft Windows NT | =4.0-sp6a | |
Microsoft Windows NT | =4.0-sp6a | |
Microsoft Windows XP | ||
Microsoft Windows XP | ||
Microsoft Windows XP | ||
Microsoft Windows XP | ||
Microsoft Windows XP | =gold | |
Microsoft Windows XP | =sp1 | |
Microsoft Windows XP | =sp1 | |
Microsoft Windows XP | =sp1 | |
Microsoft Windows XP | =sp1 | |
Microsoft Windows XP | =sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1305 has a severity rating of critical due to its potential to cause a denial of service and kernel crash.
To fix CVE-2004-1305, users should upgrade to a secure version of Windows that is no longer vulnerable to this flaw.
CVE-2004-1305 affects multiple Windows operating systems including Windows NT, Windows 2000, Windows XP, and Windows 2003.
CVE-2004-1305 is a denial of service vulnerability related to the Windows Animated Cursor (ANI) capability.
Yes, CVE-2004-1305 can be exploited remotely by attackers sending specially crafted animated cursor files.