First published: Tue Jul 19 2005(Updated: )
The JPEG decoder in Microsoft Internet Explorer allows remote attackers to cause a denial of service (CPU consumption or crash) and possibly execute arbitrary code via certain crafted JPEG images, as demonstrated using (1) mov_fencepost.jpg, (2) cmp_fencepost.jpg, (3) oom_dos.jpg, or (4) random.jpg.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Explorer | =6.0-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2308 has a medium severity rating due to its potential to cause denial of service and possible arbitrary code execution.
To fix CVE-2005-2308, it is recommended to update Microsoft Internet Explorer to the latest version available.
CVE-2005-2308 can result in high CPU consumption, application crashes, or execution of potentially harmful code.
CVE-2005-2308 specifically affects Microsoft Internet Explorer 6.0 with Service Pack 2.
Yes, CVE-2005-2308 can be exploited remotely through specially crafted JPEG images.