First published: Tue Jun 13 2006(Updated: )
Buffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and Sp2, Server 2003 SP1 and earlier, and Windows 98 and Me allows remote attackers to execute arbitrary code via a crafted ART image that causes heap corruption.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
microsoft ie | =6.0-sp1 | |
Internet Explorer | =5.0.1 | |
Internet Explorer | =5.0.1-sp1 | |
Internet Explorer | =5.0.1-sp2 | |
Internet Explorer | =5.0.1-sp3 | |
Internet Explorer | =5.0.1-sp4 | |
Internet Explorer | =6.0 | |
Microsoft Windows 2003 Server | =datacenter_edition | |
Microsoft Windows 2003 Server | =datacenter_edition-sp1 | |
Microsoft Windows 2003 Server | =datacenter_edition_64-bit | |
Microsoft Windows 2003 Server | =datacenter_edition_64-bit-sp1 | |
Microsoft Windows 2003 Server | =enterprise_64-bit | |
Microsoft Windows 2003 Server | =enterprise_edition-sp1 | |
Microsoft Windows 2003 Server | =enterprise_edition_64-bit | |
Microsoft Windows 2003 Server | =enterprise_edition_64-bit-sp1 | |
Microsoft Windows 2003 Server | =r2 | |
Microsoft Windows 2003 Server | =sp1 | |
Microsoft Windows 2003 Server | =standard | |
Microsoft Windows 2003 Server | =standard-sp1 | |
Microsoft Windows 2003 Server | =standard_64-bit | |
Microsoft Windows 2003 Server | =web | |
Microsoft Windows 2003 Server | =web-sp1 | |
Microsoft Windows XP | ||
Microsoft Windows XP | ||
Microsoft Windows XP | ||
Microsoft Windows XP | =gold | |
Microsoft Windows XP | =sp1 | |
Microsoft Windows XP | =sp1 | |
Microsoft Windows XP | =sp1 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Internet Explorer | =6.0-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-2378 has a severity rating that indicates it allows remote attackers to execute arbitrary code.
To fix CVE-2006-2378, users should apply the latest security patches provided by Microsoft for affected versions.
CVE-2006-2378 affects Microsoft Windows XP SP1, SP2, Server 2003 SP1 and earlier, and Windows 98 and Me.
The primary impact of CVE-2006-2378 is heap corruption due to buffer overflow, which can lead to remote code execution.
While applying patches is the best solution, limiting the use of affected software can serve as a temporary workaround for CVE-2006-2378.