First published: Thu Aug 10 2006(Updated: )
Sign extension vulnerability in the createBrushIndirect function in the GDI library (gdi32.dll) in Microsoft Windows XP, Server 2003, and possibly other versions, allows user-assisted attackers to cause a denial of service (application crash) via a crafted WMF file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows XP | =sp1 | |
Microsoft Windows 2003 Server | =sp1 | |
Microsoft Windows 2003 Server | =r2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =gold |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4071 is classified as a denial of service vulnerability.
To mitigate CVE-2006-4071, apply the latest security patches provided by Microsoft for affected Windows versions.
CVE-2006-4071 affects Microsoft Windows XP and Windows Server 2003, including specific service pack versions.
CVE-2006-4071 can be exploited through specially crafted WMF files that lead to application crashes.
CVE-2006-4071 requires user interaction to exploit, making remote exploitation unlikely.