First published: Wed Apr 11 2007(Updated: )
Integer overflow in Windows Explorer in Microsoft Windows XP SP1 might allow user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large width dimension in a crafted BMP image, as demonstrated by w4intof.bmp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows XP | =sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1946 has a severity rating of moderate due to its potential to cause denial of service and arbitrary code execution.
To fix CVE-2007-1946, update Microsoft Windows XP to a newer service pack or apply relevant security patches provided by Microsoft.
CVE-2007-1946 specifically affects Microsoft Windows XP with Service Pack 1.
CVE-2007-1946 is classified as an integer overflow vulnerability.
Yes, CVE-2007-1946 can be exploited by remote attackers via specially crafted BMP images.