CVE-2008-4127: Medium severity internet explorer vulnerability
Published Sep 18, 2008
·Updated
Mshtml.dll in Microsoft Internet Explorer 7 Gold 7.0.5730 and 8 Beta 8.0.6001 on Windows XP SP2 allows remote attackers to cause a denial of service (failure of subsequent image rendering) via a crafted PNG file, related to an infinite loop in the CDwnTaskExec::ThreadExec function.
Affected Software
3 affected components
Microsoft Internet Explorer=7.0.5730-unknown
Microsoft Internet Explorer=8.0.6001-beta
Microsoft Windows XP=sp2
Event History
Sep 18, 2008
CVE Published
via MITRE·05:47 PM
Data Sourced
via MITRE·05:47 PM
Description
Data Sourced
05:59 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-4127?
CVE-2008-4127 is classified as a denial of service vulnerability.
2
How do I fix CVE-2008-4127?
To fix CVE-2008-4127, upgrade to a version of Internet Explorer that is not vulnerable, such as later versions beyond IE8 Beta.
3
What versions of Internet Explorer are affected by CVE-2008-4127?
CVE-2008-4127 affects Internet Explorer 7.0.5730 and Internet Explorer 8.0.6001 Beta.
4
What type of attack does CVE-2008-4127 facilitate?
CVE-2008-4127 facilitates a denial of service attack by exploiting an infinite loop in image rendering.
5
Can CVE-2008-4127 be exploited via crafted files?
Yes, CVE-2008-4127 can be exploited using a specially crafted PNG file.