CVE-2006-2378

Buffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and Sp2, Server 2003 SP1 and earlier, and Windows 98 and Me allows remote attackers to execute arbitrary code via a crafted ART image that causes heap corruption.
References
Link Resource
http://secunia.com/advisories/20605 Vendor Advisory
http://securitytracker.com/id?1016292
http://www.idefense.com/intelligence/vulnerabilities/display.php?id=407
http://www.kb.cert.org/vuls/id/923236 Patch US Government Resource
http://www.osvdb.org/26432
http://www.securityfocus.com/bid/18394 Patch
http://www.us-cert.gov/cas/techalerts/TA06-164A.html US Government Resource
http://www.vupen.com/english/advisories/2006/2320
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-022
https://exchange.xforce.ibmcloud.com/vulnerabilities/26809
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1590
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1640
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1668
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1756
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1866
http://secunia.com/advisories/20605 Vendor Advisory
http://securitytracker.com/id?1016292
http://www.idefense.com/intelligence/vulnerabilities/display.php?id=407
http://www.kb.cert.org/vuls/id/923236 Patch US Government Resource
http://www.osvdb.org/26432
http://www.securityfocus.com/bid/18394 Patch
http://www.us-cert.gov/cas/techalerts/TA06-164A.html US Government Resource
http://www.vupen.com/english/advisories/2006/2320
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-022
https://exchange.xforce.ibmcloud.com/vulnerabilities/26809
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1590
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1640
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1668
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1756
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1866
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:ie:6.0:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp3:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp4:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:microsoft:windows_2003_server:datacenter_edition:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:datacenter_edition:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:datacenter_edition_64-bit:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:datacenter_edition_64-bit:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:enterprise_64-bit:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:enterprise_edition:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:enterprise_edition_64-bit:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:enterprise_edition_64-bit:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:r2:*:datacenter_64-bit:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:sp1:*:enterprise:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:standard:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:standard:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:standard_64-bit:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:web:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:web:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:*:64-bit:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:*:home:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:*:media_center:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:gold:professional:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp1:64-bit:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp1:home:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp1:media_center:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp2:home:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp2:media_center:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp2:tablet_pc:*:*:*:*:*

History

21 Nov 2024, 00:11

Type Values Removed Values Added
References () http://secunia.com/advisories/20605 - Vendor Advisory () http://secunia.com/advisories/20605 - Vendor Advisory
References () http://securitytracker.com/id?1016292 - () http://securitytracker.com/id?1016292 -
References () http://www.idefense.com/intelligence/vulnerabilities/display.php?id=407 - () http://www.idefense.com/intelligence/vulnerabilities/display.php?id=407 -
References () http://www.kb.cert.org/vuls/id/923236 - Patch, US Government Resource () http://www.kb.cert.org/vuls/id/923236 - Patch, US Government Resource
References () http://www.osvdb.org/26432 - () http://www.osvdb.org/26432 -
References () http://www.securityfocus.com/bid/18394 - Patch () http://www.securityfocus.com/bid/18394 - Patch
References () http://www.us-cert.gov/cas/techalerts/TA06-164A.html - US Government Resource () http://www.us-cert.gov/cas/techalerts/TA06-164A.html - US Government Resource
References () http://www.vupen.com/english/advisories/2006/2320 - () http://www.vupen.com/english/advisories/2006/2320 -
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-022 - () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-022 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/26809 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/26809 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1590 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1590 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1640 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1640 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1668 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1668 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1756 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1756 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1866 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1866 -

Information

Published : 2006-06-13 19:06

Updated : 2024-11-21 00:11


NVD link : CVE-2006-2378

Mitre link : CVE-2006-2378

CVE.ORG link : CVE-2006-2378


JSON object : View

Products Affected

microsoft

  • internet_explorer
  • windows_xp
  • ie
  • windows_2003_server