CVE-2006-0020
Description
An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute code via a crafted WMF file with a manipulated WMF header size, possibly involving an integer overflow, a different vulnerability than CVE-2005-4560, and aka "WMF Image Parsing Memory Corruption Vulnerability."
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9- cpe:2.3:o:microsoft:windows_2000:*:sp4:*:fr:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:r2:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:microsoft:windows_2003_server:r2:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_2003_server:sp1:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_98:*:gold:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:microsoft:windows_98:*:gold:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_98se:*:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_me:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp1:tablet_pc:*:*:*:*:*+ 1 more
- cpe:2.3:o:microsoft:windows_xp:*:sp1:tablet_pc:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_xp:*:sp2:tablet_pc:*:*:*:*:*
- Range: 5.01 SP4, 5.5 SP2
Patches
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
11- secunia.com/advisories/18729nvdPatchVendor Advisory
- www.kb.cert.org/vuls/id/312956nvdPatchThird Party AdvisoryUS Government Resource
- www.securityfocus.com/bid/16516nvdPatch
- linuxbox.org/pipermail/funsec/2006-January/002828.htmlnvdExploitVendor Advisory
- secunia.com/advisories/18912nvdVendor Advisory
- www.microsoft.com/technet/security/advisory/913333.mspxnvdVendor Advisory
- www.us-cert.gov/cas/techalerts/TA06-045A.htmlnvdThird Party AdvisoryUS Government Resource
- www.osvdb.org/22976nvd
- www.vupen.com/english/advisories/2006/0469nvd
- docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-004nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1638nvd
News mentions
0No linked articles in our index yet.